<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2012-02-13" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2005-0001" published="2005-05-02" name="CVE-2005-0001" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18849" source="XF">linux-fault-handler-gain-privileges(18849)</ref>
      <ref url="http://www.trustix.org/errata/2005/0001/" source="TRUSTIX">2005-0001</ref>
      <ref url="http://www.securityfocus.com/bid/12244" source="BID">12244</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT">RHSA-2005:092</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-043.html" source="REDHAT">RHSA-2005:043</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT">RHSA-2005:016</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://securitytracker.com/id?1012862" source="SECTRACK">1012862</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/13822" source="SECUNIA">13822</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10322" source="OVAL">oval:org.mitre.oval:def:10322</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581146702951&amp;w=2" source="BUGTRAQ">20050114 [USN-60-0] Linux kernel vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110554694522719&amp;w=2" source="BUGTRAQ">20050112 Linux kernel i386 SMP page fault handler privilege escalation</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030826.html" source="FULLDISC">20050112 Linux kernel i386 SMP page fault handler privilege escalation</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0022-pagefault.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0022-pagefault.txt</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.7" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.24" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" />
        <vers num="2.4.28" />
        <vers num="2.4.29" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0002" published="2005-05-02" name="CVE-2005-0002" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-22.xml" source="GENTOO" adv="1">GLSA-200501-22</ref>
      <ref url="http://securitytracker.com/id?1012840" source="SECTRACK">1012840</ref>
      <ref url="http://secunia.com/advisories/13865" source="SECUNIA">13865</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="poppassd_pam">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0003" published="2005-04-14" name="CVE-2005-0003" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12261" source="BID" patch="1" adv="1">12261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-043.html" source="REDHAT" patch="1" adv="1">RHSA-2005:043</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18886" source="XF">linux-vma-gain-privileges(18886)</ref>
      <ref url="http://www.trustix.org/errata/2005/0001/" source="TRUSTIX">2005-0001</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE">SUSE-SA:2005:018</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://securitytracker.com/id?1012885" source="SECTRACK">1012885</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9512" source="OVAL">oval:org.mitre.oval:def:9512</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg" source="MISC">http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx" />
      </prod>
      <prod vendor="avaya" name="mn100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="network_routing">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8710">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0004" published="2005-04-14" name="CVE-2005-0004" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12277" source="BID" patch="1" adv="1">12277</ref>
      <ref url="http://www.debian.org/security/2005/dsa-647" source="DEBIAN" patch="1" adv="1">DSA-647</ref>
      <ref url="http://secunia.com/advisories/13867" source="SECUNIA" patch="1" adv="1">13867</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18922" source="XF">mysql-mysqlaccess-symlink(18922)</ref>
      <ref url="http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html" source="CONFIRM">http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608297217224&amp;w=2" source="BUGTRAQ">20050118 [USN-63-1] MySQL client vulnerability</ref>
      <ref url="http://lists.mysql.com/internals/20600" source="CONFIRM">http://lists.mysql.com/internals/20600</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000947" source="CONECTIVA">CLA-2005:947</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:036" source="MANDRAKE">MDKSA-2005:036</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1" source="SUNALERT">101864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.18" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.21" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
        <vers num="4.1.2" edition="alpha" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0005" published="2005-05-02" name="CVE-2005-0005" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-071.html" source="REDHAT" patch="1">RHSA-2005:071</ref>
      <ref url="http://www.debian.org/security/2005/dsa-646" source="DEBIAN" patch="1" adv="1">DSA-646</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=184&amp;type=vulnerabilities" source="IDEFENSE">20050117 Multiple Vendor ImageMagick .psd Image File Decode Heap Overflow Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-37.xml" source="GENTOO">GLSA-200501-37</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9925" source="OVAL">oval:org.mitre.oval:def:9925</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608222117215&amp;w=2" source="BUGTRAQ">20050118 [USN-62-1] imagemagick vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-070.html" source="REDHAT">RHSA-2005:070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="graphicsmagick" name="graphicsmagick">
        <vers num="1.0" />
        <vers num="1.0.6" />
        <vers num="1.1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.4.3" />
        <vers num="5.4.7" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.2.5" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.1" />
        <vers num="6.1.1.6" />
        <vers num="6.1.2" />
        <vers num="6.1.3" />
        <vers num="6.1.4" />
        <vers num="6.1.5" />
        <vers num="6.1.6" />
        <vers num="6.1.7" />
        <vers num="6.2" />
        <vers num="6.2.0.4" />
        <vers num="6.2.0.7" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0006" published="2005-05-02" name="CVE-2005-0006" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The COPS dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (infinite loop).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1" adv="1">13946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18999" source="XF" adv="1">ethereal-cops-dos(18999)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT" adv="1">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO" adv="1">GLSA-200501-27</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC" adv="1">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10801" source="OVAL">oval:org.mitre.oval:def:10801</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0007" published="2005-05-02" name="CVE-2005-0007" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DLSw dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash from assertion).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19000" source="XF" patch="1">ethereal-dlsw-dos(19000)</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1">13946</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO">GLSA-200501-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11381" source="OVAL">oval:org.mitre.oval:def:11381</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0008" published="2005-05-02" name="CVE-2005-0008" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DNP dissector in Ethereal 0.10.5 through 0.10.8 allows remote attackers to cause "memory corruption."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19001" source="XF">ethereal-dnp-memory-corruption(19001)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT" adv="1">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO" adv="1">GLSA-200501-27</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC">P-106</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA">13946</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10689" source="OVAL">oval:org.mitre.oval:def:10689</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0009" published="2005-05-02" name="CVE-2005-0009" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Gnutella dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO" patch="1">GLSA-200501-27</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1" adv="1">13946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19002" source="XF" adv="1">ethereal-gnutella-dos(19002)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT" adv="1">RHSA-2005:037</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC" adv="1">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10623" source="OVAL">oval:org.mitre.oval:def:10623</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0010" published="2005-05-02" name="CVE-2005-0010" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19003" source="XF" patch="1">ethereal-mmse-free-memory(19003)</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1">13946</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO">GLSA-200501-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9521" source="OVAL">oval:org.mitre.oval:def:9521</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0011" published="2005-05-02" name="CVE-2005-0011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050215-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050215-1.txt</ref>
      <ref url="http://secunia.com/advisories/14306" source="SECUNIA" patch="1">14306</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.html" source="FEDORA" adv="1">FEDORA-2005-148</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-23.xml" source="GENTOO" adv="1">GLSA-200502-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0012" published="2005-05-02" name="CVE-2005-0012" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12203" source="BID" patch="1">12203</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18807" source="XF" adv="1">dillo-capi-format-string(18807)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-11.xml" source="GENTOO" adv="1">GLSA-200501-11</ref>
      <ref url="http://secunia.com/advisories/13760/" source="SECUNIA" adv="1">13760</ref>
      <ref url="http://secunia.com/advisories/13764" source="SECUNIA">13764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dillo" name="dillo_web_browser">
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.4" />
        <vers num="0.5.1" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.1.2" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0013" published="2005-05-02" name="CVE-2005-0013" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-665" source="DEBIAN" patch="1">DSA-665</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml" source="GENTOO" adv="1">GLSA-200501-44</ref>
      <ref url="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6" source="CONFIRM">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</ref>
      <ref url="http://www.securityfocus.com/bid/12400" source="BID">12400</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded" source="FEDORA">FLSA:152904</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-371.html" source="REDHAT">RHSA-2005:371</ref>
      <ref url="http://www.osvdb.org/13297" source="OSVDB">13297</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028" source="MANDRAKE">MDKSA-2005:028</ref>
      <ref url="http://securitytracker.com/id?1013019" source="SECTRACK">1013019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncpfs" name="ncpfs">
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0014" published="2005-05-02" name="CVE-2005-0014" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml" source="GENTOO">GLSA-200501-44</ref>
      <ref url="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6" source="CONFIRM">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</ref>
      <ref url="http://www.securityfocus.com/bid/12400" source="BID">12400</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded" source="FEDORA">FLSA:152904</ref>
      <ref url="http://www.osvdb.org/13298" source="OSVDB">13298</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028" source="MANDRAKE">MDKSA-2005:028</ref>
      <ref url="http://securitytracker.com/id?1013019" source="SECTRACK">1013019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncpfs" name="ncpfs">
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers prev="1" num="2.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0015" published="2005-05-02" name="CVE-2005-0015" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-650" source="DEBIAN" patch="1" adv="1">DSA-650</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18997" source="XF" adv="1">sword-diatheke-command-execution(18997)</ref>
      <ref url="http://securitytracker.com/id?1012955" source="SECTRACK">1012955</ref>
      <ref url="http://secunia.com/advisories/13897" source="SECUNIA">13897</ref>
      <ref url="http://www.securityfocus.com/bid/12320" source="BID">12320</ref>
      <ref url="http://secunia.com/advisories/13941" source="SECUNIA">13941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crosswire_bible_society" name="sword">
        <vers num="1.5.7a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0016" published="2005-04-14" name="CVE-2005-0016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-640" source="DEBIAN" patch="1" adv="1">DSA-640</ref>
      <ref url="http://secunia.com/advisories/13884/" source="SECUNIA" patch="1" adv="1">13884</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18930" source="XF" adv="1">gatos-xatitv-bo(18930)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gatos" name="gatos">
        <vers num="0.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0017" published="2005-05-02" name="CVE-2005-0017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-661" source="DEBIAN" patch="1">DSA-661</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-43.xml" source="GENTOO">GLSA-200501-43</ref>
      <ref url="http://www.securityfocus.com/bid/12380" source="BID">12380</ref>
      <ref url="http://securitytracker.com/id?1013028" source="SECTRACK">1013028</ref>
      <ref url="http://secunia.com/advisories/14067" source="SECUNIA">14067</ref>
      <ref url="http://secunia.com/advisories/14052" source="SECUNIA">14052</ref>
      <ref url="http://secunia.com/advisories/14041" source="SECUNIA">14041</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0018" published="2005-05-02" name="CVE-2005-0018" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12380" source="BID" patch="1">12380</ref>
      <ref url="http://www.debian.org/security/2005/dsa-661" source="DEBIAN" patch="1" adv="1">DSA-661</ref>
      <ref url="http://securitytracker.com/id?1013028" source="SECTRACK">1013028</ref>
      <ref url="http://secunia.com/advisories/14052" source="SECUNIA">14052</ref>
      <ref url="http://secunia.com/advisories/14041" source="SECUNIA">14041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f2c_open_source_project" name="f2c_translator">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0019" published="2005-04-27" name="CVE-2005-0019" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12518" source="BID" patch="1" adv="1">12518</ref>
      <ref url="http://www.debian.org/security/2005/dsa-675" source="DEBIAN" patch="1" adv="1">DSA-675</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19297" source="XF" adv="1">hztty-command-execution(19297)</ref>
      <ref url="http://securitytracker.com/id?1013154" source="SECTRACK">1013154</ref>
      <ref url="http://secunia.com/advisories/14236" source="SECUNIA">14236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yongguang_zhang" name="hztty">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0020" published="2005-04-14" name="CVE-2005-0020" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-641" source="DEBIAN" patch="1" adv="1">DSA-641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18933" source="XF" adv="1">playmidi-bo(18933)</ref>
      <ref url="http://www.securityfocus.com/bid/12274" source="BID">12274</ref>
      <ref url="http://www.osvdb.org/13049" source="OSVDB">13049</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:010" source="MANDRAKE">MDKSA-2005:010</ref>
      <ref url="http://securitytracker.com/id?1012957" source="SECTRACK">1012957</ref>
      <ref url="http://secunia.com/advisories/13898" source="SECUNIA">13898</ref>
      <ref url="http://secunia.com/advisories/13890" source="SECUNIA">13890</ref>
      <ref url="http://secunia.com/advisories/13828" source="SECUNIA">13828</ref>
    </refs>
    <vuln_soft>
      <prod vendor="playmidi" name="playmidi">
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.11" />
        <vers num="2.3.12" />
        <vers num="2.3.13" />
        <vers num="2.3.14" />
        <vers num="2.3.15" />
        <vers num="2.3.16" />
        <vers num="2.3.17" />
        <vers num="2.3.18" />
        <vers num="2.3.19" />
        <vers num="2.3.2" />
        <vers num="2.3.20" />
        <vers num="2.3.21" />
        <vers num="2.3.22" />
        <vers num="2.3.23" />
        <vers num="2.3.24" />
        <vers num="2.3.25" />
        <vers num="2.3.25.1" />
        <vers num="2.3.26" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0021" published="2005-05-02" name="CVE-2005-0021" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/132992" source="CERT-VN" patch="1">VU#132992</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-025.html" source="REDHAT" patch="1">RHSA-2005:025</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=183&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050114 Exim dns_buld_reverse() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=179&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050107 Exim host_aton() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html" source="MLIST">[exim] 20050104 2 smallish security issues</ref>
      <ref url="http://www.debian.org/security/2005/dsa-637" source="DEBIAN" adv="1">DSA-637</ref>
      <ref url="http://www.debian.org/security/2005/dsa-635" source="DEBIAN" adv="1">DSA-635</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-23.xml" source="GENTOO" adv="1">GLSA-200501-23</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10347" source="OVAL">oval:org.mitre.oval:def:10347</ref>
      <ref url="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44" source="CONFIRM">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers prev="1" num="4.40" />
        <vers num="4.41" />
        <vers num="4.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0022" published="2005-05-02" name="CVE-2005-0022" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-025.html" source="REDHAT" patch="1">RHSA-2005:025</ref>
      <ref url="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html" source="MLIST" patch="1">[exim] 20050104 2 smallish security issues</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=178&amp;type=vulnerabilities" source="IDEFENSE">20050107 Exim auth_spa_server() Buffer Overflow Vulnerability</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-23.xml" source="GENTOO" adv="1">GLSA-200501-23</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11293" source="OVAL">oval:org.mitre.oval:def:11293</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824870908614&amp;w=2" source="BUGTRAQ">20050212 exim auth_spa_server() PoC exploit</ref>
      <ref url="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44" source="CONFIRM">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</ref>
      <ref url="http://www.securityfocus.com/bid/12188" source="BID">12188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers prev="1" num="4.40" />
        <vers num="4.41" />
        <vers num="4.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0023" published="2005-10-05" name="CVE-2005-0023" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/22496" source="XF">libzvt-gnomeptyhelper-spoof(22496)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1931" source="VUPEN">ADV-2005-1931</ref>
      <ref url="http://www.securityfocus.com/bid/15004" source="BID">15004</ref>
      <ref url="http://secunia.com/advisories/17023" source="SECUNIA" adv="1">17023</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112879572407250&amp;w=2" source="BUGTRAQ">20051007 gnome-pty-helper writes arbitrary utmp records</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=317312" source="MISC">http://bugzilla.gnome.org/show_bug.cgi?id=317312</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330907" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="libvte4">
        <vers num="" />
      </prod>
      <prod vendor="gnome" name="libzvt2">
        <vers num="1.4.2.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0033" published="2005-05-02" name="CVE-2005-0033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/327633" source="CERT-VN" adv="1">VU#327633</ref>
      <ref url="http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html" source="MISC" patch="1">http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind8.php" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/bind8.php</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19063" source="XF">bind-qusedns-bo(19063)</ref>
      <ref url="http://www.securityfocus.com/bid/12364" source="BID">12364</ref>
      <ref url="http://securitytracker.com/id?1012996" source="SECTRACK">1012996</ref>
      <ref url="http://secunia.com/advisories/18291" source="SECUNIA">18291</ref>
      <ref url="http://secunia.com/advisories/14009" source="SECUNIA">14009</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.1/SCOSA-2006.1.txt" source="SCO">SCOSA-2006.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.4.4" />
        <vers num="8.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0034" published="2005-05-02" name="CVE-2005-0034" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/938617" source="CERT-VN" patch="1">VU#938617</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19062" source="XF" patch="1">bind-named-dns-dos(19062)</ref>
      <ref url="http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html" source="MISC" patch="1">http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX">2005-0003</ref>
      <ref url="http://www.securityfocus.com/bid/12365" source="BID">12365</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind9.php" source="CONFIRM">http://www.isc.org/index.pl?/sw/bind/bind9.php</ref>
      <ref url="http://securitytracker.com/id?1012995" source="SECTRACK">1012995</ref>
      <ref url="http://secunia.com/advisories/14008" source="SECUNIA">14008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0035" published="2005-05-02" name="CVE-2005-0035" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0310" source="VUPEN">ADV-2005-0310</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf" source="MISC">http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf</ref>
      <ref url="http://www.hyperdose.com/advisories/H2005-06.txt" source="MISC">http://www.hyperdose.com/advisories/H2005-06.txt</ref>
      <ref url="http://www.adobe.com/support/techdocs/331465.html" source="CONFIRM">http://www.adobe.com/support/techdocs/331465.html</ref>
      <ref url="http://www.securityfocus.com/bid/12989" source="BID">12989</ref>
      <ref url="http://www.osvdb.org/15242" source="OSVDB">15242</ref>
      <ref url="http://secunia.com/advisories/14813" source="SECUNIA">14813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0036" published="2005-12-31" name="CVE-2005-0036" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" source="MISC" patch="1" adv="1">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" source="MISC" patch="1">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</ref>
      <ref url="http://www.securityfocus.com/bid/13729" source="BID">13729</ref>
      <ref url="http://www.osvdb.org/25291" source="OSVDB">25291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delegate" name="delegate">
        <vers num="5.9.3" />
        <vers num="7.7.0" />
        <vers num="7.7.1" />
        <vers num="7.8.0" />
        <vers num="7.8.1" />
        <vers num="7.8.2" />
        <vers num="7.9.11" />
        <vers num="8.10" />
        <vers num="8.10.1" />
        <vers prev="1" num="8.10.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.4.0" />
        <vers num="8.5.0" />
        <vers num="8.9" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
        <vers num="8.9.3" />
        <vers num="8.9.4" />
        <vers num="8.9.5" />
        <vers num="8.9.6" />
      </prod>
      <prod vendor="etl" name="delegate">
        <vers num="5.9" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0037" published="2005-12-31" name="CVE-2005-0037" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.10 </sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" source="MISC" patch="1">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</ref>
      <ref url="http://www.securityfocus.com/bid/13729" source="BID">13729</ref>
      <ref url="http://www.osvdb.org/25291" source="OSVDB">25291</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" source="MISC">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnrd" name="dnrd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0038" published="2005-12-31" name="CVE-2005-0038" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" source="MISC">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</ref>
      <ref url="http://www.securityfocus.com/bid/13729" source="BID">13729</ref>
      <ref url="http://www.osvdb.org/25291" source="OSVDB">25291</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" source="MISC">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerdns" name="powerdns">
        <vers num="2.0_rc1" />
        <vers num="2.8" />
        <vers num="2.9.0" />
        <vers num="2.9.1" />
        <vers num="2.9.10" />
        <vers num="2.9.11" />
        <vers num="2.9.12" />
        <vers num="2.9.13" />
        <vers num="2.9.14" />
        <vers num="2.9.15" />
        <vers prev="1" num="2.9.16" />
        <vers num="2.9.2" />
        <vers num="2.9.3a" />
        <vers num="2.9.4" />
        <vers num="2.9.5" />
        <vers num="2.9.6" />
        <vers num="2.9.7" />
        <vers num="2.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0039" published="2005-05-10" name="CVE-2005-0039" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/302220" source="CERT-VN">VU#302220</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2806" source="VUPEN">ADV-2005-2806</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0507" source="VUPEN">ADV-2005-0507</ref>
      <ref url="http://www.securityfocus.com/archive/1/407774" source="HP">SSRT5957</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en" source="MISC">http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en</ref>
      <ref url="http://www.securityfocus.com/bid/13562" source="BID">13562</ref>
      <ref url="http://www.securityfocus.com/archive/1/407774" source="HP">HPSBTU01217</ref>
      <ref url="http://securitytracker.com/id?1015320" source="SECTRACK">1015320</ref>
      <ref url="http://secunia.com/advisories/17938" source="SECUNIA">17938</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566201610350&amp;w=2" source="BUGTRAQ">20050509 NISCC Vulnerability Advisory IPSEC - 004033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nissc" name="ipsec">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0040" published="2005-05-19" name="CVE-2005-0040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.woany.co.uk/advisories/dotnetnukexss.txt" source="MISC" adv="1">http://www.woany.co.uk/advisories/dotnetnukexss.txt</ref>
      <ref url="http://secunia.com/advisories/15397" source="SECUNIA">15397</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627180518591&amp;w=2" source="BUGTRAQ">20050516 DotNetNuke (Multiple XSS)</ref>
      <ref url="http://www.securityfocus.com/bid/13647" source="BID">13647</ref>
      <ref url="http://www.securityfocus.com/bid/13646" source="BID">13646</ref>
      <ref url="http://www.securityfocus.com/bid/13644" source="BID">13644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotnetnuke" name="dotnetnuke">
        <vers prev="1" num="3.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0043" published="2005-05-02" name="CVE-2005-0043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/377368" source="CERT-VN" patch="1" adv="1">VU#377368</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=180&amp;type=vulnerabilities" source="IDEFENSE" patch="1">20050113 Apple iTunes Playlist Parsing Buffer Overflow Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-01-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18851" source="XF">itunes-m3u-pls-bo(18851)</ref>
      <ref url="http://www.securityfocus.com/bid/12238" source="BID">12238</ref>
      <ref url="http://www.osvdb.org/12833" source="OSVDB">12833</ref>
      <ref url="http://securitytracker.com/id?1012839" source="SECTRACK">1012839</ref>
      <ref url="http://secunia.com/advisories/13804" source="SECUNIA">13804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0044" published="2005-05-02" name="CVE-2005-0044" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927889" source="CERT-VN" patch="1">VU#927889</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT">TA05-039A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx" source="MS" patch="1">MS05-012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19109" source="XF" adv="1">win-ole-code-execution(19109)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4499" source="OVAL" sig="1">oval:org.mitre.oval:def:4499</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3568" source="OVAL" sig="1">oval:org.mitre.oval:def:3568</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2917" source="OVAL" sig="1">oval:org.mitre.oval:def:2917</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1180" source="OVAL" sig="1">oval:org.mitre.oval:def:1180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0045" published="2005-05-02" name="CVE-2005-0045" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1" adv="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/652537" source="CERT-VN" patch="1" adv="1">VU#652537</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19089" source="XF" patch="1" adv="1">win-smb-code-execution(19089)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-011.mspx" source="MS" patch="1">MS05-011</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110795643831169&amp;w=2" source="NTBUGTRAQ">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040962600205&amp;w=2" source="BUGTRAQ">20050309 Update: MS05-011 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792638401852&amp;w=2" source="BUGTRAQ">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12484" source="BID">12484</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4043" source="OVAL" sig="1">oval:org.mitre.oval:def:4043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1889" source="OVAL" sig="1">oval:org.mitre.oval:def:1889</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1847" source="OVAL" sig="1">oval:org.mitre.oval:def:1847</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1606" source="OVAL" sig="1">oval:org.mitre.oval:def:1606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0047" published="2005-05-02" name="CVE-2005-0047" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/597889" source="CERT-VN" patch="1">VU#597889</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx" source="MS" patch="1">MS05-012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19105" source="XF">win-com-gain-privileges(19105)</ref>
      <ref url="http://www.argeniss.com/research/SSExploit.c" source="MISC">http://www.argeniss.com/research/SSExploit.c</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755870828817&amp;w=2" source="BUGTRAQ">20050530 [Argeniss] MS05-012 Exploit</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:901" source="OVAL" sig="1">oval:org.mitre.oval:def:901</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2892" source="OVAL" sig="1">oval:org.mitre.oval:def:2892</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2351" source="OVAL" sig="1">oval:org.mitre.oval:def:2351</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1159" source="OVAL" sig="1">oval:org.mitre.oval:def:1159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0048" published="2005-05-02" name="CVE-2005-0048" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html" source="CERT" patch="1">TA05-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/233754" source="CERT-VN" patch="1" adv="1">VU#233754</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" source="MS" patch="1">MS05-019</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/192" source="ISS" adv="1">20050412 Windows IP Options Remote Compromise</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4549" source="OVAL" sig="1">oval:org.mitre.oval:def:4549</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3824" source="OVAL" sig="1">oval:org.mitre.oval:def:3824</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1744" source="OVAL" sig="1">oval:org.mitre.oval:def:1744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0049" published="2005-05-02" name="CVE-2005-0049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/340409" source="CERT-VN" patch="1">VU#340409</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-006.mspx" source="MS" patch="1">MS05-006</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19091" source="XF" adv="1">win-sharepoint-services-xss(19091)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_portal_server">
        <vers num="2003" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="sharepoint_team_services">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0050" published="2005-05-02" name="CVE-2005-0050" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/130433" source="CERT-VN" patch="1">VU#130433</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-010.mspx" source="MS" patch="1" adv="1">MS05-010</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19101" source="XF" adv="1">win-license-code-execution(19101)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:644" source="OVAL" sig="1">oval:org.mitre.oval:def:644</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4786" source="OVAL" sig="1">oval:org.mitre.oval:def:4786</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3582" source="OVAL" sig="1">oval:org.mitre.oval:def:3582</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2568" source="OVAL" sig="1">oval:org.mitre.oval:def:2568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":small_business_server" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":small_business_server" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0051" published="2005-05-02" name="CVE-2005-0051" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1" adv="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/939074" source="CERT-VN" patch="1">VU#939074</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-007.mspx" source="MS" patch="1">MS05-007</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19093" source="XF">win-named-pipe-information-disclosure(19093)</ref>
      <ref url="http://www.securityfocus.com/bid/12486" source="BID">12486</ref>
      <ref url="http://securitytracker.com/id?1013112" source="SECTRACK">1013112</ref>
      <ref url="http://secunia.com/advisories/14189" source="SECUNIA">14189</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3055" source="OVAL" sig="1">oval:org.mitre.oval:def:3055</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2292" source="OVAL" sig="1">oval:org.mitre.oval:def:2292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0053" published="2005-05-02" name="CVE-2005-0053" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/698835" source="CERT-VN" patch="1">VU#698835</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19117" source="XF" patch="1" adv="1">ie-dragdrop-gain-privileges(19117)</ref>
      <ref url="http://www.securityfocus.com/bid/11466" source="BID" patch="1">11466</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" source="MS" patch="1">MS05-014</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-008.mspx" source="MS" patch="1">MS05-008</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4864" source="OVAL" sig="1">oval:org.mitre.oval:def:4864</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4726" source="OVAL" sig="1">oval:org.mitre.oval:def:4726</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3006" source="OVAL" sig="1">oval:org.mitre.oval:def:3006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2953" source="OVAL" sig="1">oval:org.mitre.oval:def:2953</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2046" source="OVAL" sig="1">oval:org.mitre.oval:def:2046</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1334" source="OVAL" sig="1">oval:org.mitre.oval:def:1334</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1015" source="OVAL" sig="1">oval:org.mitre.oval:def:1015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0054" published="2005-05-02" name="CVE-2005-0054" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/580299" source="CERT-VN" patch="1" adv="1">VU#580299</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" source="MS" patch="1">MS05-014</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796851002781&amp;w=2" source="BUGTRAQ" patch="1">20050209 Internet Explorer zone spoofing with encoded URLs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19214" source="XF">ie-file-url-encode(19214)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3586" source="OVAL" sig="1">oval:org.mitre.oval:def:3586</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3196" source="OVAL" sig="1">oval:org.mitre.oval:def:3196</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3060" source="OVAL" sig="1">oval:org.mitre.oval:def:3060</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1736" source="OVAL" sig="1">oval:org.mitre.oval:def:1736</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1308" source="OVAL" sig="1">oval:org.mitre.oval:def:1308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0055" published="2005-05-02" name="CVE-2005-0055" modified="2008-12-06" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/843771" source="CERT-VN" patch="1">VU#843771</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" source="MS" patch="1">MS05-014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19137" source="XF" adv="1">ie-cdf-execute-code(19137)</ref>
      <ref url="http://securitytracker.com/id?1013125" source="SECTRACK">1013125</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:710" source="OVAL" sig="1">oval:org.mitre.oval:def:710</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3910" source="OVAL" sig="1">oval:org.mitre.oval:def:3910</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3137" source="OVAL" sig="1">oval:org.mitre.oval:def:3137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2692" source="OVAL" sig="1">oval:org.mitre.oval:def:2692</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1005" source="OVAL" sig="1">oval:org.mitre.oval:def:1005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0056" published="2005-05-02" name="CVE-2005-0056" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/823971" source="CERT-VN" patch="1">VU#823971</ref>
      <ref url="http://www.securityfocus.com/bid/12427" source="BID" patch="1">12427</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" source="MS" patch="1">MS05-014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19137" source="XF" adv="1">ie-cdf-execute-code(19137)</ref>
      <ref url="http://securitytracker.com/id?1013126" source="SECTRACK">1013126</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4947" source="OVAL" sig="1">oval:org.mitre.oval:def:4947</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4085" source="OVAL" sig="1">oval:org.mitre.oval:def:4085</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3318" source="OVAL" sig="1">oval:org.mitre.oval:def:3318</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2817" source="OVAL" sig="1">oval:org.mitre.oval:def:2817</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2385" source="OVAL" sig="1">oval:org.mitre.oval:def:2385</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0057" published="2005-05-02" name="CVE-2005-0057" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/820427" source="CERT-VN" patch="1">VU#820427</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-015.mspx" source="MS" patch="1">MS05-015</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19110" source="XF" adv="1">win-hyperlink-code-execution(19110)</ref>
      <ref url="http://www.securityfocus.com/bid/12479" source="BID">12479</ref>
      <ref url="http://securitytracker.com/id?1013119" source="SECTRACK">1013119</ref>
      <ref url="http://secunia.com/advisories/14195" source="SECUNIA">14195</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:713" source="OVAL" sig="1">oval:org.mitre.oval:def:713</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3203" source="OVAL" sig="1">oval:org.mitre.oval:def:3203</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2570" source="OVAL" sig="1">oval:org.mitre.oval:def:2570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0058" published="2005-08-10" name="CVE-2005-0058" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-040.mspx" source="MS" patch="1">MS05-040</ref>
      <ref url="http://secunia.com/advisories/16354/" source="SECUNIA" patch="1" adv="1">16354</ref>
      <ref url="http://www.securityfocus.com/bid/14518" source="BID">14518</ref>
      <ref url="http://securitytracker.com/id?1014639" source="SECTRACK">1014639</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1297" source="OVAL" sig="1">oval:org.mitre.oval:def:1297</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1213" source="OVAL" sig="1">oval:org.mitre.oval:def:1213</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1075" source="OVAL" sig="1">oval:org.mitre.oval:def:1075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100088" source="OVAL" sig="1">oval:org.mitre.oval:def:100088</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100086" source="OVAL" sig="1">oval:org.mitre.oval:def:100086</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100085" source="OVAL" sig="1">oval:org.mitre.oval:def:100085</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100084" source="OVAL" sig="1">oval:org.mitre.oval:def:100084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0059" published="2005-05-02" name="CVE-2005-0059" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-017.mspx" source="MS" patch="1">MS05-017</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4988" source="OVAL" sig="1">oval:org.mitre.oval:def:4988</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4384" source="OVAL" sig="1">oval:org.mitre.oval:def:4384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0060" published="2005-05-02" name="CVE-2005-0060" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx" source="MS" patch="1">MS05-018</ref>
      <ref url="http://www.ngssoftware.com/advisories/ms-01.txt" source="MISC" adv="1">http://www.ngssoftware.com/advisories/ms-01.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343529426926&amp;w=2" source="BUGTRAQ" adv="1">20050413 Windows kernel overflow fixed</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4797" source="OVAL" sig="1">oval:org.mitre.oval:def:4797</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3941" source="OVAL" sig="1">oval:org.mitre.oval:def:3941</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2731" source="OVAL" sig="1">oval:org.mitre.oval:def:2731</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2562" source="OVAL" sig="1">oval:org.mitre.oval:def:2562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0061" published="2005-05-02" name="CVE-2005-0061" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx" source="MS" patch="1">MS05-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4593" source="OVAL" sig="1">oval:org.mitre.oval:def:4593</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3994" source="OVAL" sig="1">oval:org.mitre.oval:def:3994</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1761" source="OVAL" sig="1">oval:org.mitre.oval:def:1761</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1656" source="OVAL" sig="1">oval:org.mitre.oval:def:1656</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0063" published="2005-05-02" name="CVE-2005-0063" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-016.mspx" source="MS" patch="1">MS05-016</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=231&amp;type=vulnerabilities" source="IDEFENSE" patch="1">20050412 Microsoft MSHTA Script Execution Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0335" source="VUPEN">ADV-2005-0335</ref>
      <ref url="http://www.securiteam.com/exploits/5YP0T0AFFW.html" source="MISC">http://www.securiteam.com/exploits/5YP0T0AFFW.html</ref>
      <ref url="http://www.securityfocus.com/bid/13132" source="BID">13132</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755356016155&amp;w=2" source="BUGTRAQ">20050529 Spam exploiting MS05-016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:587" source="OVAL" sig="1">oval:org.mitre.oval:def:587</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:573" source="OVAL" sig="1">oval:org.mitre.oval:def:573</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4710" source="OVAL" sig="1">oval:org.mitre.oval:def:4710</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:407" source="OVAL" sig="1">oval:org.mitre.oval:def:407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3456" source="OVAL" sig="1">oval:org.mitre.oval:def:3456</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2184" source="OVAL" sig="1">oval:org.mitre.oval:def:2184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0064" published="2005-05-02" name="CVE-2005-0064" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2353" source="FEDORA" patch="1" adv="1">FLSA:2353</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2352" source="FEDORA" patch="1" adv="1">FLSA:2352</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-066.html" source="REDHAT" patch="1" adv="1">RHSA-2005:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-059.html" source="REDHAT" patch="1" adv="1">RHSA-2005:059</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-057.html" source="REDHAT" patch="1" adv="1">RHSA-2005:057</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT" patch="1" adv="1">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-034.html" source="REDHAT" patch="1" adv="1">RHSA-2005:034</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=186&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050118 Multiple Unix/Linux Vendor Xpdf makeFileKey2 Stack Overflow</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-28.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-10</ref>
      <ref url="http://www.debian.org/security/2005/dsa-648" source="DEBIAN" patch="1" adv="1">DSA-648</ref>
      <ref url="http://www.debian.org/security/2005/dsa-645" source="DEBIAN" patch="1" adv="1">DSA-645</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110625368019554&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 [USN-64-1] xpdf, CUPS vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000921" source="CONECTIVA" patch="1" adv="1">CLA-2005:921</ref>
      <ref url="ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch" source="CONFIRM" patch="1">ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-026.html" source="REDHAT">RHSA-2005:026</ref>
      <ref url="http://secunia.com/advisories/17277" source="SECUNIA">17277</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11781" source="OVAL">oval:org.mitre.oval:def:11781</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt" source="SCO">SCOSA-2005.42</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:021" source="MANDRAKE">MDKSA-2005:021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:020" source="MANDRAKE">MDKSA-2005:020</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:019" source="MANDRAKE">MDKSA-2005:019</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:018" source="MANDRAKE">MDKSA-2005:018</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:017" source="MANDRAKE">MDKSA-2005:017</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:016" source="MANDRAKE">MDKSA-2005:016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.0" />
        <vers num="1.0a" />
        <vers num="1.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0065" published="2005-05-02" name="CVE-2005-0065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The original design of TCP does not check that the TCP sequence number in an ICMP error message is within the range of sequence numbers for data that has been sent but not acknowledged (aka "TCP sequence number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0066" published="2004-12-22" name="CVE-2005-0066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0067" published="2004-12-22" name="CVE-2005-0067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0068" published="2004-12-22" name="CVE-2005-0068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0069" published="2005-01-13" name="CVE-2005-0069" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18870" source="XF" patch="1" adv="1">vim-symlink(18870)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-122.html" source="REDHAT" patch="1" adv="1">RHSA-2005:122</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-036.html" source="REDHAT" patch="1" adv="1">RHSA-2005:036</ref>
      <ref url="http://secunia.com/advisories/13841/" source="SECUNIA" patch="1" adv="1">13841</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608387001863&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050118 [USN-61-1] vim vulnerabilities</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2343" source="FEDORA" adv="1">FLSA:2343</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9402" source="OVAL">oval:org.mitre.oval:def:9402</ref>
      <ref url="http://securitytracker.com/id?1012938" source="SECTRACK">1012938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vim_development_group" name="vim">
        <vers num="6.3.011" />
        <vers num="6.3.025" />
        <vers num="6.3.030" />
        <vers num="6.3.044" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0070" published="2005-05-02" name="CVE-2005-0070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-681" source="DEBIAN" patch="1" adv="1">DSA-681</ref>
      <ref url="http://www.securityfocus.com/bid/12546" source="BID">12546</ref>
      <ref url="http://securitytracker.com/id?1013206" source="SECTRACK">1013206</ref>
      <ref url="http://secunia.com/advisories/14300" source="SECUNIA">14300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="synaesthesia" name="synaesthesia">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0071" published="2005-05-02" name="CVE-2005-0071" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vdr before 1.2.6 does not securely create files, which allows attackers to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19066" source="XF">vdr-dvdapi-file-overwrite(19066)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-42.xml" source="GENTOO">GLSA-200501-42</ref>
      <ref url="http://www.debian.org/security/2005/dsa-656" source="DEBIAN">DSA-656</ref>
      <ref url="http://www.securityfocus.com/bid/12356" source="BID">12356</ref>
      <ref url="http://secunia.com/advisories/14066" source="SECUNIA">14066</ref>
      <ref url="http://secunia.com/advisories/13995" source="SECUNIA">13995</ref>
      <ref url="http://secunia.com/advisories/13930" source="SECUNIA">13930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vdr" name="vdr">
        <vers num="1.0.0" />
        <vers num="1.0.4" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0072" published="2005-01-24" name="CVE-2005-0072" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-655" source="DEBIAN" patch="1" adv="1">DSA-655</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19045" source="XF" adv="1">zhcon-information-disclosure(19045)</ref>
      <ref url="http://www.securityfocus.com/bid/12343" source="BID">12343</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012" source="MANDRAKE">MDKSA-2005:012</ref>
      <ref url="http://securitytracker.com/id?1012977" source="SECTRACK">1012977</ref>
      <ref url="http://secunia.com/advisories/13987" source="SECUNIA">13987</ref>
      <ref url="http://secunia.com/advisories/13982" source="SECUNIA">13982</ref>
      <ref url="http://secunia.com/advisories/13977" source="SECUNIA">13977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ejoy_and_hu_yong" name="zhcon">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0073" published="2005-05-02" name="CVE-2005-0073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-677" source="DEBIAN" patch="1" adv="1">DSA-677</ref>
      <ref url="http://securitytracker.com/id?1013163" source="SECTRACK">1013163</ref>
      <ref url="http://secunia.com/advisories/14224" source="SECUNIA">14224</ref>
      <ref url="http://secunia.com/advisories/14217" source="SECUNIA">14217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="sympa">
        <vers num="3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0074" published="2005-02-11" name="CVE-2005-0074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-676" source="DEBIAN" patch="1" adv="1">DSA-676</ref>
      <ref url="http://www.securityfocus.com/bid/12523" source="BID">12523</ref>
      <ref url="http://securitytracker.com/id?1013162" source="SECTRACK">1013162</ref>
      <ref url="http://secunia.com/advisories/14250" source="SECUNIA">14250</ref>
      <ref url="http://secunia.com/advisories/14248" source="SECUNIA">14248</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpcd" name="xpcd">
        <vers num="2.08" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0075" published="2005-01-29" name="CVE-2005-0075" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2005-01-14" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2005-01-14</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-135.html" source="REDHAT" patch="1" adv="1">RHSA-2005:135</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-099.html" source="REDHAT" patch="1" adv="1">RHSA-2005:099</ref>
      <ref url="http://secunia.com/advisories/13962/" source="SECUNIA" patch="1" adv="1">13962</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9587" source="OVAL">oval:org.mitre.oval:def:9587</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" source="BUGTRAQ" adv="1">20050129 SquirrelMail Security Advisory</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" source="GENTOO">GLSA-200501-39</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0076" published="2005-05-02" name="CVE-2005-0076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19271" source="XF">xview-xvparseone-bo(19271)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-672" source="DEBIAN">DSA-672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0077" published="2005-05-02" name="CVE-2005-0077" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19068" source="XF" patch="1" adv="1">dbi-library-file-overwrite(19068)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-072.html" source="REDHAT" patch="1" adv="1">RHSA-2005:072</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-38</ref>
      <ref url="http://www.debian.org/security/2005/dsa-658" source="DEBIAN" patch="1" adv="1">DSA-658</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667936707597&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050125 [USN-70-1] Perl DBI module vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10552" source="OVAL">oval:org.mitre.oval:def:10552</ref>
      <ref url="http://www.securityfocus.com/bid/12360" source="BID">12360</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426530/30/6600/threaded" source="FEDORA">FLSA-2006:178989</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:030" source="MANDRAKE">MDKSA-2005:030</ref>
      <ref url="http://securitytracker.com/id?1013007" source="SECTRACK">1013007</ref>
      <ref url="http://secunia.com/advisories/14050" source="SECUNIA">14050</ref>
      <ref url="http://secunia.com/advisories/14015" source="SECUNIA">14015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":woody" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0078" published="2005-05-02" name="CVE-2005-0078" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19084" source="XF" patch="1" adv="1">kdebase-screensaver-security-bypass(19084)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-009.html" source="REDHAT" patch="1" adv="1">RHSA-2005:009</ref>
      <ref url="http://www.debian.org/security/2005/dsa-660" source="DEBIAN" patch="1" adv="1">DSA-660</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9260" source="OVAL">oval:org.mitre.oval:def:9260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":woody" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
        <vers num="2.1_beta1" />
        <vers num="2.1_beta2" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2_beta1" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0_beta_1" />
        <vers num="3.0_beta_2" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0079" published="2005-05-02" name="CVE-2005-0079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xtrlock 2.0 allows local users to cause a denial of service (application crash) and hijack the desktop session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-649" source="DEBIAN" patch="1">DSA-649</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18991" source="XF">xtrlock-screen-lock-bypass(18991)</ref>
      <ref url="http://www.securityfocus.com/bid/12316" source="BID">12316</ref>
      <ref url="http://secunia.com/advisories/13938" source="SECUNIA">13938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xtrlock" name="xtrlock">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0080" published="2005-05-02" name="CVE-2005-0080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2" source="BUGTRAQ" patch="1">20050110 [USN-59-1] mailman vulnerabilities</ref>
      <ref url="http://qa.debian.org/bts-security.html" source="MISC">http://qa.debian.org/bts-security.html</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1.5" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0081" published="2005-04-14" name="CVE-2005-0081" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00" />
        <vers num="7.5.00.08" />
        <vers num="7.5.00.11" />
        <vers num="7.5.00.12" />
        <vers num="7.5.00.14" />
        <vers num="7.5.00.15" />
        <vers num="7.5.00.16" />
        <vers num="7.5.00.18" />
        <vers num="7.5.00.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0082" published="2005-04-14" name="CVE-2005-0082" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00" />
        <vers num="7.5.00.08" />
        <vers num="7.5.00.11" />
        <vers num="7.5.00.12" />
        <vers num="7.5.00.14" />
        <vers num="7.5.00.15" />
        <vers num="7.5.00.16" />
        <vers num="7.5.00.18" />
        <vers num="7.5.00.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0083" published="2005-05-02" name="CVE-2005-0083" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19687" source="XF" patch="1" adv="1">maxdb-null-pointer-dos(19687)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=218&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050314 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0084" published="2005-05-02" name="CVE-2005-0084" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8 allows remote attackers to execute arbitrary code via a crafted packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-27</ref>
      <ref url="http://www.debian.org/security/2005/dsa-653" source="DEBIAN" patch="1">DSA-653</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1">13946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19004" source="XF">ethereal-x11-bo(19004)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT">RHSA-2005:037</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9140" source="OVAL">oval:org.mitre.oval:def:9140</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.16" />
        <vers num="0.8.17a" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.8.20" />
        <vers num="0.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0085" published="2005-04-27" name="CVE-2005-0085" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12442" source="BID" patch="1" adv="1">12442</ref>
      <ref url="http://www.debian.org/security/2005/dsa-680" source="DEBIAN" patch="1" adv="1">DSA-680</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19223" source="XF">htdig-config-xss(19223)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-073.html" source="REDHAT">RHSA-2005:073</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml" source="GENTOO">GLSA-200502-16</ref>
      <ref url="http://securitytracker.com/id?1013078" source="SECTRACK">1013078</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10878" source="OVAL">oval:org.mitre.oval:def:10878</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-090.html" source="REDHAT">RHSA-2005:090</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html" source="FEDORA">FLSA-2006:152907</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:063" source="MANDRAKE">MDKSA-2005:063</ref>
      <ref url="http://secunia.com/advisories/17415" source="SECUNIA">17415</ref>
      <ref url="http://secunia.com/advisories/17414" source="SECUNIA">17414</ref>
      <ref url="http://secunia.com/advisories/15007" source="SECUNIA">15007</ref>
      <ref url="http://secunia.com/advisories/14795" source="SECUNIA">14795</ref>
      <ref url="http://secunia.com/advisories/14303" source="SECUNIA">14303</ref>
      <ref url="http://secunia.com/advisories/14276" source="SECUNIA">14276</ref>
      <ref url="http://secunia.com/advisories/14255" source="SECUNIA">14255</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt" source="SCO">SCOSA-2005.46</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htdig" name="htdig">
        <vers num="3.1.5" />
        <vers num="3.1.5_7" />
        <vers num="3.1.5_8" />
        <vers num="3.1.6" />
        <vers num="3.2.0" />
        <vers num="3.2.0b2" />
        <vers num="3.2.0b3" />
        <vers num="3.2.0b4" />
        <vers num="3.2.0b5" />
        <vers num="3.2.0b6" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0086" published="2005-05-02" name="CVE-2005-0086" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2404" source="FEDORA">FLSA:2404</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19131" source="XF">less-file-bo(19131)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-068.html" source="REDHAT" adv="1">RHSA-2005:068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11027" source="OVAL">oval:org.mitre.oval:def:11027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0087" published="2005-04-27" name="CVE-2005-0087" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-033.html" source="REDHAT" patch="1" adv="1">RHSA-2005:033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10355" source="OVAL">oval:org.mitre.oval:def:10355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alsa" name="alsa-lib">
        <vers num="1.0.6" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":desktop" />
        <vers num="4.0" edition=":workstation" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0088" published="2005-05-02" name="CVE-2005-0088" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/356409" source="CERT-VN">VU#356409</ref>
      <ref url="http://www.debian.org/security/2005/dsa-689" source="DEBIAN" patch="1">DSA-689</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-14.xml" source="GENTOO" patch="1">GLSA-200502-14</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX">2005-0003</ref>
      <ref url="http://www.securityfocus.com/bid/12519" source="BID">12519</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430286/100/0/threaded" source="FEDORA">FLSA:152896</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-104.html" source="REDHAT">RHSA-2005:104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-100.html" source="REDHAT">RHSA-2005:100</ref>
      <ref url="http://securitytracker.com/id?1013156" source="SECTRACK">1013156</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10617" source="OVAL">oval:org.mitre.oval:def:10617</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815313218389&amp;w=2" source="BUGTRAQ">20050211 [USN-80-1] mod_python vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000926" source="CONECTIVA">CLA-2005:926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_python">
        <vers num="1.9a" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.4.1" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.7" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.7.3" />
        <vers num="2.7.4" />
        <vers num="2.7.5" />
        <vers num="2.7.6" />
        <vers num="2.7.7" />
        <vers prev="1" num="2.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0089" published="2005-05-02" name="CVE-2005-0089" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.python.org/security/PSF-2005-001/" source="CONFIRM" patch="1">http://www.python.org/security/PSF-2005-001/</ref>
      <ref url="http://www.debian.org/security/2005/dsa-666" source="DEBIAN" patch="1">DSA-666</ref>
      <ref url="http://python.org/security/PSF-2005-001/patch-2.2.txt" source="CONFIRM" patch="1">http://python.org/security/PSF-2005-001/patch-2.2.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746469728728&amp;w=2" source="BUGTRAQ" patch="1">20050203 Python Security Advisory PSF-2005-001 - SimpleXMLRPCServer.py</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19217" source="XF">python-simplexmlrpcserver-bypass(19217)</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX">2005-0003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-108.html" source="REDHAT">RHSA-2005:108</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9811" source="OVAL">oval:org.mitre.oval:def:9811</ref>
      <ref url="http://www.securityfocus.com/bid/12437" source="BID">12437</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:035" source="MANDRAKE">MDKSA-2005:035</ref>
      <ref url="http://securitytracker.com/id?1013083" source="SECTRACK">1013083</ref>
      <ref url="http://secunia.com/advisories/14128" source="SECUNIA">14128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python_software_foundation" name="python">
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0090" published="2005-05-02" name="CVE-2005-0090" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an "access check," which allows local users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20618" source="XF">red-hat-regression-dos(20618)</ref>
      <ref url="http://www.securityfocus.com/bid/12599" source="BID" adv="1">12599</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10425" source="OVAL">oval:org.mitre.oval:def:10425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0091" published="2005-05-02" name="CVE-2005-0091" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20619" source="XF">red-hat-patch-gain-privileges(20619)</ref>
      <ref url="http://www.securityfocus.com/bid/12599" source="BID">12599</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" adv="1">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11249" source="OVAL">oval:org.mitre.oval:def:11249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0092" published="2005-02-19" name="CVE-2005-0092" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12599" source="BID" patch="1" adv="1">12599</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20620" source="XF">red-hat-patch-dos(20620)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11647" source="OVAL">oval:org.mitre.oval:def:11647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0093" reject="1" published="2005-05-02" name="CVE-2005-0093" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0094" published="2005-01-15" name="CVE-2005-0094" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.debian.org/security/2005/dsa-651" source="DEBIAN" patch="1" adv="1">DSA-651</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-25</ref>
      <ref url="http://secunia.com/advisories/13825" source="SECUNIA" patch="1" adv="1">13825</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" adv="1">2005-0003</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2005_1.txt" source="CONFIRM" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_1.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11146" source="OVAL">oval:org.mitre.oval:def:11146</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" adv="1">CLA-2005:923</ref>
      <ref url="http://www.securityfocus.com/bid/12276" source="BID">12276</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014" source="MANDRAKE">MDKSA-2005:014</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2" />
        <vers num="2.1_patch2" />
        <vers num="2.3_.stable4" />
        <vers num="2.3_.stable5" />
        <vers num="2.3_stable5" />
        <vers num="2.4" />
        <vers num="2.4_.stable2" />
        <vers num="2.4_.stable6" />
        <vers num="2.4_.stable7" />
        <vers num="2.4_stable7" />
        <vers num="2.5.6" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
        <vers num="2.5_stable9" />
        <vers num="2.6.stable1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0095" published="2005-01-15" name="CVE-2005-0095" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2005_2.txt" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_2.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://www.debian.org/security/2005/dsa-651" source="DEBIAN" patch="1" adv="1">DSA-651</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-25</ref>
      <ref url="http://secunia.com/advisories/13825" source="SECUNIA" patch="1" adv="1">13825</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" patch="1" adv="1">CLA-2005:923</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10269" source="OVAL">oval:org.mitre.oval:def:10269</ref>
      <ref url="http://www.securityfocus.com/bid/12275" source="BID">12275</ref>
      <ref url="http://www.osvdb.org/12886" source="OSVDB">12886</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014" source="MANDRAKE">MDKSA-2005:014</ref>
      <ref url="http://securitytracker.com/id?1012882" source="SECTRACK">1012882</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2" />
        <vers num="2.1_patch2" />
        <vers num="2.3_.stable4" />
        <vers num="2.3_.stable5" />
        <vers num="2.3_stable5" />
        <vers num="2.4" />
        <vers num="2.4_.stable2" />
        <vers num="2.4_.stable6" />
        <vers num="2.4_.stable7" />
        <vers num="2.4_stable7" />
        <vers num="2.5.6" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
        <vers num="2.5_stable9" />
        <vers num="2.6.stable1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0096" published="2005-01-25" name="CVE-2005-0096" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-25</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" patch="1" adv="1">CLA-2005:923</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" adv="1">2005-0003</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10233" source="OVAL">oval:org.mitre.oval:def:10233</ref>
      <ref url="http://www.securityfocus.com/bid/12324" source="BID">12324</ref>
      <ref url="http://securitytracker.com/id?1012818" source="SECTRACK">1012818</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2" />
        <vers num="2.1_patch2" />
        <vers num="2.3_.stable4" />
        <vers num="2.3_.stable5" />
        <vers num="2.3_stable5" />
        <vers num="2.4" />
        <vers num="2.4_.stable2" />
        <vers num="2.4_.stable6" />
        <vers num="2.4_.stable7" />
        <vers num="2.4_stable7" />
        <vers num="2.5.6" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
        <vers num="2.5_stable9" />
        <vers num="2.6.stable1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0097" published="2005-01-11" name="CVE-2005-0097" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-25</ref>
      <ref url="http://secunia.com/advisories/13789" source="SECUNIA" patch="1" adv="1">13789</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11646" source="OVAL">oval:org.mitre.oval:def:11646</ref>
      <ref url="http://www.securityfocus.com/bid/12220" source="BID">12220</ref>
      <ref url="http://securitytracker.com/id?1012818" source="SECTRACK">1012818</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2" />
        <vers num="2.1_patch2" />
        <vers num="2.3_.stable4" />
        <vers num="2.3_.stable5" />
        <vers num="2.3_stable5" />
        <vers num="2.4" />
        <vers num="2.4_.stable2" />
        <vers num="2.4_.stable6" />
        <vers num="2.4_.stable7" />
        <vers num="2.4_stable7" />
        <vers num="2.5.6" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
        <vers num="2.5_stable9" />
        <vers num="2.6.stable1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0098" published="2005-03-08" name="CVE-2005-0098" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-691" source="DEBIAN" patch="1" adv="1">DSA-691</ref>
      <ref url="http://secunia.com/advisories/14495" source="SECUNIA" adv="1">14495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abuse" name="abuse-sdl">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0099" published="2005-03-08" name="CVE-2005-0099" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-691" source="DEBIAN" patch="1" adv="1">DSA-691</ref>
      <ref url="http://secunia.com/advisories/14495" source="SECUNIA" patch="1" adv="1">14495</ref>
      <ref url="http://www.osvdb.org/14610" source="OSVDB">14610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abuse" name="abuse-sdl">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0100" published="2005-02-07" name="CVE-2005-0100" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19246" source="XF" patch="1" adv="1">xemacs-movemail-format-string(19246)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-133.html" source="REDHAT" patch="1" adv="1">RHSA-2005:133</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-112.html" source="REDHAT" patch="1" adv="1">RHSA-2005:112</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-110.html" source="REDHAT" patch="1" adv="1">RHSA-2005:110</ref>
      <ref url="http://www.debian.org/security/2005/dsa-685" source="DEBIAN" patch="1" adv="1">DSA-685</ref>
      <ref url="http://www.debian.org/security/2005/dsa-671" source="DEBIAN" patch="1" adv="1">DSA-671</ref>
      <ref url="http://www.debian.org/security/2005/dsa-670" source="DEBIAN" patch="1" adv="1">DSA-670</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9408" source="OVAL">oval:org.mitre.oval:def:9408</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780416112719&amp;w=2" source="BUGTRAQ" adv="1">20050207 [USN-76-1] Emacs vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12462" source="BID">12462</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433928/30/5010/threaded" source="FEDORA">FLSA-2006:152898</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:038" source="MANDRAKE">MDKSA-2005:038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="emacs">
        <vers prev="1" num="20.0" />
        <vers num="21.3" />
      </prod>
      <prod vendor="gnu" name="xemacs">
        <vers prev="1" num="21.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0101" published="2005-02-01" name="CVE-2005-0101" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19178" source="XF">newspost-socketgetline-bo(19178)</ref>
      <ref url="http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html</ref>
      <ref url="http://secunia.com/advisories/14092/" source="SECUNIA" adv="1">14092</ref>
      <ref url="http://people.freebsd.org/~niels/issues/newspost-20050114.txt" source="MISC" adv="1">http://people.freebsd.org/~niels/issues/newspost-20050114.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746336728781&amp;w=2" source="BUGTRAQ" adv="1">20050202 RE: SECURITEY.NNOV.RU NewsPost buffer overflow [EXPLOIT]</ref>
      <ref url="http://www.securityfocus.com/bid/12418" source="BID">12418</ref>
      <ref url="http://securitytracker.com/id?1013056" source="SECTRACK">1013056</ref>
      <ref url="http://secunia.com/advisories/14098" source="SECUNIA">14098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newspost" name="newspost">
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0102" published="2005-01-24" name="CVE-2005-0102" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19031" source="XF" patch="1" adv="1">evolution-camellockhelper-bo(19031)</ref>
      <ref url="http://www.securityfocus.com/bid/12354" source="BID" patch="1" adv="1">12354</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-397.html" source="REDHAT" patch="1" adv="1">RHSA-2005:397</ref>
      <ref url="http://www.debian.org/security/2005/dsa-673" source="DEBIAN" patch="1" adv="1">DSA-673</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-35.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-35</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000925" source="CONECTIVA" patch="1" adv="1">CLA-2005:925</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-238.html" source="REDHAT">RHSA-2005:238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9616" source="OVAL">oval:org.mitre.oval:def:9616</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-69-1" source="UBUNTU">USN-69-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:024" source="MANDRAKE">MDKSA-2005:024</ref>
      <ref url="http://securitytracker.com/id?1012981" source="SECTRACK">1012981</ref>
      <ref url="http://secunia.com/advisories/13830" source="SECUNIA">13830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.3.2_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0103" published="2005-01-24" name="CVE-2005-0103" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-135.html" source="REDHAT" patch="1" adv="1">RHSA-2005:135</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-099.html" source="REDHAT" patch="1" adv="1">RHSA-2005:099</ref>
      <ref url="http://secunia.com/advisories/13962/" source="SECUNIA" patch="1" adv="1">13962</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19037" source="XF">squirrelmail-frame-file-include(19037)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" source="GENTOO">GLSA-200501-39</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10670" source="OVAL">oval:org.mitre.oval:def:10670</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" source="BUGTRAQ" adv="1">20050129 SquirrelMail Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0104" published="2005-01-29" name="CVE-2005-0104" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2005-01-20" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2005-01-20</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-135.html" source="REDHAT" patch="1" adv="1">RHSA-2005:135</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-099.html" source="REDHAT" patch="1" adv="1">RHSA-2005:099</ref>
      <ref url="http://www.debian.org/security/2005/dsa-662" source="DEBIAN" patch="1" adv="1">DSA-662</ref>
      <ref url="http://secunia.com/advisories/14096" source="SECUNIA" patch="1" adv="1">14096</ref>
      <ref url="http://secunia.com/advisories/13962/" source="SECUNIA" patch="1" adv="1">13962</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050129 SquirrelMail Security Advisory</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10568" source="OVAL">oval:org.mitre.oval:def:10568</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19036" source="XF">squirrelmail-webmailphp-xss(19036)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" source="GENTOO">GLSA-200501-39</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
        <vers num="1.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0105" published="2005-02-16" name="CVE-2005-0105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-684" source="DEBIAN" patch="1" adv="1">DSA-684</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typespeed" name="typespeed">
        <vers num="0.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0106" published="2005-05-03" name="CVE-2005-0106" modified="2009-11-13" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-113-1" source="UBUNTU" patch="1">USN-113-1</ref>
      <ref url="http://www.securityfocus.com/bid/13471" source="BID">13471</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:023" source="MANDRIVA">MDKSA-2006:023</ref>
      <ref url="http://secunia.com/advisories/18639" source="SECUNIA">18639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="5.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0107" published="2005-02-25" name="CVE-2005-0107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-690" source="DEBIAN" patch="1" adv="1">DSA-690</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="bsmtpd">
        <vers prev="1" num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0108" published="2005-01-11" name="CVE-2005-0108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18841" source="XF" adv="1">modauthradius-dos(18841)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-659" source="DEBIAN" adv="1">DSA-659</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02" source="MISC" adv="1">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548193312050&amp;w=2" source="BUGTRAQ" adv="1">20050111 Apache mod_auth_radius remote integer overflow</ref>
      <ref url="http://www.securityfocus.com/bid/12217" source="BID">12217</ref>
      <ref url="http://securitytracker.com/id?1012829" source="SECTRACK">1012829</ref>
      <ref url="http://secunia.com/advisories/14046" source="SECUNIA">14046</ref>
      <ref url="http://secunia.com/advisories/13773" source="SECUNIA">13773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_auth_radius">
        <vers num="1.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0109" published="2005-03-05" name="CVE-2005-0109" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/911878" source="CERT-VN" adv="1">VU#911878</ref>
      <ref url="http://www.securityfocus.com/bid/12724" source="BID" patch="1" adv="1">12724</ref>
      <ref url="http://securitytracker.com/id?1013967" source="SECTRACK" patch="1" adv="1">1013967</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/3002" source="VUPEN">ADV-2005-3002</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0540" source="VUPEN">ADV-2005-0540</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-800.html" source="REDHAT">RHSA-2005:800</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-476.html" source="REDHAT">RHSA-2005:476</ref>
      <ref url="http://www.daemonology.net/papers/htt.pdf" source="MISC">http://www.daemonology.net/papers/htt.pdf</ref>
      <ref url="http://www.daemonology.net/hyperthreading-considered-harmful/" source="MISC">http://www.daemonology.net/hyperthreading-considered-harmful/</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754" source="MISC">http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1" source="SUNALERT" adv="1">101739</ref>
      <ref url="http://secunia.com/advisories/18165" source="SECUNIA">18165</ref>
      <ref url="http://secunia.com/advisories/15348" source="SECUNIA">15348</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9747" source="OVAL">oval:org.mitre.oval:def:9747</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-misc&amp;m=110995101417256&amp;w=2" source="MLIST">[openbsd-misc] 20050304 Re: FreeBSD hiding security stuff</ref>
      <ref url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=110994370429609&amp;w=2" source="MLIST">[freebsd-security] 20050304 [Fwd: Re: FW:FreeBSD hiding security stuff]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=freebsd-hackers&amp;m=110994026421858&amp;w=2" source="MLIST">[freebsd-hackers] 20050304 Re: FW:FreeBSD hiding security stuff</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txt" source="SCO">SCOSA-2005.24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
        <vers num="2.1.7.1" />
        <vers num="2.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" edition="releng" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" edition="stable" />
        <vers num="3.5.1" edition="release" />
        <vers num="3.5.1" edition="stable" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="release_p8" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="release_p3" />
        <vers num="4.11" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.7" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.3" />
        <vers num="7.1.3_up" />
        <vers num="7.1.4" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86" />
        <vers num="9.0" edition="x86_update_2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
        <vers num="5.04" edition="" />
        <vers num="5.04" edition=":i386" />
        <vers num="5.04" edition=":powerpc" />
        <vers num="5.04" edition=":amd64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0110" published="2005-01-14" name="CVE-2005-0110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110569119106172&amp;w=2" source="FULLDISC" adv="1">20050114 Internet Explorer (SP2) - Remote File Download</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0111" published="2005-01-13" name="CVE-2005-0111" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12265" source="BID">12265</ref>
      <ref url="http://securitytracker.com/id?1012893" source="SECTRACK">1012893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0112" published="2005-04-14" name="CVE-2005-0112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web-based administrative interface for 3Com OfficeConnect Wireless 11g Access Point (AP) 1.00.08, and possibly earlier versions before 1.03.07A, allows remote attackers to bypass authentication and obtain sensitive information by directly accessing the (1) config.bin (2) profile.wlp?PN=ggg or (3) event.logs URLs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18994" source="XF" patch="1" adv="1">3com-officeconnect-information-disclosure(18994)</ref>
      <ref url="http://www.securityfocus.com/bid/12322" source="BID" patch="1" adv="1">12322</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=188&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050120 3Com OfficeConnect Wireless 11g AP Information Disclosure Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1012958" source="SECTRACK">1012958</ref>
      <ref url="http://secunia.com/advisories/13942" source="SECUNIA">13942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3crwe454g72">
        <vers num="1.0.2" />
        <vers num="1.0.2.11" />
        <vers num="1.0.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0113" published="2005-01-14" name="CVE-2005-0113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18894" source="XF" adv="1">irix-inpview-gain-privileges(18894)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=182&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050113 SGI IRIX inpview Design Error Vulnerability</ref>
      <ref url="http://secunia.com/advisories/13858" source="SECUNIA" adv="1">13858</ref>
      <ref url="http://www.securityfocus.com/bid/12259" source="BID">12259</ref>
      <ref url="http://www.osvdb.org/12915" source="OSVDB">12915</ref>
      <ref url="http://securitytracker.com/id?1012894" source="SECTRACK">1012894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0114" published="2005-02-11" name="CVE-2005-0114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=199&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050211 ZoneAlarm 5.1 Invalid Pointer Dereference Vulnerability</ref>
      <ref url="http://download.zonelabs.com/bin/free/securityAlert/19.html" source="CONFIRM" patch="1" adv="1">http://download.zonelabs.com/bin/free/securityAlert/19.html</ref>
      <ref url="http://www.securityfocus.com/bid/12531" source="BID">12531</ref>
      <ref url="http://secunia.com/advisories/14256" source="SECUNIA">14256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="check_point_integrity_client">
        <vers num="4.5.122.000" />
        <vers prev="1" num="5.1.556.166" />
      </prod>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="5.5.062.011" />
      </prod>
      <prod vendor="zonelabs" name="zonealarm_wireless_security">
        <vers prev="1" num="5.5.080.000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0115" published="2005-01-24" name="CVE-2005-0115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19042" source="XF" patch="1" adv="1">database-ida-portable-executable-bo(19042)</ref>
      <ref url="http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html" source="CONFIRM" patch="1" adv="1">http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12353" source="BID">12353</ref>
      <ref url="http://securitytracker.com/id?1012975" source="SECTRACK">1012975</ref>
      <ref url="http://secunia.com/advisories/13980" source="SECUNIA">13980</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datarescue" name="ida">
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0116" published="2005-01-18" name="CVE-2005-0116" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/272296" source="CERT-VN" patch="1" adv="1">VU#272296</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=185&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20050117 AWStats Remote Command Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/13893/" source="SECUNIA" patch="1" adv="1">13893</ref>
      <ref url="http://awstats.sourceforge.net/docs/awstats_changelog.txt" source="CONFIRM" patch="1" adv="1">http://awstats.sourceforge.net/docs/awstats_changelog.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12298" source="BID">12298</ref>
      <ref url="http://www.osvdb.org/13002" source="OSVDB">13002</ref>
      <ref url="http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf" source="MISC">http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers prev="1" num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0117" published="2005-01-11" name="CVE-2005-0117" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784" source="MISC" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xshisen" name="xshisen">
        <vers prev="1" num="1.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0118" published="2005-05-02" name="CVE-2005-0118" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helvis" name="helvis">
        <vers prev="1" num="1.8h2_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0119" published="2005-05-02" name="CVE-2005-0119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html" source="CONFIRM">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helvis" name="helvis">
        <vers prev="1" num="1.8h2_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0120" published="2005-05-02" name="CVE-2005-0120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt" source="MISC" adv="1">http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0121" published="2005-05-02" name="CVE-2005-0121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19040" source="XF">golddig-long-username-bo(19040)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19039" source="XF">golddig-long-mapname-bo(19039)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_siegel" name="golddig">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0122" reject="1" published="2005-04-14" name="CVE-2005-0122" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0975.  Reason: This candidate is a duplicate of CVE-2005-0975.  Notes: All CVE users should reference CVE-2005-0975 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0124" published="2005-04-14" name="CVE-2005-0124" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://seclists.org/lists/linux-kernel/2005/Jan/2020.html" source="MLIST">[linux-kernel] 20050107 [PATCH 2.6.10-mm2] fs/coda Re: [Coverity] Untrusted user data in kernel</ref>
      <ref url="http://seclists.org/lists/linux-kernel/2005/Jan/2018.html" source="MLIST" adv="1">[linux-kernel] 20050107 [PATCH 2.4.29-pre3-bk4] fs/coda Re: [Coverity] Untrusted user data in kernel</ref>
      <ref url="http://seclists.org/lists/linux-kernel/2005/Jan/1089.html" source="MLIST">[linux-kernel] 20050105 Re: [Coverity] Untrusted user data in kernel</ref>
      <ref url="http://seclists.org/lists/linux-kernel/2004/Dec/3914.html" source="MLIST">[linux-kernel] 20041216 [Coverity] Untrusted user data in kernel</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11690" source="OVAL">oval:org.mitre.oval:def:11690</ref>
      <ref url="http://www.securityfocus.com/bid/14967" source="BID">14967</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded" source="FEDORA">FLSA:157459-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0191.html" source="REDHAT">RHSA-2006:0191</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://securitytracker.com/id?1013018" source="SECTRACK">1013018</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA">19374</ref>
      <ref url="http://secunia.com/advisories/18684" source="SECUNIA">18684</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" edition="pre3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0125" published="2005-05-02" name="CVE-2005-0125" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/678150" source="CERT-VN" patch="1" adv="1">VU#678150</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-01-25</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18981" source="XF" adv="1">macos-at-gain-privileges(18981)</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0127a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0127a].txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685027017411&amp;w=2" source="BUGTRAQ" adv="1">20050127 DMA[2005-0127a] - 'Apple OSX batch family poor use of setuid'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.4" />
        <vers num="10.3.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0126" published="2005-05-02" name="CVE-2005-0126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/980078" source="CERT-VN" patch="1" adv="1">VU#980078</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19083" source="XF" patch="1" adv="1">macos-icc-profile-bo(19083)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-01-25</ref>
      <ref url="http://www.securityfocus.com/bid/12367" source="BID">12367</ref>
      <ref url="http://securitytracker.com/id?1013000" source="SECTRACK">1013000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0127" published="2005-05-02" name="CVE-2005-0127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/464662" source="CERT-VN" patch="1" adv="1">VU#464662</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19085" source="XF" patch="1" adv="1">macos-ethernet-address-disclosure(19085)</ref>
      <ref url="http://secunia.com/advisories/14005" source="SECUNIA" patch="1" adv="1">14005</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-01-25</ref>
      <ref url="http://securitytracker.com/id?1013001" source="SECTRACK">1013001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0129" published="2005-04-14" name="CVE-2005-0129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19025" source="XF" adv="1">konversation-expansion-execute-code(19025)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" source="FULLDISC">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://www.securityfocus.com/bid/12312" source="BID">12312</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050121-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20050121-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" source="GENTOO">GLSA-200501-34</ref>
      <ref url="http://securitytracker.com/id?1012972" source="SECTRACK">1012972</ref>
      <ref url="http://secunia.com/advisories/13989" source="SECUNIA">13989</ref>
      <ref url="http://secunia.com/advisories/13919" source="SECUNIA">13919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berlios" name="konversation">
        <vers num="0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0130" published="2005-04-14" name="CVE-2005-0130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC sripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19008" source="XF" adv="1">konversation-perlscript-execute-code(19008)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" source="FULLDISC">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://www.securityfocus.com/bid/12312" source="BID">12312</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050121-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20050121-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" source="GENTOO">GLSA-200501-34</ref>
      <ref url="http://securitytracker.com/id?1012972" source="SECTRACK">1012972</ref>
      <ref url="http://secunia.com/advisories/13989" source="SECUNIA">13989</ref>
      <ref url="http://secunia.com/advisories/13919" source="SECUNIA">13919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berlios" name="konversation">
        <vers num="0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0131" published="2005-04-14" name="CVE-2005-0131" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19038" source="XF">konversation-nick-password-information-disclosure(19038)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" source="FULLDISC">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://www.securityfocus.com/bid/12312" source="BID">12312</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050121-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20050121-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" source="GENTOO">GLSA-200501-34</ref>
      <ref url="http://securitytracker.com/id?1012972" source="SECTRACK">1012972</ref>
      <ref url="http://secunia.com/advisories/13989" source="SECUNIA">13989</ref>
      <ref url="http://secunia.com/advisories/13919" source="SECUNIA">13919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berlios" name="konversation">
        <vers num="0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0133" published="2005-05-02" name="CVE-2005-0133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-46</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=300116" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=300116</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000928" source="CONECTIVA" patch="1" adv="1">CLA-2005:928</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025" source="MANDRAKE">MDKSA-2005:025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.80" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0134" published="2005-05-18" name="CVE-2005-0134" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The X server in SCO UnixWare 7.1.1, 7.1.3, and 7.1.4 does not properly create socket directories in /tmp, which could allow attackers to hijack local sockets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.8/SCOSA-2005.8.txt" source="SCO" patch="1">SCOSA-2005.8</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0077" source="VUPEN">ADV-2005-0077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0135" published="2005-05-02" name="CVE-2005-0135" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT" patch="1" adv="1">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" patch="1" adv="1">RHSA-2005:284</ref>
      <ref url="http://secunia.com/advisories/15019" source="SECUNIA" patch="1" adv="1">15019</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9040" source="OVAL">oval:org.mitre.oval:def:9040</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg</ref>
      <ref url="http://www.securityfocus.com/bid/13266" source="BID">13266</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0136" published="2005-12-31" name="CVE-2005-0136" modified="2011-03-07" discovered="2005-09-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283" source="MISC" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862" source="MISC" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT" patch="1">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-420.html" source="REDHAT" patch="1">RHSA-2005:420</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11</ref>
      <ref url="http://www.gelato.unsw.edu.au/archives/linux-ia64/0409/11073.html" source="MLIST" patch="1">[linux-ia64] 20040916 Re: [Patch] Per CPU MCA/INIT data save areas</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA" patch="1" adv="1">17002</ref>
      <ref url="http://openvz.org/news/updates/kernel-022stab045.1-released" source="MISC" patch="1">http://openvz.org/news/updates/kernel-022stab045.1-released</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11628" source="OVAL">oval:org.mitre.oval:def:11628</ref>
      <ref url="http://lists.alioth.debian.org/pipermail/kernel-svn-changes/2005-August/002597.html" source="MLIST">[kernel-svn-changes] 20050816 r3920 - in branches/dist/sarge-security: . kernel kernel/i386 kernel/source kernel/source/kernel-source-2.6.8-2.6.8/debian</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="final" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0137" published="2005-05-02" name="CVE-2005-0137" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT" patch="1" adv="1">RHSA-2005:293</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" patch="1" adv="1">RHSA-2005:284</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11039" source="OVAL">oval:org.mitre.oval:def:11039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0138" published="2005-09-21" name="CVE-2005-0138" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined.  NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/p-214.shtml" source="CIAC" adv="1">P-214</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0702" source="VUPEN">ADV-2005-0702</ref>
      <ref url="http://secunia.com/advisories/15619" source="SECUNIA">15619</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.25" />
        <vers num="6.5.26" />
        <vers num="6.5.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0139" published="2005-09-21" name="CVE-2005-0139" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/p-214.shtml" source="CIAC" adv="1">P-214</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0702" source="VUPEN">ADV-2005-0702</ref>
      <ref url="http://secunia.com/advisories/15619" source="SECUNIA">15619</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.25" />
        <vers num="6.5.26" />
        <vers num="6.5.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0140" published="2005-05-02" name="CVE-2005-0140" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PeID allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19042" source="XF" patch="1" adv="1">database-ida-portable-executable-bo(19042)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12355" source="BID">12355</ref>
      <ref url="http://secunia.com/advisories/13984" source="SECUNIA">13984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peid" name="peid">
        <vers num="0.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0141" published="2005-05-02" name="CVE-2005-0141" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19168" source="XF" patch="1" adv="1">mozilla-firefox-file-upload(19168)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=249332" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=249332</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-01.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10756" source="OVAL">oval:org.mitre.oval:def:10756</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100057" source="OVAL" sig="1">oval:org.mitre.oval:def:100057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0142" published="2005-05-02" name="CVE-2005-0142" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17832" source="XF" patch="1" adv="1">mozilla-world-readable(17832)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=251297" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=251297</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-02.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-02.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9543" source="OVAL">oval:org.mitre.oval:def:9543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100056" source="OVAL" sig="1">oval:org.mitre.oval:def:100056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.9" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0143" published="2005-03-23" name="CVE-2005-0143" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=257308" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=257308</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19166" source="XF" patch="1" adv="1">mozilla-ssl-spoofing(19166)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-03.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-03.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11297" source="OVAL">oval:org.mitre.oval:def:11297</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100055" source="OVAL" sig="1">oval:org.mitre.oval:def:100055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.8" edition="alpha2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0144" published="2005-05-02" name="CVE-2005-0144" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19169" source="XF" patch="1" adv="1">mozilla-ssl-view-source-spoofing(19169)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=262689" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=262689</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-04.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-04.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11016" source="OVAL">oval:org.mitre.oval:def:11016</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100054" source="OVAL" sig="1">oval:org.mitre.oval:def:100054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0145" published="2005-01-24" name="CVE-2005-0145" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=265176" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=265176</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19170" source="XF" patch="1" adv="1">mozilla-script-click-event-bypass(19170)</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-07.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-07.html</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100051" source="OVAL" sig="1">oval:org.mitre.oval:def:100051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0146" published="2005-05-02" name="CVE-2005-0146" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=265728" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=265728</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19171" source="XF">mozilla-middle-click-information-disclosure(19171)</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-08.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-08.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10362" source="OVAL">oval:org.mitre.oval:def:10362</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0147" published="2005-05-02" name="CVE-2005-0147" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19174" source="XF" patch="1" adv="1">mozilla-407-proxy-obtain-information(19174)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=267263" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=267263</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-09.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-09.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9578" source="OVAL">oval:org.mitre.oval:def:9578</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100049" source="OVAL" sig="1">oval:org.mitre.oval:def:100049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0148" published="2005-05-02" name="CVE-2005-0148" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system.  NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19173" source="XF" patch="1" adv="1">thunderbird-javascript-handler-launch(19173)</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=263546" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=263546</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-10.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-10.html</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100048" source="OVAL" sig="1">oval:org.mitre.oval:def:100048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0149" published="2005-02-15" name="CVE-2005-0149" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=268107" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=268107</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19172" source="XF" patch="1" adv="1">mozilla-cookie-policy-bypass(19172)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-094.html" source="REDHAT" patch="1" adv="1">RHSA-2005:094</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-11.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-11.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11407" source="OVAL">oval:org.mitre.oval:def:11407</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100047" source="OVAL" sig="1">oval:org.mitre.oval:def:100047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0150" published="2005-05-26" name="CVE-2005-0150" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=265668" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=265668</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19187" source="XF" patch="1" adv="1">mozilla-firefox-livefeed-xss(19187)</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-12.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-12.html</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100046" source="OVAL" sig="1">oval:org.mitre.oval:def:100046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0151" published="2005-06-13" name="CVE-2005-0151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/331688.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/331688.html</ref>
      <ref url="http://securitytracker.com/id?1014170" source="SECTRACK">1014170</ref>
      <ref url="http://securitytracker.com/id?1014169" source="SECTRACK">1014169</ref>
      <ref url="http://securitytracker.com/id?1014168" source="SECTRACK">1014168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="creative_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="adobe" name="photoshop">
        <vers num="8.0" />
      </prod>
      <prod vendor="adobe" name="premiere">
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0152" published="2005-02-02" name="CVE-2005-0152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/203214" source="CERT-VN" patch="1" adv="1">VU#203214</ref>
      <ref url="http://www.debian.org/security/2005/dsa-662" source="DEBIAN" patch="1" adv="1">DSA-662</ref>
      <ref url="http://secunia.com/advisories/14096" source="SECUNIA" patch="1" adv="1">14096</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0155" published="2005-05-02" name="CVE-2005-0155" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19207" source="XF" patch="1" adv="1">perl-perliodebug-file-overwrite(19207)</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1">2005-0003</ref>
      <ref url="http://www.securityfocus.com/bid/12426" source="BID" patch="1" adv="1">12426</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-105.html" source="REDHAT" patch="1" adv="1">RHSA-2005:105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-103.html" source="REDHAT" patch="1" adv="1">RHSA-2005:103</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-13</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779723332339&amp;w=2" source="FULLDISC" patch="1" adv="1">20050207 DMA[2005-0131a] - 'Setuid Perl PERLIO_DEBUG root owned file creation'</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050202 [USN-72-1] Perl vulnerabilities</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0131a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0131a].txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10404" source="OVAL">oval:org.mitre.oval:def:10404</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031" source="MANDRAKE">MDKSA-2005:031</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm</ref>
      <ref url="http://secunia.com/advisories/21646" source="SECUNIA">21646</ref>
      <ref url="http://secunia.com/advisories/14120" source="SECUNIA">14120</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056" source="CONECTIVA">CLSA-2006:1056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0156" published="2005-02-07" name="CVE-2005-0156" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19208" source="XF" patch="1" adv="1">perl-perliodebug-bo(19208)</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.securityfocus.com/bid/12426" source="BID" patch="1" adv="1">12426</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-105.html" source="REDHAT" patch="1" adv="1">RHSA-2005:105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-103.html" source="REDHAT" patch="1" adv="1">RHSA-2005:103</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml" source="GENTOO" adv="1">GLSA-200502-13</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0131b].txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10803" source="OVAL">oval:org.mitre.oval:def:10803</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779721503111&amp;w=2" source="FULLDISC" adv="1">20050207 DMA[2005-0131b] - 'Setuid Perl PERLIO_DEBUG</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2" source="BUGTRAQ" adv="1">20050202 [USN-72-1] Perl vulnerabilities</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031" source="MANDRAKE">MDKSA-2005:031</ref>
      <ref url="http://secunia.com/advisories/14120" source="SECUNIA">14120</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056" source="CONECTIVA">CLSA-2006:1056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.8.0" />
        <vers num="5.8.1" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.4.1" />
        <vers num="5.8.4.2" />
        <vers num="5.8.4.2.3" />
        <vers num="5.8.4.3" />
        <vers num="5.8.4.4" />
        <vers num="5.8.4.5" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0157" published="2005-05-03" name="CVE-2005-0157" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-720" source="DEBIAN" patch="1">DSA-720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartlist" name="smartlist">
        <vers prev="1" num="3.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0158" published="2005-05-02" name="CVE-2005-0158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-06.xml" source="GENTOO" patch="1">GLSA-200503-06</ref>
      <ref url="http://www.debian.org/security/2005/dsa-687" source="DEBIAN" patch="1" adv="1">DSA-687</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bidwatcher" name="bidwatcher">
        <vers num="1.0.5" />
        <vers num="1.1.2" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9.1" />
        <vers num="1.1.9.2" />
        <vers num="1.2.0" />
        <vers num="1.3.0_beta" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0159" published="2005-04-27" name="CVE-2005-0159" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12540" source="BID" patch="1" adv="1">12540</ref>
      <ref url="http://www.debian.org/security/2005/dsa-679" source="DEBIAN" patch="1" adv="1">DSA-679</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19317" source="XF">toolchain-source-symlink(19317)</ref>
      <ref url="http://secunia.com/advisories/14277" source="SECUNIA">14277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="toolchain-source">
        <vers num="3.0.3-1" />
        <vers num="3.0.3-2" />
        <vers num="3.0.3-3" />
        <vers num="3.0.4" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0160" published="2005-02-22" name="CVE-2005-0160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/215006" source="CERT-VN">VU#215006</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_sr.html" source="SUSE">SUSE-SR:2005:016</ref>
      <ref url="http://secunia.com/advisories/14359" source="SECUNIA" adv="1">14359</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html" source="FULLDISC" adv="1">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref>
      <ref url="http://www.securityfocus.com/bid/12630" source="BID">12630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-merge" name="unace">
        <vers num="1.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0161" published="2005-02-22" name="CVE-2005-0161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_sr.html" source="SUSE">SUSE-SR:2005:016</ref>
      <ref url="http://secunia.com/advisories/14359" source="SECUNIA" adv="1">14359</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html" source="FULLDISC" adv="1">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref>
      <ref url="http://www.securityfocus.com/bid/12628" source="BID">12628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-merge" name="unace">
        <vers num="1.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0162" published="2005-01-26" name="CVE-2005-0162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19078" source="XF" patch="1" adv="1">openswan-xauth-pam-bo(19078)</ref>
      <ref url="http://www.openswan.org/support/vuln/IDEF0785/" source="CONFIRM" patch="1" adv="1">http://www.openswan.org/support/vuln/IDEF0785/</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=190&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050126 Openswan XAUTH/PAM Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12377" source="BID">12377</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00103.html" source="FEDORA">FEDORA-2005-082</ref>
      <ref url="http://www.osvdb.org/13195" source="OSVDB">13195</ref>
      <ref url="http://securitytracker.com/id?1013014" source="SECTRACK">1013014</ref>
      <ref url="http://secunia.com/advisories/14062" source="SECUNIA">14062</ref>
      <ref url="http://secunia.com/advisories/14038" source="SECUNIA">14038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openswan" name="openswan">
        <vers prev="1" num="1.0.9" />
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0173" published="2005-05-02" name="CVE-2005-0173" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/924198" source="CERT-VN" patch="1" adv="1">VU#924198</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://www.debian.org/security/2005/dsa-667" source="DEBIAN" patch="1" adv="1">DSA-667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" patch="1">CLA-2005:923</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1187" source="CONFIRM">http://www.squid-cache.org/bugs/show_bug.cgi?id=1187</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10251" source="OVAL">oval:org.mitre.oval:def:10251</ref>
      <ref url="http://www.securityfocus.com/bid/12431" source="BID">12431</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" source="MANDRAKE">MDKSA-2005:034</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0.patch1" />
        <vers num="2.0.patch2" />
        <vers num="2.0.pre1" />
        <vers num="2.0.release" />
        <vers num="2.1.patch1" />
        <vers num="2.1.patch2" />
        <vers num="2.1.pre1" />
        <vers num="2.1.pre3" />
        <vers num="2.1.pre4" />
        <vers num="2.1.release" />
        <vers num="2.2.devel3" />
        <vers num="2.2.devel4" />
        <vers num="2.2.pre1" />
        <vers num="2.2.pre2" />
        <vers num="2.2.stable1" />
        <vers num="2.2.stable2" />
        <vers num="2.2.stable3" />
        <vers num="2.2.stable4" />
        <vers num="2.2.stable5" />
        <vers num="2.3.devel2" />
        <vers num="2.3.devel3" />
        <vers num="2.3.stable1" />
        <vers num="2.3.stable2" />
        <vers num="2.3.stable3" />
        <vers num="2.3.stable4" />
        <vers num="2.3.stable5" />
        <vers num="2.4.stable1" />
        <vers num="2.4.stable2" />
        <vers num="2.4.stable3" />
        <vers num="2.4.stable4" />
        <vers num="2.4.stable6" />
        <vers num="2.4.stable7" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0174" published="2005-02-07" name="CVE-2005-0174" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/768702" source="CERT-VN" adv="1">VU#768702</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1">RHSA-2005:060</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html" source="FEDORA">FEDORA-2005-373</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10656" source="OVAL">oval:org.mitre.oval:def:10656</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" source="BUGTRAQ" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" adv="1">CLA-2005:931</ref>
      <ref url="http://www.securityfocus.com/bid/12412" source="BID">12412</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" source="MANDRAKE">MDKSA-2005:034</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.6" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
        <vers num="2.5_stable9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0175" published="2005-02-07" name="CVE-2005-0175" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/625878" source="CERT-VN" patch="1" adv="1">VU#625878</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://www.debian.org/security/2005/dsa-667" source="DEBIAN" patch="1" adv="1">DSA-667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" patch="1" adv="1">CLA-2005:931</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2005_5.txt" source="CONFIRM" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_5.txt</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html" source="FEDORA">FEDORA-2005-373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11605" source="OVAL">oval:org.mitre.oval:def:11605</ref>
      <ref url="http://www.securityfocus.com/bid/12433" source="BID">12433</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" source="MANDRAKE">MDKSA-2005:034</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.6" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
        <vers num="2.5_stable9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0176" published="2005-02-15" name="CVE-2005-0176" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" adv="1">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8778" source="OVAL">oval:org.mitre.oval:def:8778</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" source="BUGTRAQ" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-472.html" source="REDHAT">RHSA-2005:472</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1225" source="OVAL" sig="1">oval:org.mitre.oval:def:1225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0177" published="2005-03-07" name="CVE-2005-0177" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ" source="CONFIRM" patch="1" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" patch="1" adv="1">CLA-2005:930</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10298" source="OVAL">oval:org.mitre.oval:def:10298</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" source="BUGTRAQ" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0178" published="2005-03-07" name="CVE-2005-0178" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A" source="CONFIRM" patch="1" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10647" source="OVAL">oval:org.mitre.oval:def:10647</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" source="BUGTRAQ" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netkit" name="linux_netkit">
        <vers num="0.17" />
        <vers num="0.17.17" />
      </prod>
      <prod vendor="vserver" name="linux-vserver">
        <vers num="1.20" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.23" />
        <vers num="1.24" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.24" />
        <vers num="2.0.25" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
        <vers num="2.0.29" />
        <vers num="2.0.3" />
        <vers num="2.0.30" />
        <vers num="2.0.31" />
        <vers num="2.0.32" />
        <vers num="2.0.33" />
        <vers num="2.0.34" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.0.9.9" />
        <vers num="2.1" />
        <vers num="2.1.89" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.27" edition="rc2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.99" edition="pre1" />
        <vers num="2.3.99" edition="pre2" />
        <vers num="2.3.99" edition="pre3" />
        <vers num="2.3.99" edition="pre4" />
        <vers num="2.3.99" edition="pre5" />
        <vers num="2.3.99" edition="pre6" />
        <vers num="2.3.99" edition="pre7" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" edition="pre3" />
        <vers num="2.4.30" edition="rc2" />
        <vers num="2.4.30" edition="rc3" />
        <vers num="2.4.31" edition="pre1" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.20.1" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0179" published="2005-03-07" name="CVE-2005-0179" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9890" source="OVAL">oval:org.mitre.oval:def:9890</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" source="FULLDISC" adv="1">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" edition="pre3" />
        <vers num="2.4.30" edition="rc2" />
        <vers num="2.4.30" edition="rc3" />
        <vers num="2.4.31" edition="pre1" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0180" published="2005-03-07" name="CVE-2005-0180" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10667" source="OVAL">oval:org.mitre.oval:def:10667</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" source="FULLDISC" adv="1">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
      <ref url="http://www.securityfocus.com/bid/12198" source="BID">12198</ref>
      <ref url="http://www.securityfocus.com/archive/1/386374" source="BUGTRAQ">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" source="MANDRAKE">MDKSA-2005:218</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0182" published="2005-01-06" name="CVE-2005-0182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18765" source="XF" adv="1">moddosevasive-symlink(18765)</ref>
      <ref url="http://www.securityfocus.com/bid/12181" source="BID" adv="1">12181</ref>
      <ref url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01" source="MISC" adv="1">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547469530582&amp;w=2" source="BUGTRAQ" adv="1">20050111 Mod_dosevasive symlink and race vulnerability</ref>
      <ref url="http://secunia.com/advisories/13725" source="SECUNIA">13725</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_dosevasive" name="mod_dosevasive">
        <vers num="1.8" />
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0183" published="2005-05-02" name="CVE-2005-0183" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18855" source="XF" adv="1">vacation-ftpfile-command-execution(18855)</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03" source="MISC">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2" source="BUGTRAQ" adv="1">20050111 Squirrelmail vacation v0.15 local root exploit</ref>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=51" source="CONFIRM">http://www.squirrelmail.org/plugin_view.php?id=51</ref>
      <ref url="http://www.securityfocus.com/bid/12222" source="BID">12222</ref>
      <ref url="http://securitytracker.com/id?1012866" source="SECTRACK">1012866</ref>
      <ref url="http://secunia.com/advisories/13791" source="SECUNIA">13791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="vacation_plugin">
        <vers prev="1" num="0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0184" published="2005-05-02" name="CVE-2005-0184" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18856" source="XF" adv="1">vacation-ftpfile-directory-traversal(18856)</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03" source="MISC" adv="1">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2" source="BUGTRAQ" adv="1">20050111 Squirrelmail vacation v0.15 local root exploit</ref>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=51" source="CONFIRM">http://www.squirrelmail.org/plugin_view.php?id=51</ref>
      <ref url="http://www.securityfocus.com/bid/12222" source="BID">12222</ref>
      <ref url="http://securitytracker.com/id?1012866" source="SECTRACK">1012866</ref>
      <ref url="http://secunia.com/advisories/13791" source="SECUNIA">13791</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0185" published="2005-05-02" name="CVE-2005-0185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18937" source="XF" adv="1">nodemanager-linkdown-bo(18937)</ref>
      <ref url="http://www.security.org.sg/vuln/nodemanager200.html" source="MISC" adv="1">http://www.security.org.sg/vuln/nodemanager200.html</ref>
      <ref url="http://secunia.com/advisories/13881/" source="SECUNIA" adv="1">13881</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599796118583&amp;w=2" source="BUGTRAQ" adv="1">20050117 [SIG^2 G-TEC] NodeManager Professional V2.00 Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12283" source="BID">12283</ref>
      <ref url="http://securitytracker.com/id?1012915" source="SECTRACK">1012915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnet_soft_factory" name="nodemanager_professional">
        <vers num="2.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0186" published="2005-01-19" name="CVE-2005-0186" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18956" source="XF" patch="1" adv="1">cisco-ios-sccp-dos(18956)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml" source="CISCO" adv="1">20050119 Vulnerability in Cisco IOS Embedded Call Processing Solutions</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4849" source="OVAL">oval:org.mitre.oval:def:4849</ref>
      <ref url="http://securitytracker.com/id?1012945" source="SECTRACK">1012945</ref>
      <ref url="http://secunia.com/advisories/13913" source="SECUNIA">13913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1yd" />
        <vers num="12.2t" />
        <vers num="12.3" />
        <vers num="12.3t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0187" published="2005-05-02" name="CVE-2005-0187" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17627" source="XF">athoc-toolbar-bo(17627)</ref>
      <ref url="http://www.securityfocus.com/bid/11341" source="BID">11341</ref>
      <ref url="http://www.ngssoftware.com/advisories/athoc-01full.txt" source="MISC" adv="1">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2" source="BUGTRAQ" adv="1">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2" source="BUGTRAQ" adv="1">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="athoc" name="athoc_toolbar">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0188" published="2004-10-06" name="CVE-2005-0188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17628" source="XF">athoc-toolbar-format-string(17628)</ref>
      <ref url="http://www.securityfocus.com/bid/11341" source="BID">11341</ref>
      <ref url="http://www.ngssoftware.com/advisories/athoc-01full.txt" source="MISC">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2" source="BUGTRAQ" adv="1">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2" source="BUGTRAQ" adv="1">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="athoc" name="athoc_toolbar">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0189" published="2004-10-06" name="CVE-2005-0189" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/698390" source="CERT-VN" patch="1" adv="1">VU#698390</ref>
      <ref url="http://www.securityfocus.com/bid/12311" source="BID" patch="1" adv="1">12311</ref>
      <ref url="http://service.real.com/help/faq/security/040928_player/EN/" source="MISC" patch="1" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2005-q1/0046.html" source="NTBUGTRAQ" patch="1" adv="1">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" source="BUGTRAQ">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":german" />
        <vers num="10.0" edition=":" />
        <vers num="10.0" edition="::english" />
        <vers num="10.0" edition="::japanese" />
        <vers num="10.0_6.0.12.690" />
        <vers num="10.0_beta" />
        <vers num="10.5" />
        <vers num="10.5_6.0.12.1016_beta" />
        <vers num="10.5_6.0.12.1040" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0190" published="2004-09-29" name="CVE-2005-0190" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17551" source="XF" patch="1" adv="1">realplayer-media-file-deletion(17551)</ref>
      <ref url="http://www.securityfocus.com/bid/11308" source="BID" patch="1" adv="1">11308</ref>
      <ref url="http://www.ngssoftware.com/advisories/real-02full.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/real-02full.txt</ref>
      <ref url="http://service.real.com/help/faq/security/040928_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://secunia.com/advisories/12672/" source="SECUNIA" patch="1" adv="1">12672</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2" source="BUGTRAQ" adv="1">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" source="BUGTRAQ" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":german" />
        <vers num="10.0" edition=":" />
        <vers num="10.0" edition="::english" />
        <vers num="10.0" edition="::japanese" />
        <vers num="10.0_6.0.12.690" />
        <vers num="10.0_beta" />
        <vers num="10.5" />
        <vers num="10.5_6.0.12.1016_beta" />
        <vers num="10.5_6.0.12.1040" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0191" published="2005-01-19" name="CVE-2005-0191" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18982" source="XF" patch="1" adv="1">realplayer-long-filename-offbyone-bo(18982)</ref>
      <ref url="http://www.ngssoftware.com/advisories/real-03full.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/real-03full.txt</ref>
      <ref url="http://service.real.com/help/faq/security/040928_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":german" />
        <vers num="10.0" edition=":" />
        <vers num="10.0" edition="::english" />
        <vers num="10.0" edition="::japanese" />
        <vers num="10.0_6.0.12.690" />
        <vers num="10.0_beta" />
        <vers num="10.5" />
        <vers num="10.5_6.0.12.1016_beta" />
        <vers num="10.5_6.0.12.1040" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0192" published="2004-10-06" name="CVE-2005-0192" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18984" source="XF" patch="1" adv="1">realplayer-rjs-filenane-directory-traversal(18984)</ref>
      <ref url="http://www.ngssoftware.com/advisories/real-03full.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/real-03full.txt</ref>
      <ref url="http://service.real.com/help/faq/security/040928_player/EN/" source="MISC" patch="1" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":german" />
        <vers num="10.0" edition=":" />
        <vers num="10.0" edition="::english" />
        <vers num="10.0" edition="::japanese" />
        <vers num="10.0_6.0.12.690" />
        <vers num="10.0_beta" />
        <vers num="10.5" />
        <vers num="10.5_6.0.12.1016_beta" />
        <vers num="10.5_6.0.12.1040" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0193" published="2005-01-22" name="CVE-2005-0193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19011" source="XF" adv="1">isync-mrouter-bo(19011)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642400018425&amp;w=2" source="BUGTRAQ" adv="1">20050122 Mac OS X 10.3 iSync Privilege Escalation</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00001.html" source="APPLE" adv="1">APPLE-SA-2005-04-19</ref>
      <ref url="http://www.securityfocus.com/bid/12334" source="BID">12334</ref>
      <ref url="http://securitytracker.com/id?1012974" source="SECTRACK">1012974</ref>
      <ref url="http://secunia.com/advisories/13965" source="SECUNIA">13965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isync" name="mrouter">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0194" published="2005-05-02" name="CVE-2005-0194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/260421" source="CERT-VN" patch="1" adv="1">VU#260421</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls</ref>
      <ref url="http://www.debian.org/security/2005/dsa-667" source="DEBIAN" patch="1" adv="1">DSA-667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901183320453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050221 [USN-84-1] Squid vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" patch="1">CLA-2005:923</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1166" source="CONFIRM" adv="1">http://www.squid-cache.org/bugs/show_bug.cgi?id=1166</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0.patch1" />
        <vers num="2.0.patch2" />
        <vers num="2.0.pre1" />
        <vers num="2.0.release" />
        <vers num="2.1.patch1" />
        <vers num="2.1.patch2" />
        <vers num="2.1.pre1" />
        <vers num="2.1.pre3" />
        <vers num="2.1.pre4" />
        <vers num="2.1.release" />
        <vers num="2.2.devel3" />
        <vers num="2.2.devel4" />
        <vers num="2.2.pre1" />
        <vers num="2.2.pre2" />
        <vers num="2.2.stable1" />
        <vers num="2.2.stable2" />
        <vers num="2.2.stable3" />
        <vers num="2.2.stable4" />
        <vers num="2.2.stable5" />
        <vers num="2.3.devel2" />
        <vers num="2.3.devel3" />
        <vers num="2.3.stable1" />
        <vers num="2.3.stable2" />
        <vers num="2.3.stable3" />
        <vers num="2.3.stable4" />
        <vers num="2.3.stable5" />
        <vers num="2.4.stable1" />
        <vers num="2.4.stable2" />
        <vers num="2.4.stable3" />
        <vers num="2.4.stable4" />
        <vers num="2.4.stable6" />
        <vers num="2.4.stable7" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0195" published="2005-05-02" name="CVE-2005-0195" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" source="CERT" patch="1" adv="1">TA05-026A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/472582" source="CERT-VN" patch="1" adv="1">VU#472582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19072" source="XF" patch="1" adv="1">cisco-ios-ipv6-dos(19072)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-ipv6.shtml" source="CISCO" patch="1" adv="1">20050126 Multiple Crafted IPv6 Packets Cause Reload</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5813" source="OVAL">oval:org.mitre.oval:def:5813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0s" />
        <vers num="12.0sx" />
        <vers num="12.0sz" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bx" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cz" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2jk" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2se" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yz" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zi" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zn" />
        <vers num="12.2zo" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3j" />
        <vers num="12.3ja" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xm" />
        <vers num="12.3xn" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xt" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3ye" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0196" published="2005-05-02" name="CVE-2005-0196" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" source="CERT" patch="1" adv="1">TA05-026A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/689326" source="CERT-VN" patch="1" adv="1">VU#689326</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19074" source="XF" patch="1" adv="1">cisco-ios-bgp-packetdos(19074)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-bgp.shtml" source="CISCO" patch="1" adv="1">20050126 Cisco IOS Misformed BGP Packet Causes Reload</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5652" source="OVAL">oval:org.mitre.oval:def:5652</ref>
      <ref url="http://securitytracker.com/id?1013013" source="SECTRACK">1013013</ref>
      <ref url="http://secunia.com/advisories/14034" source="SECUNIA">14034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0w5" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0wx" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xp" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xt" />
        <vers num="12.0xu" />
        <vers num="12.0xv" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1az" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ew" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2mx" />
        <vers num="12.2s" />
        <vers num="12.2se" />
        <vers num="12.2su" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2x" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xw" />
        <vers num="12.2xz" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zi" />
        <vers num="12.2zj" />
        <vers num="12.2zk" />
        <vers num="12.2zl" />
        <vers num="12.2zm" />
        <vers num="12.2zn" />
        <vers num="12.2zo" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bw" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xn" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xv" />
        <vers num="12.3xx" />
        <vers num="12.3ya" />
        <vers num="12.3yc" />
        <vers num="12.3yd" />
        <vers num="12.3ye" />
        <vers num="12.3yf" />
        <vers num="12.3yh" />
        <vers num="12.3yj" />
        <vers num="12.3yl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0197" published="2005-05-02" name="CVE-2005-0197" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_base_score="6.1">
    <desc>
      <descript source="cve">Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" source="CERT" patch="1" adv="1">TA05-026A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/583638" source="CERT-VN" patch="1" adv="1">VU#583638</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19071" source="XF" patch="1" adv="1">cisco-ios-mpls-dos(19071)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-les.shtml" source="CISCO" patch="1" adv="1">20050126 Crafted Packet Causes Reload on Cisco Routers</ref>
      <ref url="http://www.securityfocus.com/bid/12369" source="BID">12369</ref>
      <ref url="http://securitytracker.com/id?1013015" source="SECTRACK">1013015</ref>
      <ref url="http://secunia.com/advisories/14031" source="SECUNIA">14031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5662" source="OVAL">oval:org.mitre.oval:def:5662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1t" />
        <vers num="12.2" />
        <vers num="12.2t" />
        <vers num="12.3" />
        <vers num="12.3t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0198" published="2005-05-02" name="CVE-2005-0198" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-68QSL5" source="CONFIRM" patch="1">http://www.kb.cert.org/vuls/id/CRDY-68QSL5</ref>
      <ref url="http://www.kb.cert.org/vuls/id/702777" source="CERT-VN" adv="1">VU#702777</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-128.html" source="REDHAT" patch="1" adv="1">RHSA-2005:128</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-02.xml" source="GENTOO" patch="1">GLSA-200502-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11306" source="OVAL">oval:org.mitre.oval:def:11306</ref>
      <ref url="http://www.securityfocus.com/bid/12391" source="BID">12391</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:026" source="MANDRAKE">MDKSA-2005:026</ref>
      <ref url="http://securitytracker.com/id?1013037" source="SECTRACK">1013037</ref>
      <ref url="http://secunia.com/advisories/14097" source="SECUNIA">14097</ref>
      <ref url="http://secunia.com/advisories/14057" source="SECUNIA">14057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="uw-imap">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0199" published="2005-05-02" name="CVE-2005-0199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19143" source="XF" patch="1" adv="1">ngircd-listmakemask-bo(19143)</ref>
      <ref url="http://www.securityfocus.com/bid/12397" source="BID" patch="1">12397</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-40.xml" source="GENTOO" patch="1">GLSA-200501-40</ref>
      <ref url="http://arthur.ath.cx/pipermail/ngircd-ml/2005-January/000228.html" source="MLIST" patch="1">[ngIRCd-ML] 20050126 ngIRCd 0.8.2</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=79705" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=79705</ref>
      <ref url="http://securitytracker.com/id?1013047" source="SECTRACK">1013047</ref>
      <ref url="http://secunia.com/advisories/14059" source="SECUNIA">14059</ref>
      <ref url="http://secunia.com/advisories/14056" source="SECUNIA">14056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ngircd" name="ngircd">
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.8" />
        <vers num="0.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0200" published="2005-05-02" name="CVE-2005-0200" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-41.xml" source="GENTOO" patch="1">GLSA-200501-41</ref>
      <ref url="http://tikiwiki.org/art102" source="CONFIRM" patch="1">http://tikiwiki.org/art102</ref>
      <ref url="http://secunia.com/advisories/13948" source="SECUNIA">13948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki_project" name="tikiwiki">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0201" published="2005-06-29" name="CVE-2005-0201" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-102.html" source="REDHAT" patch="1" adv="1">RHSA-2005:102</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:105" source="MANDRAKE" patch="1" adv="1">MDKSA-2005:105</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-144-1" source="UBUNTU">USN-144-1</ref>
      <ref url="http://www.auscert.org.au/render.html?it=5156" source="AUSCERT" adv="1">ESB-2005.0435</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10973" source="OVAL">oval:org.mitre.oval:def:10973</ref>
      <ref url="http://www.securityfocus.com/bid/12435" source="BID">12435</ref>
      <ref url="http://securitytracker.com/id?1013075" source="SECTRACK">1013075</ref>
      <ref url="http://secunia.com/advisories/15844" source="SECUNIA">15844</ref>
      <ref url="http://secunia.com/advisories/15833" source="SECUNIA">15833</ref>
      <ref url="http://secunia.com/advisories/15638" source="SECUNIA">15638</ref>
      <ref url="http://secunia.com/advisories/14119" source="SECUNIA">14119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-bus" name="d-bus">
        <vers prev="1" num="0.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0202" published="2005-05-02" name="CVE-2005-0202" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-137.html" source="REDHAT" patch="1" adv="1">RHSA-2005:137</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-136.html" source="REDHAT" patch="1" adv="1">RHSA-2005:136</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-11.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-11</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805795122386&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050209 [USN-78-1] Mailman vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://www.debian.org/security/2005/dsa-674" source="DEBIAN">DSA-674</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10657" source="OVAL">oval:org.mitre.oval:def:10657</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031562.html" source="FULLDISC" adv="1">20050209 Administrivia: List Compromised due to Mailman Vulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_07_mailman.html" source="SUSE">SUSE-SA:2005:007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:037" source="MANDRAKE">MDKSA-2005:037</ref>
      <ref url="http://securitytracker.com/id?1013145" source="SECTRACK">1013145</ref>
      <ref url="http://secunia.com/advisories/14211" source="SECUNIA">14211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0203" reject="1" published="2005-06-09" name="CVE-2005-0203" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0204" published="2005-05-02" name="CVE-2005-0204" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://www.trustix.org/errata/2006/0006" source="TRUSTIX">2006-0006</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://secunia.com/advisories/18784" source="SECUNIA" adv="1">18784</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10320" source="OVAL">oval:org.mitre.oval:def:10320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0205" published="2005-05-02" name="CVE-2005-0205" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-175.html" source="REDHAT" patch="1" adv="1">RHSA-2005:175</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050228-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050228-1.txt</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=208&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050228 KPPP Privileged File Descriptor Leak Vulnerability</ref>
      <ref url="http://www.debian.org/security/2005/dsa-692" source="DEBIAN" patch="1" adv="1">DSA-692</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000934" source="CONECTIVA" patch="1">CLA-2005:934</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9596" source="OVAL">oval:org.mitre.oval:def:9596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bernd_wuebben" name="kppp">
        <vers num="2.1.2" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0206" published="2005-04-27" name="CVE-2005-0206" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11501" source="BID" patch="1" adv="1">11501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-213.html" source="REDHAT" patch="1" adv="1">RHSA-2005:213</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17818" source="XF">xpdf-pdf-bo(17818)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-132.html" source="REDHAT">RHSA-2005:132</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-057.html" source="REDHAT">RHSA-2005:057</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-034.html" source="REDHAT">RHSA-2005:034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11107" source="OVAL">oval:org.mitre.oval:def:11107</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:056" source="MANDRAKE">MDKSA-2005:056</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052" source="MANDRAKE">MDKSA-2005:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:044" source="MANDRAKE">MDKSA-2005:044</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:043" source="MANDRAKE">MDKSA-2005:043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:042" source="MANDRAKE">MDKSA-2005:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:041" source="MANDRAKE">MDKSA-2005:041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ascii" name="ptex">
        <vers num="3.1.4" />
      </prod>
      <prod vendor="cstex" name="cstetex">
        <vers num="2.0.2" />
      </prod>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="gnome" name="gpdf">
        <vers num="0.110" />
        <vers num="0.112" />
        <vers num="0.131" />
      </prod>
      <prod vendor="kde" name="koffice">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3_beta1" />
        <vers num="1.3_beta2" />
        <vers num="1.3_beta3" />
      </prod>
      <prod vendor="kde" name="kpdf">
        <vers num="3.2" />
      </prod>
      <prod vendor="pdftohtml" name="pdftohtml">
        <vers num="0.32a" />
        <vers num="0.32b" />
        <vers num="0.33" />
        <vers num="0.33a" />
        <vers num="0.34" />
        <vers num="0.35" />
        <vers num="0.36" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="tetex" name="tetex">
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="1.0" />
        <vers num="1.0a" />
        <vers num="1.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.3" />
        <vers num="3.0" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="sgi" name="advanced_linux_environment">
        <vers num="3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":i386" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":sparc" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.0" edition=":ppc" />
        <vers num="7.0" edition="alpha" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":sparc" />
        <vers num="7.1" edition=":spa" />
        <vers num="7.1" edition=":x86" />
        <vers num="7.1" edition="alpha" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":i386" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":ppc" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":sparc" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0207" published="2005-05-02" name="CVE-2005-0207" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12330" source="BID" patch="1">12330</ref>
      <ref url="http://www.securityfocus.com/advisories/7880" source="SUSE" patch="1" adv="1">SUSE-SA:2005:003</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000930" source="CONECTIVA" patch="1">CLA-2005:930</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11001" source="OVAL">oval:org.mitre.oval:def:11001</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0208" published="2005-05-02" name="CVE-2005-0208" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0473.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/795812" source="CERT-VN" patch="1" adv="1">VU#795812</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-215.html" source="REDHAT" patch="1" adv="1">RHSA-2005:215</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-03</ref>
      <ref url="http://secunia.com/advisories/14386" source="SECUNIA" patch="1" adv="1">14386</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050225 [USN-85-1] Gaim vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933" source="CONECTIVA" patch="1">CLA-2005:933</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10477" source="OVAL">oval:org.mitre.oval:def:10477</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=12" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/?id=12</ref>
      <ref url="http://www.securityfocus.com/bid/12660" source="BID">12660</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049" source="MANDRAKE">MDKSA-2005:049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0209" published="2005-05-02" name="CVE-2005-0209" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945" source="CONECTIVA" patch="1">CLA-2005:945</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-420.html" source="REDHAT">RHSA-2005:420</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11855" source="OVAL">oval:org.mitre.oval:def:11855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0210" published="2005-05-02" name="CVE-2005-0210" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945" source="CONECTIVA" patch="1">CLA-2005:945</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.securityfocus.com/bid/12816" source="BID">12816</ref>
      <ref url="http://www.osvdb.org/14966" source="OSVDB">14966</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" source="MANDRAKE">MDKSA-2005:218</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://secunia.com/advisories/14295" source="SECUNIA">14295</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10275" source="OVAL">oval:org.mitre.oval:def:10275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0211" published="2005-05-02" name="CVE-2005-0211" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/886006" source="CERT-VN" patch="1" adv="1">VU#886006</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://www.debian.org/security/2005/dsa-667" source="DEBIAN" patch="1" adv="1">DSA-667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9573" source="OVAL">oval:org.mitre.oval:def:9573</ref>
      <ref url="http://www.securityfocus.com/bid/12432" source="BID">12432</ref>
      <ref url="http://www.osvdb.org/13319" source="OSVDB">13319</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" source="MANDRAKE">MDKSA-2005:034</ref>
      <ref url="http://securitytracker.com/id?1013045" source="SECTRACK">1013045</ref>
      <ref url="http://secunia.com/advisories/14076" source="SECUNIA">14076</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0212" published="2005-05-02" name="CVE-2005-0212" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Amp II engine as used by Gore: Ultimate Soldier 1.50 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero byte UDP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18789" source="XF">amp-3d-socket-dos(18789)</ref>
      <ref url="http://www.securityfocus.com/bid/12192" source="BID">12192</ref>
      <ref url="http://aluigi.altervista.org/adv/amp2zero-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/amp2zero-adv.txt</ref>
      <ref url="http://secunia.com/advisories/13754" source="SECUNIA">13754</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110503597505648&amp;w=2" source="BUGTRAQ">20050106 Socket unreacheable in Amp II engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amp" name="amp_ii_3d_game_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0213" published="2005-05-02" name="CVE-2005-0213" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18798" source="XF">winhki-zip-directory-traversal(18798)</ref>
      <ref url="http://www.securityfocus.com/bid/12176" source="BID">12176</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110505334903257&amp;w=2" source="BUGTRAQ" adv="1">20050106 WinAc AND WinHKI ZIP File Directory Transversal </ref>
      <ref url="http://securitytracker.com/id?1012798" source="SECTRACK">1012798</ref>
      <ref url="http://secunia.com/advisories/13738" source="SECUNIA">13738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webtoolmaster_software" name="winhki">
        <vers num="1.4d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0214" published="2005-05-02" name="CVE-2005-0214" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12193" source="BID" patch="1">12193</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18802" source="XF">sphp-dotdot-directory-traversal(18802)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512850603989&amp;w=2" source="BUGTRAQ" adv="1">20050107 Simple PHP Blog directory traversal vulnerability </ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-01/0210.html" source="FULLDISC" adv="1">20050107 Simple PHP Blog directory traversal vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_palmo" name="simple_php_blog">
        <vers num="0.3.7c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0215" published="2005-05-02" name="CVE-2005-0215" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a large (1) height or (2) width value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512665029209&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050107 Mozilla XBM Image Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18803" source="XF">mozilla-xbm-dos(18803)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0216" published="2005-05-02" name="CVE-2005-0216" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web sript and HTML via the userid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18814" source="XF">wbb-formmail-userid-xss(18814)</ref>
      <ref url="http://www.securityfocus.com/bid/12199" source="BID">12199</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110537385427004&amp;w=2" source="BUGTRAQ" adv="1">20050108 Security Advisory: Woltlab Burning Board Lite formmail.php XSS </ref>
      <ref url="http://secunia.com/advisories/13782" source="SECUNIA">13782</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0217" published="2005-05-02" name="CVE-2005-0217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18815" source="XF">icb-sql-injection(18815)</ref>
      <ref url="http://www.securityfocus.com/bid/12205" source="BID">12205</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110538277223800&amp;w=2" source="BUGTRAQ" adv="1">20050109 SQL Injection Vulnerability in Invision Community Blog</ref>
      <ref url="http://www.osvdb.org/12817" source="OSVDB">12817</ref>
      <ref url="http://securitytracker.com/id?1012831" source="SECTRACK">1012831</ref>
      <ref url="http://secunia.com/advisories/13783" source="SECUNIA">13783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_community_blog">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0218" published="2005-05-02" name="CVE-2005-0218" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml" source="GENTOO" patch="1">GLSA-200501-46</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=300116" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=300116</ref>
      <ref url="http://secunia.com/advisories/13900/" source="SECUNIA" adv="1">13900</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025" source="MANDRAKE">MDKSA-2005:025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.80" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0219" published="2005-05-02" name="CVE-2005-0219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8) username field in search.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" source="CONFIRM" patch="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18938" source="XF">gallery-multiple-xss(18938)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" source="BUGTRAQ" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html" source="VULNWATCH">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43473" source="XF">gallery-multiple-scripts-xss(43473)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.3.4_pl1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0220" published="2005-05-02" name="CVE-2005-0220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13887/" source="SECUNIA" patch="1">13887</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" source="CONFIRM" patch="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18938" source="XF">gallery-multiple-xss(18938)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-45.xml" source="GENTOO">GLSA-200501-45</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" source="BUGTRAQ" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.4.4_pl2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0221" published="2005-01-17" name="CVE-2005-0221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18938" source="XF" patch="1" adv="1">gallery-multiple-xss(18938)</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" source="CONFIRM" patch="1" adv="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
      <ref url="http://theinsider.deep-ice.com/texts/advisory69.txt" source="MISC" adv="1">http://theinsider.deep-ice.com/texts/advisory69.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" source="BUGTRAQ" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html" source="VULNWATCH" adv="1">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43472" source="XF">gallery-g2formsubject-xss(43472)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="2.0_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0222" published="2005-05-02" name="CVE-2005-0222" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18940" source="XF">gallery-mainphp-obtain-information(18940)</ref>
      <ref url="http://theinsider.deep-ice.com/texts/advisory69.txt" source="MISC" adv="1">http://theinsider.deep-ice.com/texts/advisory69.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" source="BUGTRAQ" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" source="CONFIRM">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html" source="VULNWATCH">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="2.0_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0223" published="2005-05-02" name="CVE-2005-0223" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserialization.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110719624029320&amp;w=2" source="HP" patch="1" adv="1">SSRT4875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="rte">
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0224" published="2005-01-31" name="CVE-2005-0224" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14082/" source="SECUNIA" patch="1" adv="1">14082</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726808700080&amp;w=2" source="HP" adv="1">SSRT5900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="virtualvault">
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0225" published="2005-05-02" name="CVE-2005-0225" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">firehol.sh in FireHOL before 1.224 creates temporary files with predictable file names, which could allow local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-01.xml" source="GENTOO">GLSA-200502-01</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/firehol/firehol/firehol.sh" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/firehol/firehol/firehol.sh</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19032" source="XF">firehol-symlink(19032)</ref>
      <ref url="http://www.securityfocus.com/bid/12336" source="BID">12336</ref>
      <ref url="http://www.osvdb.org/13137" source="OSVDB">13137</ref>
      <ref url="http://securitytracker.com/id?1012969" source="SECTRACK">1012969</ref>
      <ref url="http://secunia.com/advisories/14102" source="SECUNIA">14102</ref>
      <ref url="http://secunia.com/advisories/13970" source="SECUNIA">13970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firehol" name="firehol">
        <vers num="1.1" />
        <vers num="1.1.1.1" />
        <vers num="1.10" />
        <vers num="1.100" />
        <vers num="1.101" />
        <vers num="1.102" />
        <vers num="1.103" />
        <vers num="1.104" />
        <vers num="1.105" />
        <vers num="1.106" />
        <vers num="1.107" />
        <vers num="1.108" />
        <vers num="1.109" />
        <vers num="1.11" />
        <vers num="1.110" />
        <vers num="1.111" />
        <vers num="1.112" />
        <vers num="1.113" />
        <vers num="1.114" />
        <vers num="1.115" />
        <vers num="1.116" />
        <vers num="1.117" />
        <vers num="1.118" />
        <vers num="1.119" />
        <vers num="1.12" />
        <vers num="1.120" />
        <vers num="1.121" />
        <vers num="1.122" />
        <vers num="1.123" />
        <vers num="1.124" />
        <vers num="1.125" />
        <vers num="1.126" />
        <vers num="1.127" />
        <vers num="1.128" />
        <vers num="1.129" />
        <vers num="1.13" />
        <vers num="1.130" />
        <vers num="1.131" />
        <vers num="1.132" />
        <vers num="1.133" />
        <vers num="1.134" />
        <vers num="1.135" />
        <vers num="1.136" />
        <vers num="1.137" />
        <vers num="1.138" />
        <vers num="1.139" />
        <vers num="1.14" />
        <vers num="1.140" />
        <vers num="1.141" />
        <vers num="1.142" />
        <vers num="1.143" />
        <vers num="1.144" />
        <vers num="1.145" />
        <vers num="1.146" />
        <vers num="1.147" />
        <vers num="1.148" />
        <vers num="1.149" />
        <vers num="1.15" />
        <vers num="1.150" />
        <vers num="1.151" />
        <vers num="1.152" />
        <vers num="1.153" />
        <vers num="1.154" />
        <vers num="1.155" />
        <vers num="1.156" />
        <vers num="1.157" />
        <vers num="1.158" />
        <vers num="1.159" />
        <vers num="1.16" />
        <vers num="1.160" />
        <vers num="1.161" />
        <vers num="1.162" />
        <vers num="1.163" />
        <vers num="1.164" />
        <vers num="1.165" />
        <vers num="1.166" />
        <vers num="1.167" />
        <vers num="1.168" />
        <vers num="1.169" />
        <vers num="1.17" />
        <vers num="1.170" />
        <vers num="1.171" />
        <vers num="1.172" />
        <vers num="1.173" />
        <vers num="1.174" />
        <vers num="1.175" />
        <vers num="1.176" />
        <vers num="1.177" />
        <vers num="1.178" />
        <vers num="1.179" />
        <vers num="1.18" />
        <vers num="1.180" />
        <vers num="1.181" />
        <vers num="1.182" />
        <vers num="1.183" />
        <vers num="1.184" />
        <vers num="1.185" />
        <vers num="1.186" />
        <vers num="1.187" />
        <vers num="1.188" />
        <vers num="1.189" />
        <vers num="1.19" />
        <vers num="1.190" />
        <vers num="1.191" />
        <vers num="1.192" />
        <vers num="1.193" />
        <vers num="1.194" />
        <vers num="1.195" />
        <vers num="1.196" />
        <vers num="1.197" />
        <vers num="1.198" />
        <vers num="1.199" />
        <vers num="1.2" />
        <vers num="1.20" />
        <vers num="1.200" />
        <vers num="1.201" />
        <vers num="1.202" />
        <vers num="1.203" />
        <vers num="1.204" />
        <vers num="1.205" />
        <vers num="1.206" />
        <vers num="1.207" />
        <vers num="1.208" />
        <vers num="1.209" />
        <vers num="1.21" />
        <vers num="1.210" />
        <vers num="1.211" />
        <vers num="1.212" />
        <vers num="1.213" />
        <vers num="1.214" />
        <vers num="1.215" />
        <vers num="1.216" />
        <vers num="1.217" />
        <vers num="1.218" />
        <vers num="1.219" />
        <vers num="1.22" />
        <vers num="1.220" />
        <vers num="1.221" />
        <vers num="1.222" />
        <vers num="1.223" />
        <vers num="1.224" />
        <vers num="1.23" />
        <vers num="1.24" />
        <vers num="1.25" />
        <vers num="1.26" />
        <vers num="1.27" />
        <vers num="1.28" />
        <vers num="1.29" />
        <vers num="1.3" />
        <vers num="1.30" />
        <vers num="1.31" />
        <vers num="1.32" />
        <vers num="1.33" />
        <vers num="1.34" />
        <vers num="1.35" />
        <vers num="1.36" />
        <vers num="1.37" />
        <vers num="1.38" />
        <vers num="1.39" />
        <vers num="1.4" />
        <vers num="1.40" />
        <vers num="1.41" />
        <vers num="1.42" />
        <vers num="1.43" />
        <vers num="1.44" />
        <vers num="1.45" />
        <vers num="1.46" />
        <vers num="1.47" />
        <vers num="1.48" />
        <vers num="1.49" />
        <vers num="1.5" />
        <vers num="1.50" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.55" />
        <vers num="1.56" />
        <vers num="1.57" />
        <vers num="1.58" />
        <vers num="1.59" />
        <vers num="1.6" />
        <vers num="1.60" />
        <vers num="1.61" />
        <vers num="1.62" />
        <vers num="1.63" />
        <vers num="1.64" />
        <vers num="1.65" />
        <vers num="1.66" />
        <vers num="1.67" />
        <vers num="1.68" />
        <vers num="1.69" />
        <vers num="1.7" />
        <vers num="1.70" />
        <vers num="1.71" />
        <vers num="1.72" />
        <vers num="1.73" />
        <vers num="1.74" />
        <vers num="1.75" />
        <vers num="1.76" />
        <vers num="1.77" />
        <vers num="1.78" />
        <vers num="1.79" />
        <vers num="1.8" />
        <vers num="1.80" />
        <vers num="1.81" />
        <vers num="1.82" />
        <vers num="1.83" />
        <vers num="1.84" />
        <vers num="1.85" />
        <vers num="1.86" />
        <vers num="1.87" />
        <vers num="1.88" />
        <vers num="1.89" />
        <vers num="1.9" />
        <vers num="1.90" />
        <vers num="1.91" />
        <vers num="1.92" />
        <vers num="1.93" />
        <vers num="1.94" />
        <vers num="1.95" />
        <vers num="1.96" />
        <vers num="1.97" />
        <vers num="1.98" />
        <vers num="1.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0226" published="2005-02-03" name="CVE-2005-0226" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nosystem.com.ar/advisories/advisory-11.txt" source="MISC" patch="1" adv="1">http://www.nosystem.com.ar/advisories/advisory-11.txt</ref>
      <ref url="http://secunia.com/advisories/14114/" source="SECUNIA" patch="1" adv="1">14114</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746413108183&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050203 ngIRCd &lt;= v0.8.2 Format String Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12434" source="BID">12434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ngircd" name="ngircd">
        <vers num="0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0227" published="2005-05-02" name="CVE-2005-0227" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-150.html" source="REDHAT" patch="1" adv="1">RHSA-2005:150</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://www.debian.org/security/2005/dsa-668" source="DEBIAN" patch="1" adv="1">DSA-668</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-08.xml" source="GENTOO" patch="1">200502-08</ref>
      <ref url="http://secunia.com/advisories/12948" source="SECUNIA" patch="1" adv="1">12948</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726899107148&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050201 [USN-71-1] PostgreSQL vulnerability</ref>
      <ref url="http://archives.postgresql.org/pgsql-announce/2005-02/msg00000.php" source="MLIST" patch="1">[pgsql-announce] 20050201 PostgreSQL Security Release</ref>
      <ref url="http://www.securityfocus.com/bid/12411" source="BID">12411</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10234" source="OVAL">oval:org.mitre.oval:def:10234</ref>
      <ref url="http://archives.postgresql.org/pgsql-bugs/2005-01/msg00269.php" source="MLIST" adv="1">[pgsql-bugs] 20050121 Privilege escalation via LOAD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2.1" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.2.5" />
        <vers num="7.2.6" />
        <vers num="7.2.7" />
        <vers num="7.4.1" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0228" reject="1" published="2005-05-02" name="CVE-2005-0228" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1388.  Reason: This candidate is a duplicate of CVE-2004-1388.  Notes: All CVE users should reference CVE-2004-1388 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0229" published="2005-04-27" name="CVE-2005-0229" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12402" source="BID" patch="1" adv="1">12402</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110824766519417&amp;w=2" source="FULLDISC" patch="1" adv="1">20050212 Credit Card data disclosure in CitrusDB</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19145" source="XF">citrus-information-disclosure(19145)</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-001.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-001.txt</ref>
      <ref url="http://www.citrusdb.org/forums/viewtopic.php?t=49" source="CONFIRM">http://www.citrusdb.org/forums/viewtopic.php?t=49</ref>
      <ref url="http://securitytracker.com/id?1013040" source="SECTRACK">1013040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb_customer_database">
        <vers num="0.1.2" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0230" published="2005-05-02" name="CVE-2005-0230" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-25.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/mfsa2005-25.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=279945" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=279945</ref>
      <ref url="http://www.securityfocus.com/bid/12468" source="BID">12468</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mikx.de/firedragging/" source="MISC">http://www.mikx.de/firedragging/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780995232064&amp;w=2" source="BUGTRAQ" adv="1">20050207 Firedragging [Firefox 1.0]</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100033" source="OVAL" sig="1">oval:org.mitre.oval:def:100033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0231" published="2005-02-07" name="CVE-2005-0231" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=280056" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=280056</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19264" source="XF" patch="1" adv="1">mozilla-firefox-tab-gain-access(19264)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:016</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-26.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-26.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.mikx.de/firetabbing/" source="MISC" adv="1">http://www.mikx.de/firetabbing/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10079" source="OVAL">oval:org.mitre.oval:def:10079</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781134617144&amp;w=2" source="BUGTRAQ" adv="1">20050207 Firetabbing [Firefox 1.0]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100032" source="OVAL" sig="1">oval:org.mitre.oval:def:100032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0232" published="2005-05-02" name="CVE-2005-0232" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19266" source="XF" patch="1">mozilla-firefox-aboutconfig-modify(19266)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:016</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=280664" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=280664</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-27.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-27.html</ref>
      <ref url="http://www.mikx.de/fireflashing/" source="MISC">http://www.mikx.de/fireflashing/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10967" source="OVAL">oval:org.mitre.oval:def:10967</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781055630856&amp;w=2" source="BUGTRAQ" adv="1">20050207 Fireflashing [Firefox 1.0]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0233" published="2005-02-08" name="CVE-2005-0233" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1" adv="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:016</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-29.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-29.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC" adv="1">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC" adv="1">http://www.shmoo.com/idn</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11229" source="OVAL">oval:org.mitre.oval:def:11229</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" source="BUGTRAQ" adv="1">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100029" source="OVAL" sig="1">oval:org.mitre.oval:def:100029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="camino">
        <vers num="0.8.5" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
      </prod>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5" />
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0234" published="2005-05-02" name="CVE-2005-0234" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC" adv="1">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC">http://www.shmoo.com/idn</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" source="BUGTRAQ">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0235" published="2005-05-02" name="CVE-2005-0235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Opera 7.54 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC">http://www.shmoo.com/idn</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" source="BUGTRAQ">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_31_opera.html" source="SUSE">SUSE-SA:2005:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0236" published="2005-05-02" name="CVE-2005-0236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC">http://www.shmoo.com/idn</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" source="BUGTRAQ">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0237" published="2005-05-02" name="CVE-2005-0237" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050316-2.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050316-2.txt</ref>
      <ref url="http://secunia.com/advisories/14162" source="SECUNIA" patch="1" adv="1">14162</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC">http://www.shmoo.com/idn</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10671" source="OVAL">oval:org.mitre.oval:def:10671</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031460.html" source="FULLDISC" adv="1">20050206 Re: state of homograph attacks</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" source="FEDORA">FLSA:178606</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-325.html" source="REDHAT">RHSA-2005:325</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058" source="MANDRAKE">MDKSA-2005:058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.2.1" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0238" published="2005-05-02" name="CVE-2005-0238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/beta/show_bug.cgi?id=147399" source="CONFIRM" patch="1" adv="1">https://bugzilla.redhat.com/beta/show_bug.cgi?id=147399</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1" adv="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC" adv="1">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC" adv="1">http://www.shmoo.com/idn</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="epiphany">
        <vers num="" />
      </prod>
      <prod vendor="mozilla" name="camino">
        <vers num="0.8.5" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
      </prod>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5" />
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0239" published="2005-05-02" name="CVE-2005-0239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/502328" source="CERT-VN" patch="1" adv="1">VU#502328</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19242" source="XF" patch="1">squirrelmail-smime-command-execution(19242)</ref>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=54" source="CONFIRM">http://www.squirrelmail.org/plugin_view.php?id=54</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=191&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" adv="1">20050207 SquirrelMail S/MIME Plugin Command Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="s_mime_plugin">
        <vers num="0.4" />
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0240" published="2005-05-02" name="CVE-2005-0240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19244" source="XF">aix-chdev-format-string(19244)</ref>
      <ref url="http://www.idefense.com/application/poi/display?type=vulnerabilities" source="IDEFENSE">20050207 IBM AIX chdev Local Format String Vulnerability</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67654" source="AIXAPAR" adv="1">IY67654</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67455" source="AIXAPAR" adv="1">IY67455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0241" published="2005-05-02" name="CVE-2005-0241" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/823350" source="CERT-VN" patch="1" adv="1">VU#823350</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19060" source="XF" patch="1">squid-http-cache-poisoning(19060)</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1216" source="CONFIRM" patch="1">http://www.squid-cache.org/bugs/show_bug.cgi?id=1216</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" patch="1">CLA-2005:931</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10998" source="OVAL">oval:org.mitre.oval:def:10998</ref>
      <ref url="http://www.securityfocus.com/bid/12412" source="BID">12412</ref>
      <ref url="http://secunia.com/advisories/14091" source="SECUNIA">14091</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0242" published="2005-02-18" name="CVE-2005-0242" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2004-6/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2004-6/advisory/</ref>
      <ref url="http://secunia.com/advisories/11815" source="SECUNIA" patch="1">11815</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.6.0.1351" />
        <vers num="6.0" />
        <vers num="6.0.0.1750" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0243" published="2005-02-17" name="CVE-2005-0243" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2005-2/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-2/advisory/</ref>
      <ref url="http://secunia.com/advisories/13712" source="SECUNIA" patch="1" adv="1">13712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.6.0.1351" />
        <vers num="6.0" />
        <vers num="6.0.0.1750" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0244" published="2005-05-02" name="CVE-2005-0244" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19184" source="XF" patch="1">postgresql-security-bypass(19184)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://secunia.com/advisories/12948" source="SECUNIA" patch="1" adv="1">12948</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/12417" source="BID">12417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10927" source="OVAL">oval:org.mitre.oval:def:10927</ref>
      <ref url="http://archives.postgresql.org/pgsql-hackers/2005-01/msg00922.php" source="MLIST" adv="1">[pgsql-hackers] 20050127 Permissions on aggregate component functions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.2.5" />
        <vers num="7.2.6" />
        <vers num="7.2.7" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.2" />
        <vers num="7.3.3" />
        <vers num="7.3.4" />
        <vers num="7.3.5" />
        <vers num="7.3.6" />
        <vers num="7.3.7" />
        <vers num="7.3.8" />
        <vers num="7.3.9" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="8.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0245" published="2005-02-01" name="CVE-2005-0245" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19188" source="XF" patch="1" adv="1">postgresql-cursor-bo(19188)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-150.html" source="REDHAT" patch="1" adv="1">RHSA-2005:150</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://secunia.com/advisories/12948" source="SECUNIA" patch="1" adv="1">12948</ref>
      <ref url="http://www.debian.org/security/2005/dsa-683" source="DEBIAN" adv="1">DSA-683</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10175" source="OVAL">oval:org.mitre.oval:def:10175</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" source="BUGTRAQ" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
      <ref url="http://archives.postgresql.org/pgsql-patches/2005-01/msg00216.php" source="MLIST" adv="1">[pgsql-patches] 20050120 Re: WIP: pl/pgsql cleanup</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php" source="MLIST" adv="1">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00298.php" source="MLIST" adv="1">[pgsql-committers] 20050121 pgsql: Prevent overrunning a heap-allocated buffer is more than 1024</ref>
      <ref url="http://www.securityfocus.com/bid/12417" source="BID">12417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.2.5" />
        <vers num="7.2.6" />
        <vers num="7.2.7" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.2" />
        <vers num="7.3.3" />
        <vers num="7.3.4" />
        <vers num="7.3.5" />
        <vers num="7.3.6" />
        <vers num="7.3.7" />
        <vers num="7.3.8" />
        <vers num="7.3.9" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0246" published="2005-05-02" name="CVE-2005-0246" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19185" source="XF" patch="1">postgresql-contribintagg-dos(19185)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://secunia.com/advisories/12948" source="SECUNIA" patch="1" adv="1">12948</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00401.php" source="MLIST" patch="1">[pgsql-committers] 20050127 pgsql: Fix security and 64-bit issues in contrib/intagg.</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10148" source="OVAL">oval:org.mitre.oval:def:10148</ref>
      <ref url="http://www.securityfocus.com/bid/12417" source="BID">12417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.2.5" />
        <vers num="7.2.6" />
        <vers num="7.2.7" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.2" />
        <vers num="7.3.3" />
        <vers num="7.3.4" />
        <vers num="7.3.5" />
        <vers num="7.3.6" />
        <vers num="7.3.7" />
        <vers num="7.3.8" />
        <vers num="7.3.9" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="8.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0247" published="2005-05-02" name="CVE-2005-0247" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19378" source="XF" patch="1">postgresql-fetch-makefetchstmt-bo(19378)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19377" source="XF" patch="1">postgresql-makeselectstmt-arbitrary-bo(19377)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19376" source="XF" patch="1">postgresql-makeselectstmt-input-bo(19376)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19375" source="XF" patch="1">postgresql-readsqlconstruct-bo(19375)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-150.html" source="REDHAT" patch="1" adv="1">RHSA-2005:150</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_27_postgresql.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:027</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-19.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-19</ref>
      <ref url="http://www.debian.org/security/2005/dsa-683" source="DEBIAN" patch="1" adv="1">DSA-683</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php" source="MLIST" patch="1">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref>
      <ref url="http://www.securityfocus.com/bid/12417" source="BID">12417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9345" source="OVAL">oval:org.mitre.oval:def:9345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.2.5" />
        <vers num="7.2.6" />
        <vers num="7.2.7" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.2" />
        <vers num="7.3.3" />
        <vers num="7.3.4" />
        <vers num="7.3.5" />
        <vers num="7.3.6" />
        <vers num="7.3.7" />
        <vers num="7.3.8" />
        <vers num="7.3.9" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="8.0.0" />
        <vers num="8.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0248" published="2005-05-02" name="CVE-2005-0248" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18868" source="XF" patch="1">solaris-smc-blank-password(18868)</ref>
      <ref url="http://www.securityfocus.com/bid/12260" source="BID" patch="1">12260</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57717-1" source="SUNALERT" patch="1">57717</ref>
      <ref url="http://secunia.com/advisories/13803/" source="SECUNIA" patch="1" adv="1">13803</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-096.shtml" source="CIAC" adv="1">P-096</ref>
      <ref url="http://securitytracker.com/id?1012860" source="SECTRACK">1012860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0249" published="2005-02-08" name="CVE-2005-0249" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/107822" source="CERT-VN" patch="1" adv="1">VU#107822</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18869" source="XF" patch="1" adv="1">upx-engine-gain-control(18869)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/187" source="ISS" patch="1" adv="1">20050208 Symantec AntiVirus Library Heap Overflow</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2005.02.08.html" source="CONFIRM" patch="1" adv="1">http://www.symantec.com/avcenter/security/Content/2005.02.08.html</ref>
      <ref url="http://securitytracker.com/id?1013133" source="SECTRACK">1013133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.1.6" />
        <vers prev="1" num="4.0" edition="" />
        <vers prev="1" num="4.0" edition=":netapp_filer" />
        <vers prev="1" num="4.0" edition=":bluecoat" />
        <vers prev="1" num="4.0" edition=":netapp_netcache" />
        <vers prev="1" num="4.3" />
        <vers prev="1" num="4.3.3" edition="" />
        <vers prev="1" num="4.3.3" edition=":filers" />
        <vers prev="1" num="4.3.3" edition=":bluecoat" />
        <vers prev="1" num="4.3.3" edition=":caching" />
        <vers prev="1" num="4.3.3" edition=":netapp_filer" />
        <vers prev="1" num="4.3.3" edition=":netapp_netcache" />
      </prod>
      <prod vendor="symantec" name="brightmail_antispam">
        <vers prev="1" num="4.0" />
        <vers prev="1" num="5.5" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="1.0.1_build_8.01.434" edition="mr3" />
        <vers num="1.0.1_build_8.01.437" />
        <vers num="1.0.1_build_8.01.446" edition="mr4" />
        <vers num="1.0.1_build_8.01.457" edition="mr5" />
        <vers num="1.0.1_build_8.01.460" edition="mr6" />
        <vers num="1.0.1_build_8.01.464" edition="mr7" />
        <vers num="1.0.1_build_8.01.471" edition="mr8" />
        <vers num="1.1.1_mr1_build_8.1.1.314a" />
        <vers num="1.1.1_mr2_build_8.1.1.319" />
        <vers num="1.1.1_mr3_build_8.1.1.323" />
        <vers num="1.1.1_mr4_build_8.1.1.329" />
        <vers num="1.1.1_mr5_build_8.1.1.336" />
      </prod>
      <prod vendor="symantec" name="gateway_security">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
      <prod vendor="symantec" name="mail_security">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":domino" />
        <vers prev="1" num="4.0.2" edition="" />
        <vers prev="1" num="4.0.2" edition=":smtp" />
        <vers num="4.1" edition="build_458" />
        <vers num="4.1" edition="build_458:exchange" />
        <vers num="4.1" edition="build_459" />
        <vers num="4.1" edition="build_459:exchange" />
        <vers num="4.1" edition="build_461" />
        <vers num="4.1" edition="build_461:exchange" />
        <vers num="4.5_build_719" edition="" />
        <vers num="4.5_build_719" edition=":exchange" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2.18_build_83" edition="" />
        <vers num="2.18_build_83" edition=":exchange" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":windows" />
        <vers num="8.01.434" edition="" />
        <vers num="8.01.434" edition=":corporate" />
        <vers num="8.01.437" edition="" />
        <vers num="8.01.437" edition=":corporate" />
        <vers num="8.01.446" edition="" />
        <vers num="8.01.446" edition=":corporate" />
        <vers num="8.01.457" edition="" />
        <vers num="8.01.457" edition=":corporate" />
        <vers num="8.01.460" edition="" />
        <vers num="8.01.460" edition=":corporate" />
        <vers num="8.01.464" edition="" />
        <vers num="8.01.464" edition=":corporate" />
        <vers num="8.01.471" edition="" />
        <vers num="8.01.471" edition=":corporate" />
        <vers num="8.1.1.319" edition="" />
        <vers num="8.1.1.319" edition=":corporate" />
        <vers num="8.1.1.323" edition="" />
        <vers num="8.1.1.323" edition=":corporate" />
        <vers num="8.1.1.329" edition="" />
        <vers num="8.1.1.329" edition=":corporate" />
        <vers num="8.1.1_build8.1.1.314a" edition="" />
        <vers num="8.1.1_build8.1.1.314a" edition=":corporate" />
        <vers prev="1" num="9.0" edition="" />
        <vers prev="1" num="9.0" edition=":macintosh_corporate" />
        <vers prev="1" num="9.0" edition=":macintosh_osx" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":professional" />
        <vers prev="1" num="3.0" edition="" />
        <vers prev="1" num="3.0" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":windows" />
        <vers prev="1" num="3.0" edition="" />
        <vers prev="1" num="3.0" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="sav_filter_domino_nt_ports">
        <vers num="build3.0.5" edition="" />
        <vers num="build3.0.5" edition=":aix" />
        <vers num="build3.0.5" edition=":os_400" />
      </prod>
      <prod vendor="symantec" name="sav_filter_for_domino_nt">
        <vers num="3.1.1" />
      </prod>
      <prod vendor="symantec" name="web_security">
        <vers num="3.01.59" />
        <vers num="3.01.60" />
        <vers num="3.01.61" />
        <vers num="3.01.62" />
        <vers num="3.01.63" />
        <vers num="3.01.67" />
        <vers num="3.01.68" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0250" published="2005-05-02" name="CVE-2005-0250" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/896729" source="CERT-VN" adv="1">VU#896729</ref>
      <ref url="http://www.securityfocus.com/bid/12496" source="BID" patch="1">12496</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=193&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20050208 IBM AIX auditselect Local Format String Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19255" source="XF">aix-auditselect-format-string(19255)</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67802" source="AIXAPAR" adv="1">IY67802</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67519" source="AIXAPAR" adv="1">IY67519</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67472" source="AIXAPAR" adv="1">IY67472</ref>
      <ref url="http://secunia.com/advisories/14198" source="SECUNIA" adv="1">14198</ref>
      <ref url="http://securitytracker.com/id?1013103" source="SECTRACK">1013103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0251" published="2005-05-02" name="CVE-2005-0251" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12583" source="BID" patch="1" adv="1">12583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2" source="FULLDISC" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2" source="BUGTRAQ" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biborb" name="biborb">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0252" published="2005-05-02" name="CVE-2005-0252" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12583" source="BID" patch="1">12583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2" source="FULLDISC" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2" source="BUGTRAQ" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biborb" name="biborb">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0253" published="2005-05-02" name="CVE-2005-0253" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12583" source="BID" patch="1">12583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2" source="FULLDISC" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2" source="BUGTRAQ" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biborb" name="biborb">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0254" published="2005-05-02" name="CVE-2005-0254" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12583" source="BID" patch="1">12583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2" source="FULLDISC" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2" source="BUGTRAQ" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biborb" name="biborb">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0255" published="2005-05-02" name="CVE-2005-0255" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-337.html" source="REDHAT" patch="1" adv="1">RHSA-2005:337</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-277.html" source="REDHAT" patch="1" adv="1">RHSA-2005:277</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:016</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=200&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050228 Mozilla Firefox and Mozilla Browser Out Of Memory Heap Corruption Design Error</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-18.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-18.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9111" source="OVAL">oval:org.mitre.oval:def:9111</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100040" source="OVAL" sig="1">oval:org.mitre.oval:def:100040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7.3" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0256" published="2005-05-02" name="CVE-2005-0256" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-705" source="DEBIAN" patch="1" adv="1">DSA-705</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1271" source="VUPEN" adv="1">ADV-2006-1271</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0588" source="VUPEN" adv="1">ADV-2005-0588</ref>
      <ref url="http://www.osvdb.org/14203" source="OSVDB">14203</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=207&amp;type=vulnerabilities" source="IDEFENSE">20050225 WU-FTPD File Globbing Denial of Service Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57795-1" source="SUNALERT">57795</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101699-1" source="SUNALERT">101699</ref>
      <ref url="http://secunia.com/advisories/19561" source="SECUNIA" adv="1">19561</ref>
      <ref url="http://secunia.com/advisories/18210" source="SECUNIA" adv="1">18210</ref>
      <ref url="http://secunia.com/advisories/14411" source="SECUNIA" adv="1">14411</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00637342" source="HP">HPSBUX02110</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00637342" source="HP">SSRT061110</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.63/SCOSA-2005.63.txt" source="SCO">SCOSA-2005.63</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1762" source="OVAL" sig="1">oval:org.mitre.oval:def:1762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1333" source="OVAL" sig="1">oval:org.mitre.oval:def:1333</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1265" source="OVAL" sig="1">oval:org.mitre.oval:def:1265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.6.1" />
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0258" published="2005-03-14" name="CVE-2005-0258" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via "/../" sequences in the avatarselect parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=205&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050222 phpBB Group phpBB2 Arbitrary File Unlink Vulnerability</ref>
      <ref url="http://www.phpbb.com/support/documents.php?mode=changelog" source="CONFIRM" adv="1">http://www.phpbb.com/support/documents.php?mode=changelog</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml" source="GENTOO">GLSA-200503-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0259" published="2005-03-14" name="CVE-2005-0259" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/774686" source="CERT-VN">VU#774686</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=204&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050222 phpBB Group phpBB Arbitrary File Disclosure Vulnerability</ref>
      <ref url="http://www.phpbb.com/support/documents.php?mode=changelog" source="CONFIRM" adv="1">http://www.phpbb.com/support/documents.php?mode=changelog</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml" source="GENTOO">GLSA-200503-02</ref>
      <ref url="http://secunia.com/advisories/14362/" source="SECUNIA">14362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0260" published="2005-05-02" name="CVE-2005-0260" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=194&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050209 Computer Associates BrightStor ARCserve Backup v11 Discovery Service Remote Buffer Overflow Vulnerability</ref>
      <ref url="http://supportconnectw.ca.com/public/enews/BrightStor/brigcurrent.asp#news1" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/enews/BrightStor/brigcurrent.asp#news1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19251" source="XF">brightstor-discovery-bo(19251)</ref>
      <ref url="http://securitytracker.com/id?1013138" source="SECTRACK">1013138</ref>
      <ref url="http://secunia.com/advisories/14183" source="SECUNIA">14183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0261" published="2005-02-10" name="CVE-2005-0261" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67655&amp;apar=only" source="AIXAPAR" patch="1" adv="1">IY67655</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67457&amp;apar=only" source="AIXAPAR" patch="1" adv="1">IY67457</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19281" source="XF">ibm-aix-ispath-information-disclosure(19281)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=195&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050210 IBM AIX lspath Local File Access Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12513" source="BID">12513</ref>
      <ref url="http://secunia.com/advisories/14232" source="SECUNIA">14232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0262" published="2005-05-02" name="CVE-2005-0262" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=196&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050210 IBM AIX ipl_varyon Local Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19282" source="XF">ibm-aix-iplvaryon-bo(19282)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67812&amp;apar=only" source="AIXAPAR">IY67812</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67750&amp;apar=only" source="AIXAPAR">IY67750</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY66933&amp;apar=only" source="AIXAPAR">IY66933</ref>
      <ref url="http://www.securityfocus.com/bid/12516" source="BID">12516</ref>
      <ref url="http://secunia.com/advisories/14231" source="SECUNIA">14231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0263" published="2005-05-02" name="CVE-2005-0263" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=197&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050210 IBM AIX netpmon Local Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19278" source="XF">ibm-aix-netpmon-bo(19278)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67807&amp;apar=only" source="AIXAPAR">IY67807</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67136&amp;apar=only" source="AIXAPAR">IY67136</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67124&amp;apar=only" source="AIXAPAR">IY67124</ref>
      <ref url="http://www.securityfocus.com/bid/12517" source="BID">12517</ref>
      <ref url="http://secunia.com/advisories/14237" source="SECUNIA">14237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0264" published="2005-05-02" name="CVE-2005-0264" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461644407935&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050101 Various Vulnerabilities in OWL Intranet Engine</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18705" source="XF">owl-intranet-engine-xss(18705)</ref>
      <ref url="http://www.securityfocus.com/bid/12114" source="BID">12114</ref>
      <ref url="http://secunia.com/advisories/13695" source="SECUNIA">13695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="owl" name="owl_intranet_engine">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0265" published="2005-05-02" name="CVE-2005-0265" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12114" source="BID" patch="1">12114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18704" source="XF">owl-intranet-engine-sql-injection(18704)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461644407935&amp;w=2" source="BUGTRAQ" adv="1">20050101 Various Vulnerabilities in OWL Intranet Engine</ref>
      <ref url="http://secunia.com/advisories/13695" source="SECUNIA">13695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="owl" name="owl_intranet_engine">
        <vers num="0.7" />
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0266" published="2005-01-01" name="CVE-2005-0266" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461706232174&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050101 Cross Site Scripting Vulnerabilities and Possible Code Execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18719" source="XF">sugar-sales-index-xss(18719)</ref>
      <ref url="http://www.securityfocus.com/bid/12113" source="BID">12113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sugarcrm" name="sugarcrm">
        <vers num="1.0" />
        <vers num="1.0f" />
        <vers num="1.0g" />
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers num="1.1b" />
        <vers num="1.1c" />
        <vers num="1.1d" />
        <vers num="1.1e" />
        <vers num="1.1f" />
        <vers num="1.5d" />
        <vers num="2.0.1" />
        <vers num="2.0.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0267" published="2005-05-02" name="CVE-2005-0267" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12150" source="BID" patch="1">12150</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18741" source="XF">flatnuke-indexphp-gain-access(18741)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2" source="BUGTRAQ" adv="1">20050102 Multiple Vulnerabilities in FlatNuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0268" published="2005-01-03" name="CVE-2005-0268" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18746" source="XF" patch="1" adv="1">flatnuke-indexphp-xss(18746)</ref>
      <ref url="http://www.securityfocus.com/bid/12150" source="BID" patch="1" adv="1">12150</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2" source="BUGTRAQ" adv="1">20050102 Multiple Vulnerabilities in FlatNuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0269" published="2005-05-02" name="CVE-2005-0269" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18729" source="XF" patch="1">gnuboard-gbupdate-file-upload(18729)</ref>
      <ref url="http://www.securityfocus.com/bid/12149" source="BID">12149</ref>
      <ref url="http://secunia.com/advisories/13711" source="SECUNIA">13711</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477648219738&amp;w=2" source="BUGTRAQ" adv="1">20050103 STG Security Advisory: [SSA-20041224-21] File extensions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sir" name="gnuboard">
        <vers num="3.30" />
        <vers num="3.31" />
        <vers num="3.32" />
        <vers num="3.33" />
        <vers num="3.34" />
        <vers num="3.35" />
        <vers num="3.36" />
        <vers num="3.37" />
        <vers num="3.38" />
        <vers num="3.39" />
        <vers num="3.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0270" published="2005-05-02" name="CVE-2005-0270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18731" source="XF">reviewpost-php-xss(18731)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref>
      <ref url="http://secunia.com/advisories/13697/" source="SECUNIA" adv="1">13697</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2" source="BUGTRAQ" adv="1">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="reviewpost_php_pro">
        <vers num="1.0.2" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers prev="1" num="2.84" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0271" published="2005-01-03" name="CVE-2005-0271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18732" source="XF" patch="1" adv="1">reviewpost-php-sql-injection(18732)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref>
      <ref url="http://secunia.com/advisories/13697/" source="SECUNIA" patch="1" adv="1">13697</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="reviewpost_php_pro">
        <vers num="1.0.2" />
        <vers num="2.5" />
        <vers prev="1" num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0272" published="2005-05-02" name="CVE-2005-0272" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13697/" source="SECUNIA" patch="1" adv="1">13697</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18735" source="XF">reviewpost-php-file-upload(18735)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="reviewpost_php_pro">
        <vers num="1.0.2" />
        <vers num="2.5" />
        <vers prev="1" num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0273" published="2005-05-02" name="CVE-2005-0273" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18744" source="XF" patch="1">photopost-php-showgallery-xss(18744)</ref>
      <ref url="http://www.securityfocus.com/bid/12156" source="BID">12156</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref>
      <ref url="http://secunia.com/advisories/13680/" source="SECUNIA" adv="1">13680</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2" source="BUGTRAQ" adv="1">20050103 Multiple PhotoPost Pro Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers prev="1" num="4.85" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0274" published="2005-01-03" name="CVE-2005-0274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18744" source="XF" patch="1" adv="1">photopost-php-showgallery-xss(18744)</ref>
      <ref url="http://www.securityfocus.com/bid/12156" source="BID" patch="1" adv="1">12156</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050103 Multiple PhotoPost Pro Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/13680/" source="SECUNIA" adv="1">13680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers prev="1" num="4.85" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0275" published="2005-05-02" name="CVE-2005-0275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18750" source="XF">3cdaemon-reserved-name-dos(18750)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2" source="BUGTRAQ" adv="1">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cdaemon">
        <vers num="2.0" edition="revision_10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0276" published="2005-05-02" name="CVE-2005-0276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18751" source="XF">3cdaemon-login-dos(18751)</ref>
      <ref url="http://www.securityfocus.com/bid/12155" source="BID">12155</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2" source="BUGTRAQ" adv="1">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cdaemon">
        <vers num="2.0" edition="revision_10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0277" published="2005-05-02" name="CVE-2005-0277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18754" source="XF">3cdaemon-long-command-dos(18754)</ref>
      <ref url="http://www.securityfocus.com/bid/12155" source="BID">12155</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886719528518&amp;w=2" source="BUGTRAQ">20050218 3com 3CDaemon FTP Unauthorized "USER" Remote BOverflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2" source="BUGTRAQ" adv="1">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cdaemon">
        <vers num="2.0" edition="revision_10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0278" published="2005-05-02" name="CVE-2005-0278" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18756" source="XF">3cdaemon-command-obtain-information(18756)</ref>
      <ref url="http://www.securityfocus.com/bid/12155" source="BID">12155</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2" source="BUGTRAQ" adv="1">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cdaemon">
        <vers num="2.0" edition="revision_10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0279" published="2005-05-02" name="CVE-2005-0279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Soldner Secret Wars 30830 and earlier does not properly handle the "message too long" socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18749" source="XF">soldner-secret-wars-dos(18749)</ref>
      <ref url="http://www.securityfocus.com/bid/12162" source="BID">12162</ref>
      <ref url="http://secunia.com/advisories/13716" source="SECUNIA">13716</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2" source="BUGTRAQ">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jowood_productions" name="soldner_secret_wars">
        <vers prev="1" num="30830" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0280" published="2005-01-04" name="CVE-2005-0280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18752" source="XF" adv="1">soldner-secret-wars-format-string(18752)</ref>
      <ref url="http://www.securityfocus.com/bid/12162" source="BID" adv="1">12162</ref>
      <ref url="http://secunia.com/advisories/13716" source="SECUNIA">13716</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2" source="BUGTRAQ" adv="1">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jowood_productions" name="soldner_secret_wars">
        <vers num="30830" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0281" published="2005-05-02" name="CVE-2005-0281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or quoted when the administrator views the server logs.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18753" source="XF">soldner-secret-wars-xss(18753)</ref>
      <ref url="http://www.securityfocus.com/bid/12162" source="BID">12162</ref>
      <ref url="http://secunia.com/advisories/13716" source="SECUNIA">13716</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2" source="BUGTRAQ" adv="1">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jowood_productions" name="soldner_secret_wars">
        <vers prev="1" num="30830" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0282" published="2005-05-02" name="CVE-2005-0282" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/187" source="XF">mybb-member-sql-injection(18755)</ref>
      <ref url="http://www.securityfocus.com/bid/12161" source="BID">12161</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486566600980&amp;w=2" source="BUGTRAQ" adv="1">20050104 MyBB SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0283" published="2005-01-04" name="CVE-2005-0283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18748" source="XF" adv="1">qwikiwiki-directory-traversal(18748)</ref>
      <ref url="http://www.securityfocus.com/bid/12163" source="BID" adv="1">12163</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486832621053&amp;w=2" source="BUGTRAQ" adv="1">20050104 QWikiwiki directory traversal vulnerability</ref>
      <ref url="http://www.qwikiwiki.com/index.php?page=QwikiVulnerability" source="CONFIRM">http://www.qwikiwiki.com/index.php?page=QwikiVulnerability</ref>
      <ref url="http://secunia.com/advisories/12044" source="SECUNIA">12044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_barrett" name="qwikiwiki">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0284" published="2005-01-10" name="CVE-2005-0284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18859" source="XF" adv="1">woltlab-book-addentry-sql-injection(18859)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548032401506&amp;w=2" source="BUGTRAQ" adv="1">20050110 Woltlab Burning Book addentry.php SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_book">
        <vers num="1.0_gold" />
        <vers num="1.1.1e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0285" published="2005-05-02" name="CVE-2005-0285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18848" source="XF">webseries-pa-url-security-bypass(18848)</ref>
      <ref url="http://www.securityfocus.com/bid/12216" source="BID">12216</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547396124885&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-001</ref>
      <ref url="http://securitytracker.com/id?1012854" source="SECTRACK">1012854</ref>
      <ref url="http://secunia.com/advisories/13821" source="SECUNIA">13821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bottomline" name="webseries_payment_application">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0286" published="2005-05-02" name="CVE-2005-0286" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18861" source="XF">mediapartner-bhtml-source-disclosure(18861)</ref>
      <ref url="http://www.securityfocus.com/bid/12236" source="BID">12236</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547824902053&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-004</ref>
      <ref url="http://securitytracker.com/id?1012855" source="SECTRACK">1012855</ref>
      <ref url="http://secunia.com/advisories/13820" source="SECUNIA">13820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emotion" name="mediapartner_web_server">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0287" published="2005-01-10" name="CVE-2005-0287" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18862" source="XF" adv="1">webseries-report-execution(18862)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548383812462&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-009</ref>
      <ref url="http://securitytracker.com/id?1012854" source="SECTRACK">1012854</ref>
      <ref url="http://secunia.com/advisories/13821" source="SECUNIA">13821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bottomline" name="webseries_payment_application">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0288" published="2005-01-11" name="CVE-2005-0288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18860" source="XF" adv="1">webseries-pa-password-gain-access(18860)</ref>
      <ref url="http://www.securityfocus.com/bid/12231" source="BID" adv="1">12231</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549684319400&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-008</ref>
      <ref url="http://securitytracker.com/id?1012854" source="SECTRACK">1012854</ref>
      <ref url="http://secunia.com/advisories/13821" source="SECUNIA">13821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bottomline" name="webseries_payment_application">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0289" published="2005-05-02" name="CVE-2005-0289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110582124528867&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050115 Apple Airport WDS DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18865" source="XF">apple-airport-dos(18865)</ref>
      <ref url="http://www.securityfocus.com/bid/12152" source="BID">12152</ref>
      <ref url="http://secunia.com/advisories/13753" source="SECUNIA">13753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="airport_express">
        <vers prev="1" num="6.1" />
      </prod>
      <prod vendor="apple" name="airport_extreme">
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0290" published="2005-01-17" name="CVE-2005-0290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18920" source="XF" adv="1">netgear-fvs318-filter-bypass(18920)</ref>
      <ref url="http://www.securityfocus.com/bid/12278" source="BID" adv="1">12278</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2" source="BUGTRAQ" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html" source="FULLDISC" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
      <ref url="http://securitytracker.com/id?1012913" source="SECTRACK">1012913</ref>
      <ref url="http://secunia.com/advisories/13787" source="SECUNIA">13787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="fvs318">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0291" published="2005-01-17" name="CVE-2005-0291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18921" source="XF" adv="1">netgear-fvs318-log-xss(18921)</ref>
      <ref url="http://www.securityfocus.com/bid/12278" source="BID" adv="1">12278</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2" source="BUGTRAQ" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html" source="FULLDISC" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
      <ref url="http://www.osvdb.org/13012" source="OSVDB">13012</ref>
      <ref url="http://securitytracker.com/id?1012913" source="SECTRACK">1012913</ref>
      <ref url="http://secunia.com/advisories/13787" source="SECUNIA">13787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="fvs318">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0292" published="2005-01-17" name="CVE-2005-0292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12289" source="BID" patch="1" adv="1">12289</ref>
      <ref url="http://www.securityfocus.com/archive/1/392485" source="BUGTRAQ" patch="1" adv="1">20050307 Re: phpGiftReq SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18925" source="XF" adv="1">phpgiftregistry-sql-injection(18925)</ref>
      <ref url="http://secunia.com/advisories/13873" source="SECUNIA" adv="1">13873</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599710017066&amp;w=2" source="BUGTRAQ" adv="1">20050116 phpGiftReq SQL Injection</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html" source="FULLDISC" adv="1">20050116 phpGiftReq SQL Injection</ref>
      <ref url="http://securitytracker.com/id?1012910" source="SECTRACK">1012910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_gift_registry" name="phpgiftreg">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0293" published="2005-05-02" name="CVE-2005-0293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18928" source="XF">minis-month-directory-traversal(18928)</ref>
      <ref url="http://www.securityfocus.com/bid/12279" source="BID">12279</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2" source="BUGTRAQ" adv="1">20050116 Minis directory traversal vulnerability</ref>
      <ref url="http://securitytracker.com/id?1012911" source="SECTRACK">1012911</ref>
      <ref url="http://secunia.com/advisories/13866" source="SECUNIA">13866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minis" name="minis">
        <vers num="0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0294" published="2005-01-16" name="CVE-2005-0294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18929" source="XF" adv="1">minis-month-dos(18929)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2" source="BUGTRAQ" adv="1">20050116 Minis directory traversal vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030966.html" source="FULLDISC" adv="1">20050116 Minis directory traversal vulnerability</ref>
      <ref url="http://securitytracker.com/id?1012911" source="SECTRACK">1012911</ref>
      <ref url="http://secunia.com/advisories/13866" source="SECUNIA">13866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minis" name="minis">
        <vers num="0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0295" published="2005-01-17" name="CVE-2005-0295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18952" source="XF" adv="1">nprotect-npptnt2-gain-access(18952)</ref>
      <ref url="http://www.securityfocus.com/bid/12280" source="BID" adv="1">12280</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608422029555&amp;w=2" source="BUGTRAQ" adv="1">20050116 Unrestricted I/O access vulnerability in INCA Gameguard</ref>
      <ref url="http://secunia.com/advisories/13928" source="SECUNIA">13928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inca" name="nprotect_gameguard">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0296" published="2005-01-17" name="CVE-2005-0296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page.  NOTE: the vendor has disputed this issue.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18954" source="XF" adv="1">groupwise-error-auth-bypass(18954)</ref>
      <ref url="http://www.securityfocus.com/bid/12285" source="BID" adv="1">12285</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.html" source="BUGTRAQ" adv="1">20050127 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.html" source="FULLDISC" adv="1">20050121 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref>
      <ref url="http://support.novell.com/servlet/tidfinder/10096251" source="MISC" adv="1">http://support.novell.com/servlet/tidfinder/10096251</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608203729814&amp;w=2" source="BUGTRAQ" adv="1">20050117 Novell GroupWise WebAccess error modules loading</ref>
      <ref url="http://www.osvdb.org/13135" source="OSVDB">13135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.0" edition="sp4" />
        <vers num="6.5" edition="sp1" />
        <vers num="6.5" edition="sp2" />
      </prod>
      <prod vendor="novell" name="groupwise_webaccess">
        <vers num="6.0" edition="sp4" />
        <vers num="6.5" edition="sp1" />
        <vers num="6.5" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0297" published="2005-01-18" name="CVE-2005-0297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110606477308492&amp;w=2" source="BUGTRAQ" adv="1">20050118 Multiple high risk vulnerabilities in Oracle RDBMS 10g/9i</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.1" edition="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0298" published="2005-05-02" name="CVE-2005-0298" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18947" source="XF" patch="1">oracle-directory-lob-obtain-info(18947)</ref>
      <ref url="http://www.petefinnigan.com/directory_traversal.pdf" source="MISC" patch="1" adv="1">http://www.petefinnigan.com/directory_traversal.pdf</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpu-jan-2005_advisory.pdf" source="MISC" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpu-jan-2005_advisory.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608912525883&amp;w=2" source="BUGTRAQ" adv="1">20050118 PeteFinnigan.com - Oracle security advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.2" />
        <vers num="10.1.0.3" />
        <vers num="10.1.0.3.1" />
        <vers num="8.0.6" />
        <vers num="8.0.6.3" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.4" />
        <vers num="9.0.1.5" />
        <vers num="9.0.4" />
        <vers num="9.2.0.4" />
        <vers num="9.2.0.5" />
        <vers num="9.2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0299" published="2005-05-02" name="CVE-2005-0299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12318" source="BID" patch="1">12318</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627132209963&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050120 STG Security Advisory: [SSA-20050120-24] GForge 3.x directory</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18988" source="XF">gforge-dir-dirname-directory-traversal(18988)</ref>
      <ref url="http://securitytracker.com/id?1012950" source="SECTRACK">1012950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.21" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0300" published="2005-01-20" name="CVE-2005-0300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18990" source="XF" patch="1" adv="1">jsboard-session-file-include(18990)</ref>
      <ref url="http://www.securityfocus.com/bid/12319" source="BID" patch="1" adv="1">12319</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627201120011&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050120 STG Security Advisory: [SSA-20050120-22] JSBoard file disclosure</ref>
      <ref url="http://securitytracker.com/id?1012949" source="SECTRACK">1012949</ref>
      <ref url="http://secunia.com/advisories/13920" source="SECUNIA">13920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jsboard" name="jsboard">
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0301" published="2005-05-02" name="CVE-2005-0301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19010" source="XF" patch="1">backoffice-lite-administrative-bypass(19010)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref>
      <ref url="http://www.comersus.org/forum/displayMessage.asp?mid=32753" source="CONFIRM" adv="1">http://www.comersus.org/forum/displayMessage.asp?mid=32753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_backoffice_lite">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0302" published="2005-05-02" name="CVE-2005-0302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19013" source="XF" patch="1">backoffice-lite-sql-injection(19013)</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html" source="MISC" patch="1">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_backoffice_lite">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0303" published="2005-05-02" name="CVE-2005-0303" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19014" source="XF" patch="1">backoffice-lite-xss(19014)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_backoffice_lite">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0304" published="2005-05-02" name="CVE-2005-0304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in DivX Player 2.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename in a ZIP file for a skin.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19030" source="XF">divx-player-directory-traversal(19030)</ref>
      <ref url="http://www.securityfocus.com/bid/12332" source="BID">12332</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642748517854&amp;w=2" source="BUGTRAQ" adv="1">20050121 Arbitrary files overwriting through skins in DivX Player 2.6</ref>
      <ref url="http://secunia.com/advisories/13969" source="SECUNIA">13969</ref>
      <ref url="http://aluigi.altervista.org/adv/divxplayer-adv.txt" source="MISC">http://aluigi.altervista.org/adv/divxplayer-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="divx" name="divx_player">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0305" published="2005-05-02" name="CVE-2005-0305" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18998" source="XF">siteman-gain-access(18998)</ref>
      <ref url="http://www.securityfocus.com/bid/12304" source="BID">12304</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110643320814371&amp;w=2" source="BUGTRAQ">20050122 Siteman User Database Line Insertion Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627350616949&amp;w=2" source="BUGTRAQ" adv="1">20050120 God Admin Injection Vulnerability in Siteman 1.0.x,</ref>
      <ref url="http://www.osvdb.org/13131" source="OSVDB">13131</ref>
      <ref url="http://securitytracker.com/id?1012951" source="SECTRACK">1012951</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siteman" name="siteman">
        <vers num="1.1.10" />
        <vers num="1.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0306" published="2005-01-25" name="CVE-2005-0306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19048" source="XF" patch="1" adv="1">mercuryboard-multiple-script-path-disclosure(19048)</ref>
      <ref url="http://www.securityfocus.com/bid/12359" source="BID" patch="1" adv="1">12359</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2" source="BUGTRAQ" adv="1">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0307" published="2005-01-25" name="CVE-2005-0307" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19050" source="XF" patch="1" adv="1">mercuryboard-multiple-scripts-xss(19050)</ref>
      <ref url="http://www.securityfocus.com/bid/12359" source="BID" patch="1" adv="1">12359</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2" source="BUGTRAQ" adv="1">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0308" published="2005-01-24" name="CVE-2005-0308" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19044" source="XF" adv="1">w32dasm-wsprintf-bo(19044)</ref>
      <ref url="http://www.securityfocus.com/bid/12352" source="BID" adv="1">12352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661194108205&amp;w=2" source="BUGTRAQ" adv="1">20050124 Local buffer-overflow in W32Dasm 8.93</ref>
      <ref url="http://securitytracker.com/id?1012997" source="SECTRACK">1012997</ref>
      <ref url="http://secunia.com/advisories/13986" source="SECUNIA">13986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ursoftware" name="w32dasm">
        <vers num="8.94" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0309" published="2005-01-25" name="CVE-2005-0309" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19061" source="XF" adv="1">exponent-module-xss(19061)</ref>
      <ref url="http://www.securityfocus.com/bid/12358" source="BID" adv="1">12358</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110666998407073&amp;w=2" source="BUGTRAQ" adv="1">20050125 Vulnerabilities in eXponent 0.95</ref>
      <ref url="http://www.osvdb.org/13190" source="OSVDB">13190</ref>
      <ref url="http://www.osvdb.org/13188" source="OSVDB">13188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exponent" name="exponent">
        <vers num="0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0310" published="2005-05-02" name="CVE-2005-0310" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19064" source="XF">exponent-pathoscoreversion-path-disclosure(19064)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110666998407073&amp;w=2" source="BUGTRAQ" adv="1">20050125 Vulnerabilities in eXponent 0.95</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exponent" name="exponent">
        <vers num="0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0311" published="2005-05-02" name="CVE-2005-0311" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19123" source="XF">ingate-firewall-unath-access(19123)</ref>
      <ref url="http://www.securityfocus.com/bid/12383" source="BID">12383</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110684375429946&amp;w=2" source="BUGTRAQ" adv="1">20050127 Ingate Firewall: Removed PPTP tunnels not deactivated</ref>
      <ref url="http://www.ingate.com/relnote-422.php" source="CONFIRM">http://www.ingate.com/relnote-422.php</ref>
      <ref url="http://securitytracker.com/id?1013022" source="SECTRACK">1013022</ref>
      <ref url="http://secunia.com/advisories/14060" source="SECUNIA">14060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ingate" name="ingate_firewall">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.3.1" />
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0312" published="2005-01-27" name="CVE-2005-0312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12384" source="BID" patch="1" adv="1">12384</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110687202332039&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050127 WarFTPD 1.82 RC9 DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19129" source="XF">warftpd-cwd-dos(19129)</ref>
      <ref url="http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643" source="CONFIRM" adv="1">http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="war_ftp_daemon" name="war_ftp_daemon">
        <vers num="1.8" />
        <vers num="1.82_rc9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0313" published="2005-01-27" name="CVE-2005-0313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19114" source="XF" patch="1" adv="1">magic-winmail-command-directory-traversal(19114)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19108" source="XF" patch="1" adv="1">magicwinmail-uploadphp-file-upload(19108)</ref>
      <ref url="http://www.securityfocus.com/bid/12388" source="BID" patch="1" adv="1">12388</ref>
      <ref url="http://securitytracker.com/id?1013017" source="SECTRACK">1013017</ref>
      <ref url="http://secunia.com/advisories/14053" source="SECUNIA">14053</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" source="BUGTRAQ" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amax_information_technologies" name="magic_winmail_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0314" published="2005-01-27" name="CVE-2005-0314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19113" source="XF" patch="1" adv="1">magic-winmail-userphp-xss(19113)</ref>
      <ref url="http://www.securityfocus.com/bid/12388" source="BID" patch="1" adv="1">12388</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1013017" source="SECTRACK">1013017</ref>
      <ref url="http://secunia.com/advisories/14053" source="SECUNIA">14053</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0315" published="2005-01-27" name="CVE-2005-0315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19115" source="XF" patch="1" adv="1">magicwinmail-ftp-obtain-information(19115)</ref>
      <ref url="http://www.securityfocus.com/bid/12388" source="BID" patch="1" adv="1">12388</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1013017" source="SECTRACK">1013017</ref>
      <ref url="http://secunia.com/advisories/14053" source="SECUNIA">14053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amax_information_technologies" name="magic_winmail_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0316" published="2005-01-28" name="CVE-2005-0316" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12394" source="BID" patch="1" adv="1">12394</ref>
      <ref url="http://secunia.com/advisories/14058" source="SECUNIA" patch="1" adv="1">14058</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19144" source="XF" adv="1">webwasher-classic-connect-gain-access(19144)</ref>
      <ref url="http://www.oliverkarow.de/research/WebWasherCONNECT.txt" source="MISC" adv="1">http://www.oliverkarow.de/research/WebWasherCONNECT.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693045507245&amp;w=2" source="BUGTRAQ" adv="1">20050128 WebWasher Classic - HTTP CONNECT weakness</ref>
      <ref url="http://securitytracker.com/id?1013036" source="SECTRACK">1013036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webwasher" name="webwasher_classic">
        <vers num="2.2.1" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0317" published="2005-01-28" name="CVE-2005-0317" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19161" source="XF" patch="1" adv="1">webadmin-usereditaccountwdm-xss(19161)</ref>
      <ref url="http://www.securityfocus.com/bid/12395" source="BID" patch="1" adv="1">12395</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
      <ref url="http://securitytracker.com/id?1013038" source="SECTRACK">1013038</ref>
      <ref url="http://secunia.com/advisories/14079" source="SECUNIA">14079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0318" published="2005-01-28" name="CVE-2005-0318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12395" source="BID" patch="1">12395</ref>
      <ref url="http://securitytracker.com/id?1013038" source="SECTRACK">1013038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0319" published="2005-01-28" name="CVE-2005-0319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12395" source="BID" patch="1" adv="1">12395</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19162" source="XF" adv="1">webadmin-html-injection(19162)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0320" published="2005-01-28" name="CVE-2005-0320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12396" source="BID" patch="1" adv="1">12396</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19147" source="XF" adv="1">merak-icewarp-multiple-xss(19147)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0321" published="2005-05-02" name="CVE-2005-0321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allows remote authenticated users to gain sensitive information via an HTTP request to (1) calendar_d.html, (2) calendar_m.html, (3) calendar_w.html, or (4) calendar_y.html, which reveal the installation path.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19152" source="XF">merak-icewarp-user-path-disclosure(19152)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.3.0" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="7.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0322" published="2005-05-02" name="CVE-2005-0322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19153" source="XF">merak-icewarp-weak-password-encryption(19153)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.3.0" />
        <vers num="5.3.2" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="7.6.0" />
        <vers num="7.6.4r" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0323" published="2005-05-02" name="CVE-2005-0323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19151" source="XF">infinite-mobile-delivery-xss(19151)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110703630922262&amp;w=2" source="BUGTRAQ" adv="1">20050129 XSS in Infinite Mobile Delivery v2.6 Webmail</ref>
      <ref url="http://www.securityfocus.com/bid/12399" source="BID">12399</ref>
      <ref url="http://www.lovebug.org/imd_advisory.txt" source="MISC">http://www.lovebug.org/imd_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1013044" source="SECTRACK">1013044</ref>
      <ref url="http://secunia.com/advisories/14075" source="SECUNIA">14075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="captaris" name="infinite_mobile_delivery_webmail">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0324" published="2005-05-02" name="CVE-2005-0324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19154" source="XF">infinite-mobile-delivery-path-disclosure(19154)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110703630922262&amp;w=2" source="BUGTRAQ">20050129 XSS in Infinite Mobile Delivery v2.6 Webmail</ref>
      <ref url="http://www.securityfocus.com/bid/12399" source="BID">12399</ref>
      <ref url="http://www.lovebug.org/imd_advisory.txt" source="MISC">http://www.lovebug.org/imd_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1013044" source="SECTRACK">1013044</ref>
      <ref url="http://secunia.com/advisories/14075" source="SECUNIA">14075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="captaris" name="infinite_mobile_delivery_webmail">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0325" published="2005-05-02" name="CVE-2005-0325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large values that are not properly handled in certain malloc or memcpy operations.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19150" source="XF" patch="1">xpand-rally-memory-dos(19150)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031336.html" source="FULLDISC" patch="1">20050130 Broadcast crash in Xpand Rally 1.0.0.0</ref>
      <ref url="http://aluigi.altervista.org/adv/xprallyboom-adv.txt" source="MISC" patch="1">http://aluigi.altervista.org/adv/xprallyboom-adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12409" source="BID">12409</ref>
      <ref url="http://securitytracker.com/id?1013043" source="SECTRACK">1013043</ref>
      <ref url="http://secunia.com/advisories/14073" source="SECUNIA">14073</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720064811485&amp;w=2" source="BUGTRAQ">20050130 Broadcast crash in Xpand Rally 1.0.0.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="techland" name="xpand_rally">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0326" published="2005-05-02" name="CVE-2005-0326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720365923818&amp;w=2" source="BUGTRAQ" patch="1">20050131 [PersianHacker.net] Full Path Disclosure and PHP Injection In Pafiledb 3.1 Final</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19175" source="XF">pafiledb-login-path-disclosure(19175)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0327" published="2005-05-02" name="CVE-2005-0327" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19176" source="XF">pafiledb-login-file-include(19176)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720365923818&amp;w=2" source="BUGTRAQ">20050131 [PersianHacker.net] Full Path Disclosure and PHP Injection In Pafiledb 3.1 Final</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0328" published="2005-05-02" name="CVE-2005-0328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN's MAC address.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20609" source="XF">zyxel-netgear-ping-information-disclosure(20609)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720465527599&amp;w=2" source="BUGTRAQ" adv="1">20050131 Zyxel / Netgear and probably other routers leaking information.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="rt311">
        <vers num="" />
      </prod>
      <prod vendor="netgear" name="rt314">
        <vers num="" />
      </prod>
      <prod vendor="zyxel" name="prestige">
        <vers num="310" />
        <vers num="314" />
        <vers num="324" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0329" published="2005-05-02" name="CVE-2005-0329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ZipGenius 5.5 and earlier allows remote attackers to create and possibly modify arbitrary files via a ZIP file with a file whose name includes .. (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12419" source="BID" patch="1">12419</ref>
      <ref url="http://securitytracker.com/id?1013542" source="SECTRACK" patch="1">1013542</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110736990230696&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050202 7a69Adv#19 - ZipGenius unpack path disclosure</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19203" source="XF">zipgenius-path-disclosure(19203)</ref>
      <ref url="http://secunia.com/advisories/14123" source="SECUNIA">14123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zipgenius" name="zipgenius">
        <vers num="standard_5.5" />
        <vers num="suite_5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0330" published="2005-05-02" name="CVE-2005-0330" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in Painkiller 1.35 and earlier, and possibly other versions before 1.61, allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a long cd-key hash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19205" source="XF" patch="1">painkiller-long-cdkey-bo(19205)</ref>
      <ref url="http://www.securityfocus.com/bid/12423" source="BID" patch="1">12423</ref>
      <ref url="http://secunia.com/advisories/14113/" source="SECUNIA" patch="1">14113</ref>
      <ref url="http://securitytracker.com/id?1013066" source="SECTRACK">1013066</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110736915015707&amp;w=2" source="BUGTRAQ">20050202 Limited buffer-overflow in Painkiller 1.35</ref>
    </refs>
    <vuln_soft>
      <prod vendor="people_can_fly" name="painkiller">
        <vers num="1.3.1" />
        <vers num="1.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0331" published="2005-05-02" name="CVE-2005-0331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20585" source="XF">winrar-dotdotdotdirectory-traversal(20585)</ref>
      <ref url="http://www.securityfocus.com/bid/12422" source="BID">12422</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737609604210&amp;w=2" source="BUGTRAQ" adv="1">20050202 7a69Adv#21 - WinRAR unpack one-folder path disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rarlab" name="winrar">
        <vers num="3.0.0" />
        <vers num="3.10" />
        <vers num="3.10_beta3" />
        <vers num="3.10_beta5" />
        <vers num="3.11" />
        <vers num="3.20" />
        <vers num="3.40" />
        <vers num="3.41" />
        <vers num="3.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0332" published="2005-05-02" name="CVE-2005-0332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19211" source="XF" patch="1">desknow-jsp-gain-access(19211)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19206" source="XF" patch="1">desknow-attachmentkey-file-upload(19206)</ref>
      <ref url="http://www.securityfocus.com/bid/12421" source="BID" patch="1">12421</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19212" source="XF">desknow-filedo-file-deletion(19212)</ref>
      <ref url="http://www.security.org.sg/vuln/desknow2512.html" source="MISC" adv="1">http://www.security.org.sg/vuln/desknow2512.html</ref>
      <ref url="http://securitytracker.com/id?1013060" source="SECTRACK">1013060</ref>
      <ref url="http://secunia.com/advisories/14116" source="SECUNIA">14116</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737616324614&amp;w=2" source="BUGTRAQ" adv="1">20050202 [SIG^2 G-TEC] DeskNow Mail and Collaboration Server Directory Traversal Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ventia" name="desknow_mail_and_collaboration_server">
        <vers num="2.5.12" />
        <vers num="2.5.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0333" published="2005-05-02" name="CVE-2005-0333" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LANChat Pro Revival 1.666c allows remote attackers to cause a denial of service (application crash) via a malformed UDP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19213" source="XF">lanchatpro-udp-packet-dos(19213)</ref>
      <ref url="http://www.securityfocus.com/bid/12439" source="BID">12439</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/LANChatRevival1.666c-adv.txt" source="MISC" adv="1">http://www.autistici.org/fdonato/advisory/LANChatRevival1.666c-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746524021133&amp;w=2" source="BUGTRAQ" adv="1">20050203 DoS in LANChat Pro Revival 1.666c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lanchat_pro_revival" name="lanchat_pro_revival">
        <vers num="1.666c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0334" published="2005-05-02" name="CVE-2005-0334" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linksys PSUS4 running firmware 6032 allows remote attackers to cause a denial of service (device crash) via an HTTP POST request containing an unknown parameter without a value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19222" source="XF">linksys-psus4-dos(19222)</ref>
      <ref url="http://www.securityfocus.com/bid/12443" source="BID">12443</ref>
      <ref url="http://secunia.com/advisories/14136" source="SECUNIA" adv="1">14136</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110747234701646&amp;w=2" source="BUGTRAQ" adv="1">20050203 [ RSTACK Public Security Advisory ] Remote DOS against Linksys PSUS4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="psus4_printserver">
        <vers num="6032" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0335" published="2005-05-02" name="CVE-2005-0335" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18842" source="XF">mediapartner-dotdot-directory-traversal(18842)</ref>
      <ref url="http://www.securityfocus.com/bid/12236" source="BID">12236</ref>
      <ref url="http://securitytracker.com/id?1012838" source="SECTRACK">1012838</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547214224714&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-010</ref>
      <ref url="http://secunia.com/advisories/13820" source="SECUNIA">13820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emotion" name="mediapartner_web_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0336" published="2005-05-02" name="CVE-2005-0336" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to inject arbitrary HTML or web script, as demonstrated using a URL containing .. sequences and HTML, which results in a directory browsing page that does not properly filter the HTML.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18845" source="XF">mediapartner-url-xss(18845)</ref>
      <ref url="http://www.securityfocus.com/bid/12236" source="BID">12236</ref>
      <ref url="http://securitytracker.com/id?1012838" source="SECTRACK">1012838</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547214224714&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-010</ref>
      <ref url="http://secunia.com/advisories/13820" source="SECUNIA">13820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emotion" name="mediapartner_web_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0337" published="2005-05-02" name="CVE-2005-0337" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19218" source="XF" patch="1">postfix-ipv6-security-bypass(19218)</ref>
      <ref url="http://www.securityfocus.com/bid/12445" source="BID" patch="1">12445</ref>
      <ref url="http://secunia.com/advisories/14137/" source="SECUNIA" patch="1">14137</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763358832637&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050204 [USN-74-1] Postfix vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11339" source="OVAL">oval:org.mitre.oval:def:11339</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=267837" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=267837</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-152.html" source="REDHAT">RHSA-2005:152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wietse_venema" name="postfix">
        <vers num="2.1.3" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0338" published="2005-05-02" name="CVE-2005-0338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19177" source="XF">savant-bo(19177)</ref>
      <ref url="http://www.securityfocus.com/bid/12429" source="BID">12429</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110728448025559&amp;w=2" source="FULLDISC">20050201 Remotely exploitable buffer overflow vulnerability in Savant Web Server 3.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110725682327452&amp;w=2" source="FULLDISC" adv="1">20050201 Remotely exploitable buffer overflow vulnerability in Savant Web Server 3.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110756234611259&amp;w=2" source="BUGTRAQ">20050204 Exploit For Savant Web Server 3.1 (tested on win2003)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="savant" name="savant_webserver">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0339" published="2005-05-02" name="CVE-2005-0339" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19229" source="XF">foxmail-mailfrom-bo(19229)</ref>
      <ref url="http://www.securityfocus.com/bid/12454" source="BID">12454</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763204301080&amp;w=2" source="BUGTRAQ" adv="1">20050205 Foxmail Server Remote Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxmail" name="foxmail_email_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0340" published="2005-05-02" name="CVE-2005-0340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19263" source="XF">Applefileserver-fploginext-dos(19263)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110791369419784&amp;w=2" source="BUGTRAQ" adv="1">20050208 AppleFileServer Denial of Service.</ref>
      <ref url="http://www.securityfocus.com/bid/12478" source="BID">12478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="afp_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0341" published="2005-05-02" name="CVE-2005-0341" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19227" source="XF">safari-contenttype-xss(19227)</ref>
      <ref url="http://tigger.uic.edu/~jrockw2/safari_20050204.txt" source="MISC" adv="1">http://tigger.uic.edu/~jrockw2/safari_20050204.txt</ref>
      <ref url="http://securitytracker.com/id?1013087" source="SECTRACK">1013087</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110756965213819&amp;w=2" source="BUGTRAQ" adv="1">20050204 Input Validation Vulnerability in Apple Safari version 1.2.4 v125.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0342" published="2005-05-02" name="CVE-2005-0342" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14188" source="SECUNIA" patch="1" adv="1">14188</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19253" source="XF">finder-dsstore-file-overwrite(19253)</ref>
      <ref url="http://www.securityfocus.com/bid/12458" source="BID">12458</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780124707975&amp;w=2" source="BUGTRAQ" adv="1">20050207 [OSX Finder] DS_Store arbitrary file overwrite vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0343" published="2005-05-02" name="CVE-2005-0343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12471" source="BID" patch="1">12471</ref>
      <ref url="http://secunia.com/advisories/12512" source="SECUNIA" patch="1">12512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19245" source="XF">perldesk-view-sql-injection(19245)</ref>
      <ref url="http://www.security-project.org/projects/board/showthread.php?p=5172#post5172" source="MISC" adv="1">http://www.security-project.org/projects/board/showthread.php?p=5172#post5172</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782042532295&amp;w=2" source="BUGTRAQ" adv="1">20050207 [SePro Bugtraq] SQL-Injection in PerlDesk 1.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logicnow" name="perldesk">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0344" published="2005-05-02" name="CVE-2005-0344" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.security.org.sg/vuln/602lansuite1221.html" source="MISC" patch="1" adv="1">http://www.security.org.sg/vuln/602lansuite1221.html</ref>
      <ref url="http://secunia.com/advisories/14169/" source="SECUNIA" patch="1" adv="1">14169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110793103506620&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050208 [SIG^2 G-TEC] 602LAN SUITE Web Mail Vulnerability Allows File Upload to Arbitrary Directories</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19258" source="XF">602lansuite-webmail-directory-traversal(19258)</ref>
      <ref url="http://securitytracker.com/id?1013106" source="SECTRACK">1013106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602lan_suite">
        <vers num="2004.0.04.1221" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0345" published="2005-05-02" name="CVE-2005-0345" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19257" source="XF">phpfusion-viewthread-obtain-information(19257)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110788267311132&amp;w=2" source="BUGTRAQ" adv="1">20050208 php-fusion 4.x vuln</ref>
      <ref url="http://www.securityfocus.com/bid/12482" source="BID">12482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0346" published="2005-05-02" name="CVE-2005-0346" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19256" source="XF">softremote-vpn-password-disclosure(19256)</ref>
      <ref url="http://www.nta-monitor.com/news/vpn-flaws/safenet/index.htm" source="MISC" adv="1">http://www.nta-monitor.com/news/vpn-flaws/safenet/index.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110791865522076&amp;w=2" source="BUGTRAQ" adv="1">20050208 SafeNet SoftRemote VPN Client Issue: Clear-text password</ref>
      <ref url="http://securitytracker.com/id?1013134" source="SECTRACK">1013134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="safenet" name="softremote_vpn_client">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0347" published="2005-05-02" name="CVE-2005-0347" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in RealArcade 1.2.0.994 and earlier allows remote attackers to execute arbitrary code via an RGS file with an invalid size string for the GUID and game name, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19259" source="XF">realarcade-rgs-bo(19259)</ref>
      <ref url="http://secunia.com/advisories/14187/" source="SECUNIA" adv="1">14187</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792779115794&amp;w=2" source="BUGTRAQ">20050208 Integer overflow and arbitrary files deletion in RealArcade</ref>
      <ref url="http://securitytracker.com/id?1013128" source="SECTRACK">1013128</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0348" published="2005-05-02" name="CVE-2005-0348" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RealArcade 1.2.0.994 allows remote attackers to delete arbitrary files via an RGP file with a .. (dot dot) in the FILENAME tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19260" source="XF">realarcade-rgp-file-deletion(19260)</ref>
      <ref url="http://www.securityfocus.com/bid/12494" source="BID">12494</ref>
      <ref url="http://secunia.com/advisories/14187/" source="SECUNIA" adv="1">14187</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792779115794&amp;w=2" source="BUGTRAQ">20050208 Integer overflow and arbitrary files deletion in RealArcade</ref>
      <ref url="http://securitytracker.com/id?1013128" source="SECTRACK">1013128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realarcade">
        <vers prev="1" num="1.2.0.994" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0349" published="2005-05-02" name="CVE-2005-0349" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The production release of the UniversalAgent for UNIX in BrightStor ARCserve Backup 11.1 contains hard-coded credentials, which allows remote attackers to access the file system and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=198&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050210 Computer Associates BrightStor ARCserve Backup UniversalAgent Backdoor Vulnerability</ref>
      <ref url="http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO63672&amp;os=UNIX&amp;returninput=0" source="CONFIRM" patch="1" adv="1">http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO63672&amp;os=UNIX&amp;returninput=0</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0145" source="VUPEN">ADV-2005-0145</ref>
      <ref url="http://www.securityfocus.com/bid/12522" source="BID">12522</ref>
      <ref url="http://www.osvdb.org/13706" source="OSVDB">13706</ref>
      <ref url="http://securitytracker.com/id?1013144" source="SECTRACK">1013144</ref>
      <ref url="http://secunia.com/advisories/14233" source="SECUNIA">14233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0350" published="2005-05-02" name="CVE-2005-0350" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/alerts/id/188" source="ISS" patch="1" adv="1">20050210 F-Secure AntiVirus Library Heap Overflow</ref>
      <ref url="http://www.f-secure.com/security/fsc-2005-1.shtml" source="CONFIRM" patch="1">http://www.f-secure.com/security/fsc-2005-1.shtml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2004" />
        <vers num="2005" />
        <vers prev="1" num="4.52" edition="" />
        <vers prev="1" num="4.52" edition=":linux_workstations" />
        <vers num="4.60" edition="" />
        <vers num="4.60" edition=":samba_servers" />
        <vers prev="1" num="4.61" edition="" />
        <vers prev="1" num="4.61" edition=":linux_servers" />
        <vers prev="1" num="4.61" edition=":linux_gateways" />
        <vers prev="1" num="5.01" edition="" />
        <vers prev="1" num="5.01" edition=":linux_server_security" />
        <vers prev="1" num="5.01" edition=":linux_client_security" />
        <vers prev="1" num="5.43" edition="" />
        <vers prev="1" num="5.43" edition=":workstations" />
        <vers prev="1" num="5.5" edition="" />
        <vers prev="1" num="5.5" edition=":windows_servers" />
        <vers prev="1" num="5.5" edition=":citrix_servers" />
        <vers prev="1" num="5.51" edition="" />
        <vers prev="1" num="5.51" edition=":mimesweeper" />
        <vers prev="1" num="5.55" edition="" />
        <vers prev="1" num="5.55" edition=":client_security" />
        <vers prev="1" num="6.2" edition="" />
        <vers prev="1" num="6.2" edition=":firewalls" />
        <vers prev="1" num="6.31" edition="" />
        <vers prev="1" num="6.31" edition=":ms_exchange" />
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2004" />
        <vers num="2005" />
      </prod>
      <prod vendor="f-secure" name="f-secure_personal_express">
        <vers prev="1" num="5.10" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="2.06" edition="" />
        <vers num="2.06" edition=":linux" />
        <vers prev="1" num="6.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0351" published="2005-04-07" name="CVE-2005-0351" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.15/SCOSA-2005.15.txt" source="SCO" patch="1" adv="1">SCOSA-2005.15</ref>
      <ref url="http://www.securityfocus.com/bid/13062" source="BID">13062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0352" published="2005-03-16" name="CVE-2005-0352" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19715" source="XF" adv="1">serversalive-gain-privileges(19715)</ref>
      <ref url="http://www.securityfocus.com/bid/12822" source="BID" adv="1">12822</ref>
      <ref url="http://secunia.com/advisories/14616/" source="SECUNIA" adv="1">14616</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100364513513&amp;w=2" source="BUGTRAQ" adv="1">20050316 Servers Alive: Local Privilege Escalation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woodstone" name="servers_alive">
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0353" published="2005-05-02" name="CVE-2005-0353" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/108790" source="CERT-VN" patch="1" adv="1">VU#108790</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-30-advisory.pdf" source="MISC" patch="1" adv="1">http://www.cirt.dk/advisories/cirt-30-advisory.pdf</ref>
      <ref url="http://secunia.com/advisories/14511" source="SECUNIA" patch="1" adv="1">14511</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19621" source="XF">sentinel-license-manager-bo(19621)</ref>
      <ref url="http://www.securityfocus.com/bid/12742" source="BID">12742</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111072872816405&amp;w=2" source="FULLDISC" adv="1">20050313 [HAT-SQUAD]  SafeNet Sentinel LM, UDP License Manager Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022094326772&amp;w=2" source="BUGTRAQ" adv="1">20050307 CIRT.DK Advisory - SafeNet Inc Sentinel License Manager 7.2.0.2 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="safenet" name="sentinel_license_manager">
        <vers num="7.2_.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0356" published="2005-05-31" name="CVE-2005-0356" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/637934" source="CERT-VN" adv="1">VU#637934</ref>
      <ref url="http://secunia.com/advisories/15417/" source="SECUNIA" patch="1">15417</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20635" source="XF">tcp-ip-timestamp-dos(20635)</ref>
      <ref url="http://www.securityfocus.com/bid/13676" source="BID">13676</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtml" source="CISCO" adv="1">20050518 Vulnerability in a Variant of the TCP Timestamps Option</ref>
      <ref url="http://secunia.com/advisories/15393" source="SECUNIA">15393</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-032.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-032.htm</ref>
      <ref url="http://secunia.com/advisories/18662" source="SECUNIA">18662</ref>
      <ref url="http://secunia.com/advisories/18222" source="SECUNIA">18222</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txt" source="SCO">SCOSA-2005.64</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc" source="FREEBSD">FreeBSD-SA-05:15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="agent_desktop">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_access_control_list_manager">
        <vers num="1.5" />
        <vers num="1.6" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="2.2" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_lms">
        <vers num="1.3" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_vpn_security_management_solution">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_windows">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="e-mail_manager">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="emergency_responder">
        <vers num="1.1" />
      </prod>
      <prod vendor="cisco" name="intelligent_contact_manager">
        <vers num="5.0" />
      </prod>
      <prod vendor="cisco" name="interactive_voice_response">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ip_contact_center_enterprise">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ip_contact_center_express">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="meetingplace">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="personal_assistant">
        <vers num="1.3(1)" />
        <vers num="1.3(2)" />
        <vers num="1.3(3)" />
        <vers num="1.3(4)" />
        <vers num="1.4(1)" />
        <vers num="1.4(2)" />
      </prod>
      <prod vendor="cisco" name="remote_monitoring_suite_option">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":unix" />
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":windows_nt" />
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":unix" />
        <vers num="2.3" edition=":windows_nt" />
        <vers num="2.3.5.1" edition="" />
        <vers num="2.3.5.1" edition=":unix" />
        <vers num="2.3.6.1" edition="" />
        <vers num="2.3.6.1" edition=":unix" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":windows_nt" />
        <vers num="2.42" edition="" />
        <vers num="2.42" edition=":windows_nt" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":windows_nt" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":windows_nt" />
        <vers num="2.6.2" edition="" />
        <vers num="2.6.2" edition=":windows_nt" />
        <vers num="2.6.3" edition="" />
        <vers num="2.6.3" edition=":windows_nt" />
        <vers num="2.6.4" edition="" />
        <vers num="2.6.4" edition=":windows_nt" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows_nt" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows_nt" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows_nt" />
        <vers num="3.1" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows_nt" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows_server" />
        <vers num="3.2(1)" />
        <vers num="3.2(1.20)" />
        <vers num="3.2(2)" />
        <vers num="3.2(3)" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.3" />
        <vers num="3.3(1)" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
      <prod vendor="cisco" name="secure_access_control_server_solution_engine">
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
      <prod vendor="cisco" name="support_tools">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="web_collaboration_option">
        <vers num="" />
      </prod>
      <prod vendor="f5" name="big-ip">
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.5.10" />
        <vers num="4.5.11" />
        <vers num="4.5.12" />
        <vers num="4.5.6" />
        <vers num="4.5.9" />
        <vers num="4.6" />
        <vers num="4.6.2" />
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.0.2" />
        <vers num="9.0.3" />
        <vers num="9.0.4" />
        <vers num="9.0.5" />
      </prod>
      <prod vendor="hitachi" name="alaxala">
        <vers num="ax" />
      </prod>
      <prod vendor="nortel" name="business_communications_manager">
        <vers num="1000" />
        <vers num="200" />
        <vers num="400" />
      </prod>
      <prod vendor="nortel" name="callpilot">
        <vers num="200i" />
        <vers num="201i" />
        <vers num="702t" />
        <vers num="703t" />
      </prod>
      <prod vendor="nortel" name="contact_center">
        <vers num="" />
      </prod>
      <prod vendor="alaxala" name="alaxala_networks">
        <vers num="ax5400s" />
        <vers num="ax7800r" />
        <vers num="ax7800s" />
      </prod>
      <prod vendor="cisco" name="aironet_ap1200">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="aironet_ap350">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1(2)" />
        <vers num="3.1(3a)" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3(3)" />
        <vers num="4.0" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11050">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11150">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11501">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11503">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11506">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11800">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="sn_5420_storage_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="unity_server">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.46" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
      </prod>
      <prod vendor="hitachi" name="gr3000">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="gr4000">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="gs4000">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="7220_wlan_access_point">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="7250_wlan_access_point">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="ethernet_routing_switch_1612">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="ethernet_routing_switch_1624">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="ethernet_routing_switch_1648">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="optical_metro_5000">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="optical_metro_5100">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="optical_metro_5200">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="succession_communication_server_1000">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="survivable_remote_gateway">
        <vers num="1.0" />
      </prod>
      <prod vendor="nortel" name="universal_signaling_point">
        <vers num="5200" />
        <vers num="compact_lite" />
      </prod>
      <prod vendor="yamaha" name="rt105">
        <vers num="" />
      </prod>
      <prod vendor="yamaha" name="rt250i">
        <vers num="" />
      </prod>
      <prod vendor="yamaha" name="rt300i">
        <vers num="" />
      </prod>
      <prod vendor="yamaha" name="rt57i">
        <vers num="" />
      </prod>
      <prod vendor="yamaha" name="rtv700">
        <vers num="" />
      </prod>
      <prod vendor="yamaha" name="rtx1000">
        <vers num="" />
      </prod>
      <prod vendor="yamaha" name="rtx1100">
        <vers num="" />
      </prod>
      <prod vendor="yamaha" name="rtx1500">
        <vers num="" />
      </prod>
      <prod vendor="yamaha" name="rtx2000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_1105_hosting_solution_engine">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_1105_wireless_lan_solution_engine">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_cd1">
        <vers num="1st" />
        <vers num="2nd" />
        <vers num="3rd" />
        <vers num="4th" />
        <vers num="5th" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_windows_wug">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="conference_connection">
        <vers num="1.1(1)" />
        <vers num="1.2" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="7.10_(05.07)s" />
        <vers num="7.20_(03.09)s" />
        <vers num="7.20_(03.10)s" />
        <vers num="7.30_(00.08)s" />
        <vers num="7.30_(00.09)s" />
      </prod>
      <prod vendor="cisco" name="mgx_8230">
        <vers num="1.2.10" />
        <vers num="1.2.11" />
      </prod>
      <prod vendor="cisco" name="mgx_8250">
        <vers num="1.2.10" />
        <vers num="1.2.11" />
      </prod>
      <prod vendor="cisco" name="sn_5420_storage_router">
        <vers num="1.1(2)" />
        <vers num="1.1(3)" />
        <vers num="1.1(4)" />
        <vers num="1.1(5)" />
        <vers num="1.1(7)" />
        <vers num="1.1.3" />
      </prod>
      <prod vendor="cisco" name="sn_5428_storage_router">
        <vers num="2-3.3.1-k9" />
        <vers num="2-3.3.2-k9" />
        <vers num="2.5.1-k9" />
        <vers num="3.2.1-k9" />
        <vers num="3.2.2-k9" />
        <vers num="3.3.1-k9" />
        <vers num="3.3.2-k9" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
        <vers num="2.1.7.1" />
        <vers num="2.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" edition="releng" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" edition="stable" />
        <vers num="3.5.1" edition="release" />
        <vers num="3.5.1" edition="stable" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="release_p8" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="release_p3" />
        <vers num="4.11" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:advanced_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard_64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0357" published="2005-08-23" name="CVE-2005-0357" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/606857" source="CERT-VN" patch="1" adv="1">VU#606857</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21887" source="XF" patch="1">legato-authunix-bypass-authentication(21887)</ref>
      <ref url="http://www.securityfocus.com/bid/14582" source="BID" patch="1">14582</ref>
      <ref url="http://www.legato.com/support/websupport/product_alerts/081605_NW_authentication.htm" source="CONFIRM" patch="1">http://www.legato.com/support/websupport/product_alerts/081605_NW_authentication.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1" source="SUNALERT" patch="1" adv="1">101886</ref>
      <ref url="http://securitytracker.com/id?1014713" source="SECTRACK" patch="1">1014713</ref>
      <ref url="http://secunia.com/advisories/16464" source="SECUNIA" patch="1" adv="1">16464</ref>
      <ref url="http://www.osvdb.org/18800" source="OSVDB">18800</ref>
      <ref url="http://secunia.com/advisories/16470" source="SECUNIA" adv="1">16470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="legato_networker">
        <vers num="4.2.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.13" />
        <vers num="7.2" />
      </prod>
      <prod vendor="sun" name="solstice_backup">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
      <prod vendor="sun" name="storedge_enterprise_backup_software">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0358" published="2005-08-23" name="CVE-2005-0358" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/407641" source="CERT-VN" patch="1" adv="1">VU#407641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21892" source="XF" patch="1">legato-token-gain-privileges(21892)</ref>
      <ref url="http://www.securityfocus.com/bid/14582" source="BID" patch="1" adv="1">14582</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1" source="SUNALERT" patch="1" adv="1">101886</ref>
      <ref url="http://securitytracker.com/id?1014713" source="SECTRACK" patch="1">1014713</ref>
      <ref url="http://secunia.com/advisories/16464" source="SECUNIA" patch="1" adv="1">16464</ref>
      <ref url="http://www.osvdb.org/18801" source="OSVDB">18801</ref>
      <ref url="http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm" source="CONFIRM">http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm</ref>
      <ref url="http://secunia.com/advisories/16470" source="SECUNIA" adv="1">16470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="legato_networker">
        <vers num="4.2.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.13" />
        <vers num="7.2" />
      </prod>
      <prod vendor="sun" name="solstice_backup">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
      <prod vendor="sun" name="storedge_enterprise_backup_software">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0359" published="2005-08-23" name="CVE-2005-0359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/801089" source="CERT-VN" patch="1" adv="1">VU#801089</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21893" source="XF" patch="1">legato-portmapper-obtain-information(21893)</ref>
      <ref url="http://www.securityfocus.com/bid/14582" source="BID" patch="1">14582</ref>
      <ref url="http://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htm" source="CONFIRM" patch="1">http://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1" source="SUNALERT" patch="1" adv="1">101886</ref>
      <ref url="http://securitytracker.com/id?1014713" source="SECTRACK" patch="1">1014713</ref>
      <ref url="http://secunia.com/advisories/16464" source="SECUNIA" patch="1" adv="1">16464</ref>
      <ref url="http://www.osvdb.org/18802" source="OSVDB">18802</ref>
      <ref url="http://secunia.com/advisories/16470" source="SECUNIA" adv="1">16470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="legato_networker">
        <vers num="4.2.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.13" />
        <vers num="7.2" />
      </prod>
      <prod vendor="sun" name="solstice_backup">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
      <prod vendor="sun" name="storedge_enterprise_backup_software">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0360" published="2005-07-05" name="CVE-2005-0360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/165022" source="CERT-VN" patch="1" adv="1">VU#165022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="log_sink_class_activex_control">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0362" published="2005-02-09" name="CVE-2005-0362" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488</ref>
      <ref url="http://www.osvdb.org/16089" source="OSVDB">16089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.7" />
        <vers num="5.8" />
        <vers num="5.9" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0363" published="2005-05-02" name="CVE-2005-0363" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-682" source="DEBIAN" patch="1" adv="1">DSA-682</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="4.0" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0364" published="2005-02-10" name="CVE-2005-0364" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19276" source="XF" patch="1" adv="1">hpux-bind-dos(19276)</ref>
      <ref url="http://secunia.com/advisories/14220/" source="SECUNIA" patch="1" adv="1">14220</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805105200470&amp;w=2" source="HP" patch="1" adv="1">HPSBUX01117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5690" source="OVAL">oval:org.mitre.oval:def:5690</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0365" published="2005-05-02" name="CVE-2005-0365" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050316-2.txt" source="CONFIRM" patch="1">http://www.kde.org/info/security/advisory-20050316-2.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-14.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-14</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110814653804757&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050211 insecure temporary file creation in kdelibs 3.3.2</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=97608" source="CONFIRM" patch="1" adv="1">http://bugs.kde.org/show_bug.cgi?id=97608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10676" source="OVAL">oval:org.mitre.oval:def:10676</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-325.html" source="REDHAT">RHSA-2005:325</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058" source="MANDRAKE">MDKSA-2005:058</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:045" source="MANDRAKE">MDKSA-2005:045</ref>
      <ref url="http://securitytracker.com/id?1013525" source="SECTRACK">1013525</ref>
      <ref url="http://secunia.com/advisories/14254" source="SECUNIA">14254</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2005-245.shtml" source="FEDORA">FEDORA-2005-245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.2.x" />
        <vers num="3.3.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0366" published="2005-05-02" name="CVE-2005-0366" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/303094" source="CERT-VN" adv="1">VU#303094</ref>
      <ref url="http://www.pgp.com/library/ctocorner/openpgp.html" source="CONFIRM" patch="1" adv="1">http://www.pgp.com/library/ctocorner/openpgp.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-29.xml" source="GENTOO" adv="1">GLSA-200503-29</ref>
      <ref url="http://eprint.iacr.org/2005/033.pdf" source="MISC">http://eprint.iacr.org/2005/033.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/12529" source="BID">12529</ref>
      <ref url="http://www.osvdb.org/13775" source="OSVDB">13775</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_07_sr.html" source="SUSE">SUSE-SR:2005:007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:057" source="MANDRAKE">MDKSA-2005:057</ref>
      <ref url="http://securitytracker.com/id?1013166" source="SECTRACK">1013166</ref>
      <ref url="http://eprint.iacr.org/2005/033" source="MISC">http://eprint.iacr.org/2005/033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpgp" name="openpgp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0367" published="2005-02-09" name="CVE-2005-0367" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796956011699&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050209 [SIG^2 G-TEC] ArGoSoft Mail Server Webmail Multiple Directory Traversal Vulnerabilities</ref>
      <ref url="http://www.security.org.sg/vuln/argosoftmail1873.html" source="MISC" adv="1">http://www.security.org.sg/vuln/argosoftmail1873.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0368" published="2005-05-02" name="CVE-2005-0368" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19235" source="XF">cmscore-multiple-sql-injection(19235)</ref>
      <ref url="http://www.securityfocus.com/bid/12457" source="BID">12457</ref>
      <ref url="http://secunia.com/advisories/14142/" source="SECUNIA" adv="1">14142</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110803385223054&amp;w=2" source="BUGTRAQ" adv="1">20050209 CMS Core SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chipmunk_scripts" name="cmscore">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0369" published="2005-05-02" name="CVE-2005-0369" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2" source="BUGTRAQ" adv="1">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armagetron" name="armagetron">
        <vers prev="1" num="0.2.6.0" />
      </prod>
      <prod vendor="armagetron" name="armagetron_advanced">
        <vers prev="1" num="0.2.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0370" published="2005-05-02" name="CVE-2005-0370" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2" source="BUGTRAQ" adv="1">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armagetron" name="armagetron">
        <vers prev="1" num="0.2.6.0" />
      </prod>
      <prod vendor="armagetron" name="armagetron_advanced">
        <vers prev="1" num="0.2.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0371" published="2005-05-02" name="CVE-2005-0371" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2" source="BUGTRAQ" adv="1">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armagetron" name="armagetron">
        <vers num="0.2.5.2" />
        <vers num="0.2.6.0" />
      </prod>
      <prod vendor="armagetron" name="armagetron_advanced">
        <vers num="0.2.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0372" published="2005-05-02" name="CVE-2005-0372" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12539" source="BID" patch="1">12539</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-27.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-27</ref>
      <ref url="http://www.debian.org/security/2005/dsa-686" source="DEBIAN" patch="1" adv="1">DSA-686</ref>
      <ref url="http://www.securityfocus.com/advisories/8380" source="FEDORA">FEDORA-2005-310</ref>
      <ref url="http://www.securityfocus.com/advisories/8379" source="FEDORA">FEDORA-2005-309</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9923" source="OVAL">oval:org.mitre.oval:def:9923</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000957" source="CONECTIVA">CLSA-2005:957</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-410.html" source="REDHAT">RHSA-2005:410</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:050" source="MANDRAKE">MDKSA-2005:050</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:717" source="OVAL" sig="1">oval:org.mitre.oval:def:717</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtk" name="gtk+">
        <vers prev="1" num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.18" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0373" published="2004-10-07" name="CVE-2005-0373" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17642" source="XF" patch="1" adv="1">cyrus-sasl-digestmda5-bo(17642)</ref>
      <ref url="http://www.securityfocus.com/bid/11347" source="BID" patch="1" adv="1">11347</ref>
      <ref url="http://www.monkey.org/openbsd/archive/ports/0407/msg00265.html" source="MLIST" patch="1" adv="1">[openbsd-ports] 20040717 UPDATE: cyrus-sasl-2.1.19</ref>
      <ref url="http://www.linuxcompatible.org/print42495.html" source="SUSE" patch="1" adv="1">SUSE-SR:2005:006</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-05</ref>
      <ref url="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup" source="CONFIRM" adv="1">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup</ref>
      <ref url="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171" source="CONFIRM" adv="1">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:054" source="MANDRAKE">MDKSA-2005:054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyrus" name="sasl">
        <vers num="1.5.24" />
        <vers num="1.5.27" />
        <vers num="1.5.28" />
        <vers num="2.1.10" />
        <vers num="2.1.11" />
        <vers num="2.1.12" />
        <vers num="2.1.13" />
        <vers num="2.1.14" />
        <vers num="2.1.15" />
        <vers num="2.1.16" />
        <vers num="2.1.17" />
        <vers num="2.1.18" />
        <vers num="2.1.18_r1" />
        <vers num="2.1.9" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="suse" name="suse_cvsup">
        <vers num="16.1h_36.i586" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0374" published="2005-05-02" name="CVE-2005-0374" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Bitboard 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via an [img] bbcode image tag with an event such as mouseover.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18871" source="XF">bitshifters-bitboard-xss(18871)</ref>
      <ref url="http://www.securityfocus.com/bid/12248" source="BID">12248</ref>
      <ref url="http://securitytracker.com/id?1012864" source="SECTRACK">1012864</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110555988111899&amp;w=2" source="BUGTRAQ" adv="1">20050112 Security Advisory: BiTBOARD xss</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitshifters" name="bitboard">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0375" published="2005-05-02" name="CVE-2005-0375" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18877" source="XF">sgallery-path-disclosure(18877)</ref>
      <ref url="http://www.waraxe.us/advisory-39.html" source="MISC" adv="1">http://www.waraxe.us/advisory-39.html</ref>
      <ref url="http://securitytracker.com/id?1012868" source="SECTRACK">1012868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_kiselev" name="sgallery">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0376" published="2005-01-12" name="CVE-2005-0376" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18878" source="XF" adv="1">sgallery-file-include(18878)</ref>
      <ref url="http://www.waraxe.us/advisory-39.html" source="MISC" adv="1">http://www.waraxe.us/advisory-39.html</ref>
      <ref url="http://securitytracker.com/id?1012868" source="SECTRACK">1012868</ref>
      <ref url="http://secunia.com/advisories/13824" source="SECUNIA" adv="1">13824</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2" source="BUGTRAQ" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html" source="FULLDISC" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_kiselev" name="sgallery">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0377" published="2005-05-02" name="CVE-2005-0377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18876" source="XF">sgallery-imageview-sql-injection(18876)</ref>
      <ref url="http://www.waraxe.us/advisory-39.html" source="MISC">http://www.waraxe.us/advisory-39.html</ref>
      <ref url="http://www.securityfocus.com/bid/12249" source="BID" adv="1">12249</ref>
      <ref url="http://securitytracker.com/id?1012868" source="SECTRACK">1012868</ref>
      <ref url="http://secunia.com/advisories/13824" source="SECUNIA" adv="1">13824</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2" source="BUGTRAQ" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_kiselev" name="sgallery">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0378" published="2005-05-02" name="CVE-2005-0378" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12255" source="BID" patch="1">12255</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110564059322774&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050113 Cross Site Scripting holes found in Horde 3.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18881" source="XF">horde-prefs-index-xss(18881)</ref>
      <ref url="http://www.hyperdose.com/advisories/H2005-01.txt" source="MISC">http://www.hyperdose.com/advisories/H2005-01.txt</ref>
      <ref url="http://securitytracker.com/id?1012892" source="SECTRACK">1012892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="horde">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0379" published="2005-05-02" name="CVE-2005-0379" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlogin.php, or the dir parameter to (3) write.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18891" source="XF">zeroboard-file-disclosure(18891)</ref>
      <ref url="http://www.securityfocus.com/bid/12257" source="BID">12257</ref>
      <ref url="http://securitytracker.com/id?1012884" source="SECTRACK">1012884</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565373407474&amp;w=2" source="BUGTRAQ" adv="1">20050113 STG Security Advisory: [SSA-20050113-25] ZeroBoard multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2" />
        <vers num="4.1_pl3" />
        <vers num="4.1_pl4" />
        <vers num="4.1_pl5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0380" published="2005-05-02" name="CVE-2005-0380" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the dir parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13769" source="SECUNIA" patch="1" adv="1">13769</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18893" source="XF">zeroboard-zero-vote-file-include(18893)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18892" source="XF">zeroboard-printcategory-file-include(18892)</ref>
      <ref url="http://www.securityfocus.com/bid/12258" source="BID">12258</ref>
      <ref url="http://www.securityfocus.com/bid/12206" source="BID">12206</ref>
      <ref url="http://www.osvdb.org/12932" source="OSVDB">12932</ref>
      <ref url="http://www.osvdb.org/12931" source="OSVDB">12931</ref>
      <ref url="http://www.osvdb.org/12930" source="OSVDB">12930</ref>
      <ref url="http://www.osvdb.org/12929" source="OSVDB">12929</ref>
      <ref url="http://www.osvdb.org/12928" source="OSVDB">12928</ref>
      <ref url="http://securitytracker.com/id?1012884" source="SECTRACK">1012884</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565373407474&amp;w=2" source="BUGTRAQ" adv="1">20050113 STG Security Advisory: [SSA-20050113-25] ZeroBoard multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2" />
        <vers num="4.1_pl3" />
        <vers num="4.1_pl4" />
        <vers num="4.1_pl5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0381" published="2005-01-13" name="CVE-2005-0381" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18880" source="XF" adv="1">forumkit-members-xss(18880)</ref>
      <ref url="http://www.securityfocus.com/bid/12256" source="BID" adv="1">12256</ref>
      <ref url="http://securitytracker.com/id?1012895" source="SECTRACK">1012895</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110563769413994&amp;w=2" source="BUGTRAQ" adv="1">20050113 XSS Vulnerability in ForumKIT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="forumkit" name="forumkit">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0382" published="2005-05-02" name="CVE-2005-0382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18890" source="XF">breed-udp-datagram-dos(18890)</ref>
      <ref url="http://www.securityfocus.com/bid/12262" source="BID">12262</ref>
      <ref url="http://secunia.com/advisories/13211" source="SECUNIA" adv="1">13211</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565587010998&amp;w=2" source="BUGTRAQ" adv="1">20050113 Server crash in Breed patch #1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="breed" name="breed">
        <vers num="patch_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0383" published="2005-05-02" name="CVE-2005-0383" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Trend Micro Control Manager 3.0 Enterprise Edition allows remote attackers to gain privileges via a replay attack of the encrypted username and password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cirt.dk/advisories/cirt-28-advisory.pdf" source="MISC" patch="1" adv="1">http://www.cirt.dk/advisories/cirt-28-advisory.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565281205427&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050113 Trend Micro Control Manager - Enterprise Edition 3.0 Web application Replay attack</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18887" source="XF">control-manager-replay-attack(18887)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110564369316593&amp;w=2" source="BUGTRAQ" adv="1">20050113 Trend Micro Control Manager - Enterprise Edition 3.0 Web application Replay attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="control_manager">
        <vers num="3.0_enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0384" published="2005-03-15" name="CVE-2005-0384" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1" source="UBUNTU">USN-95-1</ref>
      <ref url="http://www.trustix.org/errata/2005/0009/" source="TRUSTIX" adv="1">2005-0009</ref>
      <ref url="http://www.securityfocus.com/bid/12810" source="BID">12810</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" adv="1">RHSA-2005:284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-283.html" source="REDHAT" adv="1">RHSA-2005:283</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9562" source="OVAL">oval:org.mitre.oval:def:9562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.2" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0385" published="2005-05-02" name="CVE-2005-0385" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12797" source="BID" patch="1">12797</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19680" source="XF">luxman-bo-execute-commands(19680)</ref>
      <ref url="http://www.securityfocus.com/archive/1/393195/2005-03-13/2005-03-19/0" source="BUGTRAQ">20050314 DMA[2005-0310a] - 'Frank McIngvale LuxMan buffer overflow'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0310a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0310a].txt </ref>
      <ref url="http://www.debian.org/security/2005/dsa-693" source="DEBIAN" adv="1">DSA-693</ref>
      <ref url="http://secunia.com/advisories/14582" source="SECUNIA" adv="1">14582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frank_mcingvale" name="luxman">
        <vers num="0.41" />
        <vers num="0.41_17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0386" published="2005-05-02" name="CVE-2005-0386" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in network.cgi in mailreader before 2.3.29 earlier allows remote attackers to inject arbitrary web script or HTML via MIME text/enriched or text/richtext messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-700" source="DEBIAN" patch="1" adv="1">DSA-700</ref>
      <ref url="http://secunia.com/advisories/14777" source="SECUNIA" adv="1">14777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailreader.com" name="mailreader.com">
        <vers num="2.3.20" />
        <vers num="2.3.21" />
        <vers num="2.3.22" />
        <vers num="2.3.23" />
        <vers num="2.3.24" />
        <vers num="2.3.25" />
        <vers num="2.3.26" />
        <vers num="2.3.27" />
        <vers num="2.3.28" />
        <vers num="2.3.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0387" published="2005-05-02" name="CVE-2005-0387" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-704" source="DEBIAN" patch="1" adv="1">DSA-704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="remstats" name="remstats">
        <vers num="1.0.13" />
        <vers num="1.0.8a" />
        <vers num="1.0.9b" />
        <vers num="1.00a4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0388" published="2005-05-02" name="CVE-2005-0388" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-704" source="DEBIAN" patch="1" adv="1">DSA-704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="remstats" name="remstats">
        <vers num="1.0.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0389" reject="1" published="2005-05-02" name="CVE-2005-0389" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0814.  Reason: This candidate is a duplicate of CVE-2005-0814.  Notes: All CVE users should reference CVE-2005-0814 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-0390" published="2005-05-02" name="CVE-2005-0390" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP redirection capability in conn.c for Axel before 1.0b may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13059" source="BID" patch="1">13059</ref>
      <ref url="http://www.debian.org/security/2005/dsa-706" source="DEBIAN" patch="1" adv="1">DSA-706</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-09.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-09</ref>
      <ref url="http://secunia.com/advisories/14831" source="SECUNIA" patch="1">14831</ref>
      <ref url="http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg118978.html" source="CONFIRM">http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg118978.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axel" name="axel">
        <vers num="1.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0391" published="2005-05-02" name="CVE-2005-0391" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">geneweb 4.10 and earlier does not properly check file permissions and content during conversion, which allows attackers to modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-712" source="DEBIAN" patch="1" adv="1">DSA-712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20176" source="XF">geneweb-insecure-file-permission(20176)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_de_rauglaudre" name="geneweb">
        <vers prev="1" num="4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0392" published="2005-05-19" name="CVE-2005-0392" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ppxp does not drop root privileges before opening log files, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13681" source="BID">13681</ref>
      <ref url="http://www.debian.org/security/2005/dsa-725" source="DEBIAN">DSA-725</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="ppxp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0393" published="2005-07-05" name="CVE-2005-0393" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-733" source="DEBIAN" patch="1" adv="1">DSA-733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crip" name="crip">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0395" reject="1" published="2005-06-09" name="CVE-2005-0395" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0396" published="2005-05-02" name="CVE-2005-0396" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Desktop Communication Protocol (DCOP) daemon, aka dcopserver, in KDE before 3.4 allows local users to cause a denial of service (dcopserver consumption) by "stalling the DCOP authentication process."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050316-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050316-1.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-22</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111099766716483&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050316 Multiple KDE Security Advisories (2005-03-16)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10432" source="OVAL">oval:org.mitre.oval:def:10432</ref>
      <ref url="http://www.securityfocus.com/bid/12820" source="BID">12820</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" source="FEDORA">FLSA:178606</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-325.html" source="REDHAT">RHSA-2005:325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-307.html" source="REDHAT">RHSA-2005:307</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058" source="MANDRAKE">MDKSA-2005:058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="dcopserver">
        <vers prev="1" num="3.3" />
      </prod>
      <prod vendor="kde" name="desktop_communication_protocol_daemon">
        <vers prev="1" num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0397" published="2005-05-02" name="CVE-2005-0397" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19586" source="XF" patch="1">imagemagick-filename-format-string(19586)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-320.html" source="REDHAT" patch="1" adv="1">RHSA-2005:320</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:017</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-11.xml" source="GENTOO" patch="1">GLSA-200503-11</ref>
      <ref url="http://www.debian.org/security/2005/dsa-702" source="DEBIAN" patch="1" adv="1">DSA-702</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110987256010857&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050303 [USN-90-1] Imagemagick vulnerability</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=83542" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=83542</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10302" source="OVAL">oval:org.mitre.oval:def:10302</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-070.html" source="REDHAT">RHSA-2005:070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0398" published="2005-03-14" name="CVE-2005-0398" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=109966&amp;action=view" source="MISC" patch="1" adv="1">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=109966&amp;action=view</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19707" source="XF" patch="1" adv="1">racoon-isakmp-header-dos(19707)</ref>
      <ref url="http://www.securityfocus.com/bid/12804" source="BID" patch="1" adv="1">12804</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-232.html" source="REDHAT" patch="1" adv="1">RHSA-2005:232</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=6787713&amp;forum_id=32000" source="MLIST" patch="1" adv="1">[ipsec-tools-devel] 20050312 potential remote crash in racoon</ref>
      <ref url="http://securitytracker.com/id?1013433" source="SECTRACK" patch="1" adv="1">1013433</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-33.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-33</ref>
      <ref url="http://secunia.com/advisories/14584" source="SECUNIA" patch="1" adv="1">14584</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0264" source="VUPEN">ADV-2005-0264</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10028" source="OVAL">oval:org.mitre.oval:def:10028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:062" source="MANDRAKE">MDKSA-2005:062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipsec-tools" name="ipsec-tools">
        <vers num="0.3.3" />
        <vers num="0.5" />
      </prod>
      <prod vendor="kame" name="racoon">
        <vers num="2003-07-11" />
        <vers num="2004-04-05" />
        <vers num="2004-04-07b" />
        <vers num="2004-05-03" />
        <vers num="2005-01-03" />
        <vers num="2005-01-10" />
        <vers num="2005-01-17" />
        <vers num="2005-01-24" />
        <vers num="2005-01-31" />
        <vers num="2005-02-07" />
        <vers num="2005-02-14" />
        <vers num="2005-02-21" />
        <vers num="2005-02-28" />
        <vers num="2005-03-07" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":compact" />
        <vers num="2.3" edition=":junior" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="" edition=":desktop" />
        <vers num="" edition=":enterprise_server" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0399" published="2005-05-02" name="CVE-2005-0399" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/557948" source="CERT-VN" adv="1">VU#557948</ref>
      <ref url="http://secunia.com/advisories/14654" source="SECUNIA" patch="1" adv="1">14654</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=150877" source="MISC" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=150877</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19269" source="XF">gif-extension-overflow(19269)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/191" source="ISS" adv="1">20050323 Mozilla Foundation GIF Overflow</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0296" source="VUPEN">ADV-2005-0296</ref>
      <ref url="http://www.securityfocus.com/bid/12881" source="BID">12881</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-337.html" source="REDHAT" adv="1">RHSA-2005:337</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-336.html" source="REDHAT" adv="1">RHSA-2005:336</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" adv="1">RHSA-2005:323</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-30.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-30.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-160.shtml" source="CIAC">P-160</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11377" source="OVAL">oval:org.mitre.oval:def:11377</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100028" source="OVAL" sig="1">oval:org.mitre.oval:def:100028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0400" published="2005-05-02" name="CVE-2005-0400" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ext2_make_empty function call in the Linux kernel before 2.6.11.6 does not properly initialize memory when creating a block for a new directory entry, which allows local users to obtain potentially sensitive information by reading the block.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19866" source="XF" patch="1">kernel-ext2-information-disclosure(19866)</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-103-1" source="UBUNTU">USN-103-1</ref>
      <ref url="http://secunia.com/advisories/14713/" source="SECUNIA">14713</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10336" source="OVAL">oval:org.mitre.oval:def:10336</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6</ref>
      <ref url="http://arkoon.net/advisories/ext2-make-empty-leak.txt" source="MISC" adv="1">http://arkoon.net/advisories/ext2-make-empty-leak.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12932" source="BID">12932</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0191.html" source="REDHAT">RHSA-2006:0191</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0190.html" source="REDHAT">RHSA-2006:0190</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://secunia.com/advisories/18684" source="SECUNIA">18684</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238764720696&amp;w=2" source="BUGTRAQ">20050401 Information leak in the Linux kernel ext2 implementation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.11.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0401" published="2005-05-02" name="CVE-2005-0401" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12885" source="BID" patch="1">12885</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0296" source="VUPEN">ADV-2005-0296</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-336.html" source="REDHAT" adv="1">RHSA-2005:336</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-32.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-32.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" adv="1">GLSA-200503-30</ref>
      <ref url="http://secunia.com/advisories/14654" source="SECUNIA" adv="1">14654</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9650" source="OVAL">oval:org.mitre.oval:def:9650</ref>
      <ref url="http://mikx.de/firescrolling2/" source="MISC">http://mikx.de/firescrolling2/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168413007891&amp;w=2" source="BUGTRAQ" adv="1">20050324 Firescrolling 2 [Firefox 1.0.1]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100026" source="OVAL" sig="1">oval:org.mitre.oval:def:100026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0402" published="2005-05-02" name="CVE-2005-0402" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=284627" source="MISC" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=284627</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-336.html" source="REDHAT" patch="1" adv="1">RHSA-2005:336</ref>
      <ref url="http://secunia.com/advisories/14654" source="SECUNIA" patch="1" adv="1">14654</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0296" source="VUPEN">ADV-2005-0296</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-31.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-31.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11868" source="OVAL">oval:org.mitre.oval:def:11868</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100027" source="OVAL" sig="1">oval:org.mitre.oval:def:100027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0403" published="2005-09-01" name="CVE-2005-0403" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT" patch="1" adv="1">RHSA-2005:293</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=144059" source="MISC">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=144059</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9435" source="OVAL">oval:org.mitre.oval:def:9435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0404" published="2005-05-02" name="CVE-2005-0404" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/5GP0B0AFFE.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/unixfocus/5GP0B0AFFE.html</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=96020" source="MISC" patch="1" adv="1">http://bugs.kde.org/show_bug.cgi?id=96020</ref>
      <ref url="http://secunia.com/advisories/14925" source="SECUNIA" adv="1">14925</ref>
      <ref url="http://mail.kde.org/pipermail/kmail-devel/2005-February/015490.html" source="MLIST" adv="1">[kmail-devel] 20050215 [Bug 96020] HTML Allows Spoofing of Emails Content</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kmail" name="kmail">
        <vers num="1.7.1" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0406" published="2005-02-14" name="CVE-2005-0406" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html" source="FULLDISC">20050214 Advisory: JPEG EXIF information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="image_processing_software" name="image_processing_software">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0407" published="2005-05-02" name="CVE-2005-0407" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Openconf 1.04, and possibly other versions before 1.10, allows remote attackers to inject arbitrary HTML and web script via the paper title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12554" source="BID">12554</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-007.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-007.txt</ref>
      <ref url="http://secunia.com/advisories/14294" source="SECUNIA" adv="1">14294</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Feb/0347.html" source="FULLDISC">20050214 Advisory: Cross Site Scripting Vulnerability in Openconf Conference Management Software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zakon_group" name="openconf">
        <vers num="1.0" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
        <vers num="1.0_beta1" />
        <vers num="1.0_beta2" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0408" published="2005-02-14" name="CVE-2005-0408" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the "boogaadeeboo" string, which is hard-coded in the $hidden_hash variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html" source="FULLDISC">20050214 Advisory: Authentication bypass in CitrusDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb">
        <vers prev="1" num="0.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0409" published="2005-02-14" name="CVE-2005-0409" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html" source="FULLDISC">20050214 Advisory: Upload Authorization bypass in CitrusDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb">
        <vers prev="1" num="0.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0410" published="2005-02-14" name="CVE-2005-0410" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031709.html" source="FULLDISC">20050214 Advisory: SQL-Injection in CitrusDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb">
        <vers prev="1" num="0.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0411" published="2005-02-14" name="CVE-2005-0411" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031710.html" source="FULLDISC">20050214 Advisory: Directory traversal in CitrusDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb">
        <vers prev="1" num="0.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0412" published="2005-04-27" name="CVE-2005-0412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19261" source="XF" adv="1">postwrap-xss(19261)</ref>
      <ref url="http://securitytracker.com/id?1013130" source="SECTRACK" adv="1">1013130</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0065.html" source="FULLDISC">20050208 XSS VULNERABILITY AT MODULE PostWrap</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidean" name="postwrap">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0413" published="2005-04-27" name="CVE-2005-0413" modified="2010-12-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php.  NOTE: it was later reported that vector 2 exists in 3.0 and earlier.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39348" source="XF">myphpforum-member-sql-injection(39348)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19272" source="XF">myphpforum-multiple-sql-injection(19272)</ref>
      <ref url="http://www.securityfocus.com/bid/27083" source="BID">27083</ref>
      <ref url="http://www.securityfocus.com/bid/12501" source="BID">12501</ref>
      <ref url="http://www.milw0rm.com/exploits/4822" source="MILW0RM">4822</ref>
      <ref url="http://securitytracker.com/id?1013136" source="SECTRACK" adv="1">1013136</ref>
      <ref url="http://secunia.com/advisories/14205" source="SECUNIA" adv="1">14205</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Feb/0125.html" source="BUGTRAQ">20050209 Several SQL injection bugs in myPHP Forum v.1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphp_forum" name="myphp_forum">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0414" published="2005-04-27" name="CVE-2005-0414" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013137" source="SECTRACK" patch="1" adv="1">1013137</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19051" source="XF">mercuryboard-index-sql-injection(19051)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110797495532358&amp;w=2" source="BUGTRAQ">20050209 Mercuryboard =?iso-8859-1?Q?&lt;=3D?= 1.1.1 Working Sql Injection</ref>
      <ref url="http://cvs.sunsite.dk/viewcvs.cgi/mercury/func/post.php.diff?r1=1.68&amp;r2=1.70" source="CONFIRM">http://cvs.sunsite.dk/viewcvs.cgi/mercury/func/post.php.diff?r1=1.68&amp;r2=1.70</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0415" published="2005-04-27" name="CVE-2005-0415" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19273" source="XF">emdros-mql-dos(19273)</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1116935&amp;group_id=37219&amp;atid=419458" source="CONFIRM" adv="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1116935&amp;group_id=37219&amp;atid=419458</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=303465" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=303465</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ulrik_petersen" name="emdros_database_engine">
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0416" published="2005-04-27" name="CVE-2005-0416" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18879" source="XF" patch="1" adv="1">win-user32-aniheader-overflow(18879)</ref>
      <ref url="http://www.securityfocus.com/bid/12233" source="BID" patch="1" adv="1">12233</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-002.mspx" source="MS" patch="1" adv="1">MS05-002</ref>
      <ref url="http://eeye.com/html/research/advisories/AD20050111.html" source="MISC">http://eeye.com/html/research/advisories/AD20050111.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110556975827760&amp;w=2" source="BUGTRAQ">20050112 Windows ANI File Parsing Proof Of Concept (MS05-002)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547079218397&amp;w=2" source="BUGTRAQ">20050111 EEYE: Windows ANI File Parsing Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0417" published="2005-04-27" name="CVE-2005-0417" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors.  NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future.  In addition, this may be a duplicate of other issues as reported by the vendor.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12508" source="BID" patch="1" adv="1">12508</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110801212422825&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050209 Patch available for high risk IBM DB2 Universal Database flaw</ref>
      <ref url="http://www.ngssoftware.com/advisories/db2-09-05-05.htm" source="MISC">http://www.ngssoftware.com/advisories/db2-09-05-05.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="6.0" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":linux" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":linux" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":linux" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":linux" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":aix" />
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0418" published="2005-05-02" name="CVE-2005-0418" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-03-24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="j2se">
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":sdk" />
        <vers num="1.4.2_01" edition="" />
        <vers num="1.4.2_01" edition=":sdk" />
        <vers num="1.4.2_02" edition="" />
        <vers num="1.4.2_02" edition=":sdk" />
        <vers num="1.4.2_03" edition="" />
        <vers num="1.4.2_03" edition=":sdk" />
        <vers num="1.4.2_04" edition="" />
        <vers num="1.4.2_04" edition=":sdk" />
        <vers num="1.4.2_05" edition="" />
        <vers num="1.4.2_05" edition=":sdk" />
        <vers num="1.4.2_06" edition="" />
        <vers num="1.4.2_06" edition=":sdk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0419" published="2005-04-27" name="CVE-2005-0419" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19250" source="XF">3cserver-multiple-command-bo(19250)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780306326130&amp;w=2" source="BUGTRAQ" adv="1">20050207 Vulnerability in 3Com 3CServer v1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cserver">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0420" published="2005-04-27" name="CVE-2005-0420" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19225" source="XF" adv="1">owa-owalogonasp-url-redirect(19225)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0105" source="VUPEN">ADV-2005-0105</ref>
      <ref url="http://www.securityfocus.com/bid/12459" source="BID" adv="1">12459</ref>
      <ref url="http://secunia.com/advisories/14144" source="SECUNIA" adv="1">14144</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Feb/0106.html" source="FULLDISC">20050206 Microsoft Outlook Web Access URL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2003" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0421" published="2005-04-27" name="CVE-2005-0421" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19248" source="XF">delphiturkcodebank-obtain-information(19248)</ref>
      <ref url="http://securitytracker.com/id?1013139" source="SECTRACK" adv="1">1013139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delphiturk" name="delphiturk_ftp">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0422" published="2005-04-27" name="CVE-2005-0422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19248" source="XF" adv="1">delphiturkcodebank-obtain-information(19248)</ref>
      <ref url="http://securitytracker.com/id?1013139" source="SECTRACK" adv="1">1013139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delphiturk" name="codebank">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0423" published="2005-04-27" name="CVE-2005-0423" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12521" source="BID" patch="1" adv="1">12521</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19299" source="XF" adv="1">aspjar-guest-login-sql-injection(19299)</ref>
      <ref url="http://secunia.com/advisories/14225/" source="SECUNIA" adv="1">14225</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110809687921701&amp;w=2" source="BUGTRAQ">20050210 ASPjar guestbook (Injection in login page)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspjar" name="aspjar_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0424" published="2005-04-27" name="CVE-2005-0424" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages.  NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12521" source="BID" patch="1" adv="1">12521</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19301" source="XF" adv="1">aspjar-delete-message-deletion(19301)</ref>
      <ref url="http://secunia.com/advisories/14225/" source="SECUNIA" adv="1">14225</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110809687921701&amp;w=2" source="BUGTRAQ">20050210 ASPjar guestbook (Injection in login page)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspjar" name="aspjar_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0425" published="2005-05-02" name="CVE-2005-0425" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24008815" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg24008815</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24008814" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg24008814</ref>
      <ref url="http://secunia.com/advisories/14274" source="SECUNIA" patch="1" adv="1">14274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.0" />
        <vers num="5.1.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0426" published="2005-05-02" name="CVE-2005-0426" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19119" source="XF">solaris-udp-end-point-dos(19119)</ref>
      <ref url="http://www.securityfocus.com/bid/12385" source="BID">12385</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57728-1" source="SUNALERT" adv="1">57728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0427" published="2005-05-02" name="CVE-2005-0427" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19315" source="XF">webmin-encrypted-password(19315)</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=77731" source="MISC" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=77731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="webmin">
        <vers num="1.140" />
        <vers num="1.150" />
        <vers num="1.160" />
        <vers num="1.170" edition="r1" />
        <vers num="1.170" edition="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0428" published="2005-05-02" name="CVE-2005-0428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19221" source="XF" patch="1" adv="1">powerdns-random-bytes-dos(19221)</ref>
      <ref url="http://www.securityfocus.com/bid/12446" source="BID" patch="1" adv="1">12446</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-15</ref>
      <ref url="http://ds9a.nl/cgi-bin/cvstrac/pdns/tktview?tn=21" source="MISC">http://ds9a.nl/cgi-bin/cvstrac/pdns/tktview?tn=21</ref>
      <ref url="http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-17" source="CONFIRM">http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerdns" name="powerdns">
        <vers num="2.0_rc1" />
        <vers num="2.8" />
        <vers num="2.9.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0429" published="2005-05-02" name="CVE-2005-0429" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110840807415315&amp;w=2" source="BUGTRAQ" adv="1">20050213 vbulletin 3.0.x PHP code execution</ref>
      <ref url="http://www.securityfocus.com/bid/12542" source="BID">12542</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0430" published="2005-02-12" name="CVE-2005-0430" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/q3infoboom-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/q3infoboom-adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12534" source="BID">12534</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824822224025&amp;w=2" source="BUGTRAQ">20050212 Infostring crash and shutdown in the Quake 3 engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quake_3_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0431" published="2005-05-02" name="CVE-2005-0431" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19283" source="XF">barracuda-open-relay(19283)</ref>
      <ref url="http://secunia.com/advisories/14243" source="SECUNIA" adv="1">14243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805534732492&amp;w=2" source="BUGTRAQ" adv="1">20050210 Barracuda Spam Firewall &lt;= 3.1.10 acts as open relay for whitelisted senders.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barracuda_networks" name="barracuda_spam_firewall">
        <vers num="3.1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0432" published="2005-05-02" name="CVE-2005-0432" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14298" source="SECUNIA" patch="1" adv="1">14298</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA05-74.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA05-74.00.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp5" />
        <vers num="8.1" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0433" published="2005-02-15" name="CVE-2005-0433" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19344" source="XF">phpnuke-multiple-scripts-path-disclosure(19344)</ref>
      <ref url="http://www.waraxe.us/advisory-40.html" source="MISC" adv="1">http://www.waraxe.us/advisory-40.html</ref>
      <ref url="http://www.securityfocus.com/bid/12561" source="BID" adv="1">12561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0434" published="2005-02-15" name="CVE-2005-0434" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19346" source="XF">phpnuke-downloads-weblinks-xss(19346)</ref>
      <ref url="http://www.waraxe.us/advisory-40.html" source="MISC" adv="1">http://www.waraxe.us/advisory-40.html</ref>
      <ref url="http://www.securityfocus.com/bid/12561" source="BID" adv="1">12561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0435" published="2005-05-02" name="CVE-2005-0435" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14299" source="SECUNIA" patch="1" adv="1">14299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19333" source="XF">awstats-awstatpl-obtain-information(19333)</ref>
      <ref url="http://www.securityfocus.com/archive/1/390368" source="BUGTRAQ" adv="1">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0436" published="2005-05-02" name="CVE-2005-0436" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14299" source="SECUNIA" patch="1" adv="1">14299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19336" source="XF">awstats-function-code-execution(19336)</ref>
      <ref url="http://www.securityfocus.com/archive/1/390368" source="BUGTRAQ" adv="1">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/13832" source="OSVDB">13832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0437" published="2005-05-02" name="CVE-2005-0437" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14299" source="SECUNIA" patch="1" adv="1">14299</ref>
      <ref url="http://www.securityfocus.com/archive/1/390368" source="BUGTRAQ" adv="1">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0438" published="2005-05-02" name="CVE-2005-0438" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14299" source="SECUNIA" patch="1" adv="1">14299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19477" source="XF">awstats-information-disclosure(19477)</ref>
      <ref url="http://www.securityfocus.com/archive/1/390368" source="BUGTRAQ" adv="1">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0439" published="2005-05-02" name="CVE-2005-0439" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12556" source="BID" patch="1">12556</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880</ref>
      <ref url="http://midas.psi.ch/elogs/Forum/941" source="CONFIRM" patch="1" adv="1">http://midas.psi.ch/elogs/Forum/941</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19313" source="XF">elog-weblog-bo(19313)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0440" published="2005-05-02" name="CVE-2005-0440" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12556" source="BID" patch="1">12556</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880</ref>
      <ref url="http://midas.psi.ch/elogs/Forum/941" source="CONFIRM" adv="1">http://midas.psi.ch/elogs/Forum/941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0441" published="2004-12-22" name="CVE-2005-0441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19980" source="XF" patch="1" adv="1">sybase-ase-install-java-bo(19980)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19979" source="XF" patch="1" adv="1">sybase-ase-abstract-bo(19979)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19978" source="XF" patch="1" adv="1">sybase-ase-declare-bo(19978)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19976" source="XF" patch="1" adv="1">sybase-ase-convert-bo(19976)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19974" source="XF" patch="1" adv="1">sybase-ase-attribvalid-bo(19974)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19354" source="XF" patch="1" adv="1">sybase-adaptive-server(19354)</ref>
      <ref url="http://www.sybase.com/detail?id=1034752" source="CONFIRM" patch="1" adv="1">http://www.sybase.com/detail?id=1034752</ref>
      <ref url="http://www.sybase.com/detail?id=1034520" source="CONFIRM" patch="1" adv="1">http://www.sybase.com/detail?id=1034520</ref>
      <ref url="http://www.securityfocus.com/bid/12080" source="BID" patch="1" adv="1">12080</ref>
      <ref url="http://www.securityfocus.com/archive/1/393851" source="BUGTRAQ" patch="1" adv="1">20050321 Details of Sybase ASE bugs withheld</ref>
      <ref url="http://secunia.com/advisories/13632" source="SECUNIA" patch="1" adv="1">13632</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272918117194&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050405 Sybase ASE Multiple Security Issues (#NISR05042005)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0315.html" source="BUGTRAQ" patch="1" adv="1">20041222 Sybase ASE 12.5.2 vulnerabilities</ref>
      <ref url="http://www.ngssoftware.com/advisories/sybase-ase.txt" source="MISC" adv="1">http://www.ngssoftware.com/advisories/sybase-ase.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="adaptive_server_enterprise">
        <vers num="11.03.3" edition="" />
        <vers num="11.03.3" edition=":linux" />
        <vers num="11.5" edition="" />
        <vers num="11.5" edition=":hp" />
        <vers num="11.5" edition=":win" />
        <vers num="11.5" edition=":sun" />
        <vers num="11.5" edition=":digital_unix" />
        <vers num="11.5.1" edition="" />
        <vers num="11.5.1" edition=":sun" />
        <vers num="11.5.1" edition=":win" />
        <vers num="11.5.1" edition=":digital_unix" />
        <vers num="11.5.1" edition=":hp" />
        <vers num="11.9.2" edition="" />
        <vers num="11.9.2" edition=":win" />
        <vers num="11.9.2" edition=":sun" />
        <vers num="11.9.2" edition=":digital_unix" />
        <vers num="11.9.2" edition=":hp" />
        <vers num="12.0" edition="" />
        <vers num="12.0" edition=":hp" />
        <vers num="12.0" edition=":win" />
        <vers num="12.0" edition=":sun" />
        <vers num="12.0" edition=":digital_unix" />
        <vers num="12.0.1" edition="" />
        <vers num="12.0.1" edition=":hp" />
        <vers num="12.0.1" edition=":sun" />
        <vers num="12.0.1" edition=":win" />
        <vers num="12.0.1" edition=":digital_unix" />
        <vers num="12.5" edition="" />
        <vers num="12.5" edition=":hp" />
        <vers num="12.5" edition=":sgi" />
        <vers num="12.5" edition=":sun" />
        <vers num="12.5" edition=":linux" />
        <vers num="12.5" edition=":digital_unix" />
        <vers num="12.5" edition=":win" />
        <vers num="12.5.2" />
        <vers num="12.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0442" published="2005-05-02" name="CVE-2005-0442" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12549" source="BID" patch="1">12549</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=5741" source="CONFIRM" patch="1" adv="1">http://www.cubecart.com/site/forums/index.php?showtopic=5741</ref>
      <ref url="http://secunia.com/advisories/14272" source="SECUNIA" patch="1" adv="1">14272</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19322" source="XF">cubecart-dotdot-directory-traversal(19322)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111281888605580&amp;w=2" source="BUGTRAQ" adv="1">20050406 RE: [NOBYTES.COM: #6] CubeCart 2.0.6 - Information Disclosure</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110842125901191&amp;w=2" source="BUGTRAQ" adv="1">20050214 [NOBYTES.COM: #2] CubeCart 2.0.4 - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.1" />
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0443" published="2005-05-02" name="CVE-2005-0443" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12549" source="BID" patch="1">12549</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=5741" source="CONFIRM" patch="1" adv="1">http://www.cubecart.com/site/forums/index.php?showtopic=5741</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19328" source="XF">cubecart-index-xss(19328)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110842125901191&amp;w=2" source="BUGTRAQ" adv="1">20050214 [NOBYTES.COM: #2] CubeCart 2.0.4 - Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/14064" source="OSVDB">14064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.1" />
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0444" published="2005-02-14" name="CVE-2005-0444" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-18.xml" source="GENTOO" adv="1">GLSA-200502-18</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="4.5.2_build_8848" edition="r4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0445" published="2005-05-02" name="CVE-2005-0445" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14253" source="SECUNIA" patch="1" adv="1">14253</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19335" source="XF">open-webmail-logindomain-xss(19335)</ref>
      <ref url="http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:01/2.5x.patch" source="CONFIRM">http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:01/2.5x.patch</ref>
      <ref url="http://turtle.ee.ncku.edu.tw/openwebmail/doc/changes.txt" source="CONFIRM">http://turtle.ee.ncku.edu.tw/openwebmail/doc/changes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12547" source="BID">12547</ref>
      <ref url="http://securitytracker.com/id?1013172" source="SECTRACK">1013172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_webmail" name="open_webmail">
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.10" />
        <vers num="2.20" />
        <vers num="2.21" />
        <vers num="2.30" />
        <vers num="2.32" />
        <vers num="2.40" />
        <vers num="2.41" />
        <vers num="2.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0446" published="2005-05-02" name="CVE-2005-0446" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE8-dns_assert.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE8-dns_assert.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE8-dns_assert" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE8-dns_assert</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-173.html" source="REDHAT" patch="1" adv="1">RHSA-2005:173</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-25</ref>
      <ref url="http://www.debian.org/security/2005/dsa-688" source="DEBIAN" patch="1" adv="1">DSA-688</ref>
      <ref url="http://secunia.com/advisories/14271" source="SECUNIA" patch="1" adv="1">14271</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" patch="1" adv="1">CLA-2005:931</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19332" source="XF">squid-xstrndup-dos(19332)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11264" source="OVAL">oval:org.mitre.oval:def:11264</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901183320453&amp;w=2" source="BUGTRAQ" adv="1">20050221 [USN-84-1] Squid vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/12551" source="BID">12551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-201.html" source="REDHAT">RHSA-2005:201</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:047" source="MANDRAKE">MDKSA-2005:047</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0.patch1" />
        <vers num="2.0.patch2" />
        <vers num="2.0.pre1" />
        <vers num="2.0.release" />
        <vers num="2.0_patch2" />
        <vers num="2.1.patch1" />
        <vers num="2.1.patch2" />
        <vers num="2.1.pre1" />
        <vers num="2.1.pre3" />
        <vers num="2.1.pre4" />
        <vers num="2.1.release" />
        <vers num="2.1_patch2" />
        <vers num="2.2.devel3" />
        <vers num="2.2.devel4" />
        <vers num="2.2.pre1" />
        <vers num="2.2.pre2" />
        <vers num="2.2.stable1" />
        <vers num="2.2.stable2" />
        <vers num="2.2.stable3" />
        <vers num="2.2.stable4" />
        <vers num="2.2.stable5" />
        <vers num="2.3.devel2" />
        <vers num="2.3.devel3" />
        <vers num="2.3.stable1" />
        <vers num="2.3.stable2" />
        <vers num="2.3.stable3" />
        <vers num="2.3.stable4" />
        <vers num="2.3.stable5" />
        <vers num="2.3_.stable4" />
        <vers num="2.3_.stable5" />
        <vers num="2.3_stable5" />
        <vers num="2.4" />
        <vers num="2.4.stable1" />
        <vers num="2.4.stable2" />
        <vers num="2.4.stable3" />
        <vers num="2.4.stable4" />
        <vers num="2.4.stable6" />
        <vers num="2.4.stable7" />
        <vers num="2.4_.stable2" />
        <vers num="2.4_.stable6" />
        <vers num="2.4_.stable7" />
        <vers num="2.4_stable7" />
        <vers num="2.5.6" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5.stable8" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
        <vers num="2.5_stable9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0447" published="2005-02-15" name="CVE-2005-0447" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14286" source="SECUNIA" patch="1" adv="1">14286</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19331" source="XF">solaris-arp-dos(19331)</ref>
      <ref url="http://www.securityfocus.com/bid/12553" source="BID">12553</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57673-1" source="SUNALERT">57673</ref>
      <ref url="http://securitytracker.com/id?1013179" source="SECTRACK">1013179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0448" published="2005-05-02" name="CVE-2005-0448" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-38</ref>
      <ref url="http://www.debian.org/security/2005/dsa-696" source="DEBIAN" patch="1" adv="1">DSA-696</ref>
      <ref url="http://www.securityfocus.com/advisories/8704" source="HP">HPSBUX01208</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10475" source="OVAL">oval:org.mitre.oval:def:10475</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-94-1" source="UBUNTU">USN-94-1</ref>
      <ref url="http://www.securityfocus.com/bid/12767" source="BID">12767</ref>
      <ref url="http://www.securityfocus.com/advisories/8704" source="HP">HPSBUX01208</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-881.html" source="REDHAT">RHSA-2005:881</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-674.html" source="REDHAT">RHSA-2005:674</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:079" source="MANDRIVA">MDKSA-2005:079</ref>
      <ref url="http://secunia.com/advisories/18517" source="SECUNIA">18517</ref>
      <ref url="http://secunia.com/advisories/18075" source="SECUNIA">18075</ref>
      <ref url="http://secunia.com/advisories/17079" source="SECUNIA">17079</ref>
      <ref url="http://secunia.com/advisories/14531" source="SECUNIA">14531</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056" source="CONECTIVA">CLSA-2006:1056</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U" source="SGI">20060101-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:728" source="OVAL" sig="1">oval:org.mitre.oval:def:728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.8.0" />
        <vers num="5.8.1" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0449" published="2005-05-02" name="CVE-2005-0449" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" patch="1" adv="1">RHSA-2005:284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-283.html" source="REDHAT" patch="1" adv="1">RHSA-2005:283</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945" source="CONECTIVA" patch="1">CLA-2005:945</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-82-1" source="UBUNTU">USN-82-1</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" source="MANDRAKE">MDKSA-2005:218</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1018" source="DEBIAN">DSA-1018</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA" adv="1">19607</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA" adv="1">19374</ref>
      <ref url="http://secunia.com/advisories/19369" source="SECUNIA" adv="1">19369</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10753" source="OVAL">oval:org.mitre.oval:def:10753</ref>
      <ref url="http://oss.sgi.com/archives/netdev/2005-01/msg01036.html" source="MLIST" adv="1">[netdev] 20050124 Re: skb_checksum_help</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0450" published="2005-05-02" name="CVE-2005-0450" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013191" source="SECTRACK" adv="1">1013191</ref>
      <ref url="http://secunia.com/advisories/14283" source="SECUNIA" adv="1">14283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sami" name="sami_http_server">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0451" published="2005-05-02" name="CVE-2005-0451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013191" source="SECTRACK" adv="1">1013191</ref>
      <ref url="http://secunia.com/advisories/14283" source="SECUNIA" adv="1">14283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sami" name="sami_http_server">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0452" published="2005-02-16" name="CVE-2005-0452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "&lt;".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12574" source="BID" adv="1">12574</ref>
      <ref url="http://secunia.com/advisories/14214" source="SECUNIA" adv="1">14214</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2" source="BUGTRAQ" adv="1">20050217 XSS vulnerabilty in ASP.Net [with details]</ref>
      <ref url="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml" source="MISC" adv="1">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="1.0" edition="sp1" />
        <vers num="1.0" edition="sp2" />
        <vers num="1.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0453" published="2005-02-16" name="CVE-2005-0453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-21.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-21</ref>
      <ref url="http://secunia.com/advisories/14297" source="SECUNIA" patch="1" adv="1">14297</ref>
      <ref url="http://article.gmane.org/gmane.comp.web.lighttpd/1171" source="CONFIRM" patch="1" adv="1">http://article.gmane.org/gmane.comp.web.lighttpd/1171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lighttpd" name="lighttpd">
        <vers num="1.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0454" published="2005-05-02" name="CVE-2005-0454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.php, or (2) the mid or bid parameters to forums.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackgen.org/advisories/hackgen-2005-003.txt" source="MISC" adv="1">http://www.hackgen.org/advisories/hackgen-2005-003.txt</ref>
      <ref url="http://securitytracker.com/id?1013216" source="SECTRACK" adv="1">1013216</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110858497207809&amp;w=2" source="BUGTRAQ" adv="1">20050216 [hackgen-2005-#003] - SQL injection bugs in DCP-Portal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19361" source="XF">dcpportal-multiple-sql-injection(19361)</ref>
      <ref url="http://www.securityfocus.com/bid/12573" source="BID">12573</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419280/100/0/threaded" source="BUGTRAQ">20051211 [PHP-CHECKER] 99 potential SQL injection vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/108" source="SREASON">108</ref>
      <ref url="http://glide.stanford.edu/yichen/research/sec.pdf" source="MISC">http://glide.stanford.edu/yichen/research/sec.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codeworx_technologies" name="dcp-portal">
        <vers prev="1" num="6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0455" published="2005-05-02" name="CVE-2005-0455" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-265.html" source="REDHAT" patch="1" adv="1">RHSA-2005:265</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=209&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050301 RealNetworks RealPlayer .smil Buffer Overflow Vulnerability</ref>
      <ref url="http://service.real.com/help/faq/security/050224_player" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/050224_player</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10926" source="OVAL">oval:org.mitre.oval:def:10926</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-271.html" source="REDHAT">RHSA-2005:271</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0456" published="2005-01-12" name="CVE-2005-0456" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/882926" source="CERT-VN" adv="1">VU#882926</ref>
      <ref url="http://www.opera.com/linux/changelogs/754u2/" source="CONFIRM" patch="1" adv="1">http://www.opera.com/linux/changelogs/754u2/</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-17</ref>
      <ref url="http://secunia.com/advisories/13818/" source="SECUNIA" patch="1" adv="1">13818</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18867" source="XF" adv="1">opera-data-dialog-spoofing(18867)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_31_opera.html" source="SUSE">SUSE-SA:2005:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux" />
        <vers num="5.0" edition=":mac" />
        <vers num="5.0.2" edition="" />
        <vers num="5.0.2" edition=":win32" />
        <vers num="5.1.0" edition="" />
        <vers num="5.1.0" edition=":win32" />
        <vers num="5.1.1" edition="" />
        <vers num="5.1.1" edition=":win32" />
        <vers num="5.12" edition="" />
        <vers num="5.12" edition=":win32" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":win32" />
        <vers num="6.0.1" edition=":linux" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":linux" />
        <vers num="6.0.2" edition=":win32" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":linux" />
        <vers num="6.0.3" edition=":win32" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":win32" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="6.0.6" edition="" />
        <vers num="6.0.6" edition=":win32" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":linux" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.11b" />
        <vers num="7.11j" />
        <vers num="7.20" />
        <vers num="7.20_beta1_build2981" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.50" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" />
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0457" published="2005-05-02" name="CVE-2005-0457" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-17</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=81747" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=81747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.50" />
        <vers num="7.50b1" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0458" published="2005-05-02" name="CVE-2005-0458" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110851122614995&amp;w=2" source="BUGTRAQ" adv="1">20050215 [NOBYTES.COM: #3] osCommerce 2.2-MS2 - XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="oscommerce">
        <vers num="2.2_ms2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0459" published="2005-05-02" name="CVE-2005-0459" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013210" source="SECTRACK" adv="1">1013210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2_pre1" />
        <vers num="2.2_rc1" />
        <vers num="2.2_rc2" />
        <vers num="2.2_rc3" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.5_pl1" />
        <vers num="2.5.5_rc1" />
        <vers num="2.5.5_rc2" />
        <vers num="2.5.6_rc1" />
        <vers num="2.5.7" />
        <vers num="2.5.7_pl1" />
        <vers num="2.6.0_pl1" />
        <vers num="2.6.0_pl2" />
        <vers num="2.6.0_pl3" />
        <vers num="2.6.2_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0460" published="2005-05-02" name="CVE-2005-0460" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/13787" source="OSVDB" patch="1" adv="1">13787</ref>
      <ref url="http://secunia.com/advisories/14284" source="SECUNIA" patch="1" adv="1">14284</ref>
      <ref url="http://lostmon.blogspot.com/2005/02/mercuryboard-debug-information.html" source="MISC" patch="1" adv="1">http://lostmon.blogspot.com/2005/02/mercuryboard-debug-information.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0461" published="2005-05-02" name="CVE-2005-0461" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14262" source="SECUNIA" patch="1" adv="1">14262</ref>
      <ref url="http://newsbruiser.tigris.org/servlets/NewsItemView?newsItemID=1016" source="CONFIRM" patch="1">http://newsbruiser.tigris.org/servlets/NewsItemView?newsItemID=1016</ref>
      <ref url="http://newsbruiser.tigris.org/source/browse/newsbruiser/CHANGELOG?rev=1.283&amp;content-type=text/x-cvsweb-markup" source="CONFIRM">http://newsbruiser.tigris.org/source/browse/newsbruiser/CHANGELOG?rev=1.283&amp;content-type=text/x-cvsweb-markup</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0462" published="2005-02-17" name="CVE-2005-0462" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13937" source="SECUNIA" patch="1" adv="1">13937</ref>
      <ref url="http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html" source="MISC">http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0463" published="2005-05-02" name="CVE-2005-0463" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12610" source="BID" patch="1">12610</ref>
      <ref url="http://www.inl.fr/article.php3?id_article=7" source="CONFIRM" patch="1" adv="1">http://www.inl.fr/article.php3?id_article=7</ref>
      <ref url="http://securitytracker.com/id?1013220" source="SECTRACK" patch="1" adv="1">1013220</ref>
      <ref url="http://secunia.com/advisories/14321" source="SECUNIA" patch="1" adv="1">14321</ref>
      <ref url="http://www.osvdb.org/13853" source="OSVDB" adv="1">13853</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inl" name="ulog-php">
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0464" published="2005-05-02" name="CVE-2005-0464" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=226&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050407 SGI IRIX gr_osview Information Disclosure Vulnerability</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050402-01-P" source="SGI" patch="1">20050402-01-P</ref>
      <ref url="http://www.osvdb.org/15351" source="OSVDB">15351</ref>
      <ref url="http://securitytracker.com/id?1013662" source="SECTRACK">1013662</ref>
      <ref url="http://secunia.com/advisories/14875" source="SECUNIA">14875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0465" published="2005-05-02" name="CVE-2005-0465" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=225&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050407 SGI IRIX gr_osview File Overwrite Vulnerability</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050402-01-P" source="SGI" patch="1">20050402-01-P</ref>
      <ref url="http://securitytracker.com/id?1013662" source="SECTRACK">1013662</ref>
      <ref url="http://secunia.com/advisories/14875" source="SECUNIA">14875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.1t" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.4b" />
        <vers num="4.0.4t" />
        <vers num="4.0.5" />
        <vers num="4.0.5_iop" />
        <vers num="4.0.5_ipr" />
        <vers num="4.0.5a" />
        <vers num="4.0.5b" />
        <vers num="4.0.5e" />
        <vers num="4.0.5f" />
        <vers num="4.0.5g" />
        <vers num="4.0.5h" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.10f" />
        <vers num="6.5.10m" />
        <vers num="6.5.11" />
        <vers num="6.5.11f" />
        <vers num="6.5.11m" />
        <vers num="6.5.12" />
        <vers num="6.5.12f" />
        <vers num="6.5.12m" />
        <vers num="6.5.13" />
        <vers num="6.5.13f" />
        <vers num="6.5.13m" />
        <vers num="6.5.14" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22" />
        <vers num="6.5.2f" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.4f" />
        <vers num="6.5.4m" />
        <vers num="6.5.5" />
        <vers num="6.5.5f" />
        <vers num="6.5.5m" />
        <vers num="6.5.6" />
        <vers num="6.5.6f" />
        <vers num="6.5.6m" />
        <vers num="6.5.7" />
        <vers num="6.5.7f" />
        <vers num="6.5.7m" />
        <vers num="6.5.8" />
        <vers num="6.5.8f" />
        <vers num="6.5.8m" />
        <vers num="6.5.9" />
        <vers num="6.5.9f" />
        <vers num="6.5.9m" />
        <vers num="6.5_20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0467" published="2005-02-21" name="CVE-2005-0467" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=201&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050221 Multiple PuTTY SFTP Client Packet Parsing Integer Overflow Vulnerabilities</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-28</ref>
      <ref url="http://secunia.com/advisories/14333" source="SECUNIA" patch="1" adv="1">14333</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19403" source="XF">putty-sftppktgetstring-bo(19403)</ref>
      <ref url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html" source="CONFIRM" adv="1">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html</ref>
      <ref url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html" source="CONFIRM" adv="1">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414</ref>
      <ref url="http://secunia.com/advisories/17214" source="SECUNIA">17214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="putty" name="putty">
        <vers prev="1" num="0.56" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0468" published="2005-05-02" name="CVE-2005-0468" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/341908" source="CERT-VN">VU#341908</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-330.html" source="REDHAT" patch="1" adv="1">RHSA-2005:330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-327.html" source="REDHAT" patch="1" adv="1">RHSA-2005:327</ref>
      <ref url="http://www.debian.org/security/2005/dsa-703" source="DEBIAN" patch="1" adv="1">DSA-703</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050405-01-P" source="SGI" patch="1">20050405-01-P</ref>
      <ref url="http://www.ubuntulinux.org/usn/usn-224-1" source="UBUNTU">USN-224-1</ref>
      <ref url="http://www.securityfocus.com/bid/12919" source="BID">12919</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=221&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050328 Multiple Telnet Client env_opt_add() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.debian.de/security/2005/dsa-731" source="DEBIAN">DSA-731</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1" source="SUNALERT">57761</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1" source="SUNALERT">57755</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1" source="SUNALERT">101671</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1" source="SUNALERT">101665</ref>
      <ref url="http://secunia.com/advisories/17899" source="SECUNIA">17899</ref>
      <ref url="http://secunia.com/advisories/14745" source="SECUNIA">14745</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9640" source="OVAL">oval:org.mitre.oval:def:9640</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000962" source="CONECTIVA">CLA-2005:962</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc" source="FREEBSD" adv="1">FreeBSD-SA-05:01.telnet</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:061" source="MANDRAKE">MDKSA-2005:061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncsa" name="telnet">
        <vers num="c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0469" published="2005-05-02" name="CVE-2005-0469" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/291924" source="CERT-VN" adv="1">VU#291924</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-330.html" source="REDHAT" patch="1" adv="1">RHSA-2005:330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-327.html" source="REDHAT" patch="1" adv="1">RHSA-2005:327</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=220&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050328 Multiple Telnet Client slc_add_reply() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-36.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-36</ref>
      <ref url="http://www.debian.org/security/2005/dsa-703" source="DEBIAN" patch="1" adv="1">DSA-703</ref>
      <ref url="http://www.debian.org/security/2005/dsa-699" source="DEBIAN" patch="1" adv="1">DSA-699</ref>
      <ref url="http://www.debian.org/security/2005/dsa-697" source="DEBIAN" patch="1" adv="1">DSA-697</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1" source="SUNALERT" patch="1" adv="1">57755</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050405-01-P" source="SGI" patch="1">20050405-01-P</ref>
      <ref url="http://www.ubuntulinux.org/usn/usn-224-1" source="UBUNTU">USN-224-1</ref>
      <ref url="http://www.securityfocus.com/bid/12918" source="BID">12918</ref>
      <ref url="http://www.debian.de/security/2005/dsa-731" source="DEBIAN">DSA-731</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1" source="SUNALERT">57761</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1" source="SUNALERT">101671</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1" source="SUNALERT">101665</ref>
      <ref url="http://secunia.com/advisories/17899" source="SECUNIA">17899</ref>
      <ref url="http://secunia.com/advisories/14745" source="SECUNIA">14745</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9708" source="OVAL">oval:org.mitre.oval:def:9708</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc" source="FREEBSD" adv="1">FreeBSD-SA-05:01.telnet</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:061" source="MANDRAKE">MDKSA-2005:061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncsa" name="telnet">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0470" published="2005-03-14" name="CVE-2005-0470" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19357" source="XF" patch="1" adv="1">wpasupplicant-bo(19357)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-22</ref>
      <ref url="http://secunia.com/advisories/14313" source="SECUNIA" patch="1" adv="1">14313</ref>
      <ref url="http://securitytracker.com/id?1013226" source="SECTRACK">1013226</ref>
      <ref url="http://lists.shmoo.com/pipermail/hostap/2005-February/009465.html" source="MLIST">[HostAP] 20050213 wpa_supplicant - new stable releases v0.3.8 and v0.2.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wpa_supplicant" name="wpa_supplicant">
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0471" published="2005-03-14" name="CVE-2005-0471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/544392" source="CERT-VN" adv="1">VU#544392</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19285" source="XF">sun-java-create-files(19285)</ref>
      <ref url="http://secunia.com/secunia_research/2004-7/advisory/" source="MISC">http://secunia.com/secunia_research/2004-7/advisory/</ref>
      <ref url="http://secunia.com/advisories/11070/" source="SECUNIA" adv="1">11070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.3.0" />
        <vers num="1.4.0" />
        <vers num="1.5.0" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3.0" />
        <vers num="1.4" />
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0472" published="2005-03-14" name="CVE-2005-0472" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/839280" source="CERT-VN" patch="1" adv="1">VU#839280</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19380" source="XF" patch="1" adv="1">gaim-snac-dos(19380)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-432.html" source="REDHAT">RHSA-2005:432</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-215.html" source="REDHAT">RHSA-2005:215</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml" source="GENTOO">GLSA-200503-03</ref>
      <ref url="http://www.debian.org/security/2005/dsa-716" source="DEBIAN">DSA-716</ref>
      <ref url="http://secunia.com/advisories/14322" source="SECUNIA">14322</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10433" source="OVAL">oval:org.mitre.oval:def:10433</ref>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=10" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/index.php?id=10</ref>
      <ref url="http://www.securityfocus.com/bid/12589" source="BID">12589</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049" source="MANDRAKE">MDKSA-2005:049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2" source="BUGTRAQ">20050225 [USN-85-1] Gaim vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933" source="CONECTIVA">CLA-2005:933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0473" published="2005-03-14" name="CVE-2005-0473" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/523888" source="CERT-VN" patch="1" adv="1">VU#523888</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19381" source="XF" patch="1" adv="1">gaim-html-dos(19381)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-215.html" source="REDHAT" patch="1" adv="1">RHSA-2005:215</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml" source="GENTOO">GLSA-200503-03</ref>
      <ref url="http://secunia.com/advisories/14322" source="SECUNIA">14322</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10212" source="OVAL">oval:org.mitre.oval:def:10212</ref>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=11" source="CONFIRM">http://gaim.sourceforge.net/security/index.php?id=11</ref>
      <ref url="http://www.securityfocus.com/bid/12589" source="BID">12589</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049" source="MANDRAKE">MDKSA-2005:049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2" source="BUGTRAQ">20050225 [USN-85-1] Gaim vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933" source="CONECTIVA">CLA-2005:933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0474" published="2005-03-30" name="CVE-2005-0474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19369" source="XF" patch="1" adv="1">webcalendar-sql-injection(19369)</ref>
      <ref url="http://www.scovettalabs.com/advisory/SCL-2005.001.txt" source="MISC" patch="1" adv="1">http://www.scovettalabs.com/advisory/SCL-2005.001.txt</ref>
      <ref url="http://secunia.com/advisories/14319" source="SECUNIA" patch="1" adv="1">14319</ref>
      <ref url="http://www.osvdb.org/13918" source="OSVDB">13918</ref>
      <ref url="http://securitytracker.com/id?1013231" source="SECTRACK">1013231</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868446431706&amp;w=2" source="BUGTRAQ">20050217 [ SCL-2005.001 ] - WebCalendar: SQL Injection from encoded cookie</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="0.9.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0475" published="2005-03-30" name="CVE-2005-0475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868808723487&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050217 [PersianHacker.NET 200505-07] paFAQ Beta4 Sql Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19371" source="XF" adv="1">pafaq-sql-injection(19371)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafaq">
        <vers num="beta4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0476" published="2005-03-30" name="CVE-2005-0476" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19372" source="XF">hpm-guestbook-xss(19372)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110869187805397&amp;w=2" source="BUGTRAQ">20050217 hpm_guestbook.cgi JavaScript-Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hpm_guestbook.cgi" name="hpm_guestbook.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0477" published="2005-03-30" name="CVE-2005-0477" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19399" source="XF">invision-power-board-sml-xss(19399)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868196922995&amp;w=2" source="BUGTRAQ" adv="1">20050217 Invision Power Boards 1.3.1 FINAL XSS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1_final" />
        <vers num="1.3_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0478" published="2005-03-30" name="CVE-2005-0478" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19411" source="XF">trackercam-php-bo(19411)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19409" source="XF">trackercam-useragent-bo(19409)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0479" published="2005-03-30" name="CVE-2005-0479" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." sequences and (1) "/" slash), (2) "\" (backslash), or (3) hex-encoded characters in the fn parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19414" source="XF">trackercam-fn-directory-traversal(19414)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0480" published="2005-03-30" name="CVE-2005-0480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and earlier allows remote attackers to inject arbitrary HTML or web script via the login request, which is recorded in a log file but not properly handled when the administrator views the log file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19416" source="XF">trackercam-xss(19416)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0481" published="2005-03-30" name="CVE-2005-0481" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19415" source="XF">trackercam-fn-path-disclosure(19415)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0482" published="2005-03-30" name="CVE-2005-0482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TrackerCam 5.12 and earlier allows remote attackers to cause a denial of service (crash) via (1) a large number of connections with a negative Content-Length header, possibly triggering an integer signedness error, or (2) a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19417" source="XF">trackercam-contentlength-dos(19417)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0483" published="2005-03-30" name="CVE-2005-0483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19401" source="XF">glftpd-sitenfosh-directory-traversal(19401)</ref>
      <ref url="http://www.securityfocus.com/bid/12586" source="BID" adv="1">12586</ref>
      <ref url="http://www.securityfocus.com/archive/1/390924" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in Glftpd v1.26 - v2.00 default zip based plug-ins</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glftpd" name="glftpd">
        <vers num="1.26" />
        <vers num="1.27" />
        <vers num="1.28" />
        <vers num="1.29.1" />
        <vers num="1.31" />
        <vers num="1.32" />
        <vers num="2.0" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
        <vers num="2.0_rc5" />
        <vers num="2.0_rc6" />
        <vers num="2.0_rc7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0484" published="2005-03-30" name="CVE-2005-0484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-26.xml" source="GENTOO" adv="1">GLSA-200502-26</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=81894" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=81894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gproftpd" name="gproftpd">
        <vers prev="1" num="8.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0485" published="2005-03-30" name="CVE-2005-0485" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110863062605906&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050216 [PersianHacker.NET 200505-06] paNews v2.0b4 XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19359" source="XF" adv="1">panews-commentphp-xss(19359)</ref>
      <ref url="http://www.securityfocus.com/bid/12576" source="BID" adv="1">12576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="panews">
        <vers num="2.0_b4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0486" published="2005-03-30" name="CVE-2005-0486" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tarantella.com/security/bulletin-11.html" source="CONFIRM" patch="1" adv="1">http://www.tarantella.com/security/bulletin-11.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19407" source="XF">tarantella-enterprise-obtain-information(19407)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tarantella" name="secure_global_desktop">
        <vers num="enterprise_3.42" />
        <vers num="enterprise_4.0" />
      </prod>
      <prod vendor="tarantella" name="tarantella_enterprise">
        <vers num="3.30" />
        <vers num="3.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0487" published="2005-03-30" name="CVE-2005-0487" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18571" source="XF">kayako-index-xss(18571)</ref>
      <ref url="http://www.securityfocus.com/bid/12563" source="BID" adv="1">12563</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110845724029888&amp;w=2" source="FULLDISC" adv="1">20050215 Kayako eSupport v2.3.1 Support Tracker XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="esupport">
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0488" published="2005-06-14" name="CVE-2005-0488" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/800829" source="CERT-VN" patch="1" adv="1">VU#800829</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1" source="SUNALERT" patch="1" adv="1">57761</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1" source="SUNALERT" patch="1" adv="1">57755</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-504.html" source="REDHAT">RHSA-2005:504</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_sr.html" source="SUSE">SUSE-SR:2005:016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11373" source="OVAL">oval:org.mitre.oval:def:11373</ref>
      <ref url="http://idefense.com/application/poi/display?id=260&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050614 Multiple Vendor Telnet Client Information Disclosure Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.securityfocus.com/bid/13940" source="BID">13940</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-562.html" source="REDHAT">RHSA-2005:562</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1" source="SUNALERT">101671</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1" source="SUNALERT">101665</ref>
      <ref url="http://securitytracker.com/id?1014203" source="SECTRACK">1014203</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA">17135</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1139" source="OVAL" sig="1">oval:org.mitre.oval:def:1139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="telnet_client">
        <vers num="5.1.2600.2180" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.3.4" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0489" published="2005-12-31" name="CVE-2005-0489" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.27</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18173" source="BID" patch="1">18173</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN" patch="1" adv="1">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN" patch="1" adv="1">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN" patch="1" adv="1">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN" patch="1" adv="1">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA" patch="1" adv="1">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA" patch="1" adv="1">20163</ref>
      <ref url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes" source="CONFIRM" patch="1">http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0490" published="2005-05-02" name="CVE-2005-0490" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-20</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110959085507755&amp;w=2" source="FULLDISC" patch="1" adv="1">20050228 [USN-86-1] cURL vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000940" source="CONECTIVA" patch="1" adv="1">CLA-2005:940</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19423" source="XF">curl-kerberos-bo(19423)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=203&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050221 Multiple Unix/Linux Vendor cURL/libcURL Kerberos Authentication Buffer Overflow Vulnerability</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=202&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050221 Multiple Unix/Linux Vendor cURL/libcURL NTLM Authentication Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10273" source="OVAL">oval:org.mitre.oval:def:10273</ref>
      <ref url="http://www.securityfocus.com/bid/12616" source="BID">12616</ref>
      <ref url="http://www.securityfocus.com/bid/12615" source="BID">12615</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-340.html" source="REDHAT">RHSA-2005:340</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_11_curl.html" source="SUSE">SUSE-SA:2005:011</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:048" source="MANDRAKE">MDKSA-2005:048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="curl" name="curl">
        <vers num="7.12.1" />
      </prod>
      <prod vendor="libcurl" name="libcurl">
        <vers num="7.12.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0491" published="2005-05-02" name="CVE-2005-0491" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12594" source="BID" patch="1">12594</ref>
      <ref url="http://secunia.com/advisories/14327" source="SECUNIA" patch="1" adv="1">14327</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19398" source="XF">arkeia-backup-client-bo(19398)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110887325425794&amp;w=2" source="BUGTRAQ" adv="1">20050218 Knox Arkeia remote root/system exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knox_software" name="arkeia_server_backup">
        <vers num="5.3.0" />
        <vers num="5.3.0_rc1" />
        <vers num="5.3.0_rc2" />
        <vers num="5.3.0_rc3" />
        <vers num="5.3.0_rc4" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
        <vers num="5.3.3" />
        <vers num="5.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0492" published="2005-05-02" name="CVE-2005-0492" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/331468.html" source="CONFIRM" patch="1">http://www.adobe.com/support/techdocs/331468.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19946" source="XF">adobe-root-page-node-dos(19946)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0310" source="VUPEN">ADV-2005-0310</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110879063511486&amp;w=2" source="BUGTRAQ" adv="1">20050218 Adobe Reader invalid root page node Count value DOS</ref>
      <ref url="http://secunia.com/advisories/14813" source="SECUNIA">14813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0.3" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0493" published="2005-05-02" name="CVE-2005-0493" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam e-mail via CRLF sequences and forged mail headers in the email parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to newest version.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110876655521321&amp;w=2" source="BUGTRAQ" adv="1">20050218 BizMail 2.1 Spam Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seth_m._knorr" name="biz_mail_form">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0494" published="2005-02-21" name="CVE-2005-0494" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19387" source="XF">thomson-tcw690-gain-access(19387)</ref>
      <ref url="http://secunia.com/advisories/14353" source="SECUNIA" adv="1">14353</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886937131507&amp;w=2" source="BUGTRAQ" adv="1">20050219 Thomson TCW690 POST Password Validation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomson" name="thomson_cable_modem">
        <vers num="tcw690" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0495" published="2005-02-19" name="CVE-2005-0495" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19420" source="XF">zeroboard-xss(19420)</ref>
      <ref url="http://securitytracker.com/id?1013243" source="SECTRACK" adv="1">1013243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110884332105513&amp;w=2" source="BUGTRAQ" adv="1">20050219 Multiples vulnerability in ZeroBoard,</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2" />
        <vers num="4.1_pl3" />
        <vers num="4.1_pl4" />
        <vers num="4.1_pl5" />
        <vers num="4.1_pl6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0496" published="2005-02-21" name="CVE-2005-0496" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20667" source="XF">arkeia-backup-client-gain-access(20667)</ref>
      <ref url="http://securitytracker.com/id?1013256" source="SECTRACK" adv="1">1013256</ref>
      <ref url="http://metasploit.com/research/arkeia_agent/" source="MISC" adv="1">http://metasploit.com/research/arkeia_agent/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900879826004&amp;w=2" source="BUGTRAQ" adv="1">20050220 Arkeia Network Backup Client Remote Access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knox_software" name="arkeia">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0497" published="2005-05-02" name="CVE-2005-0497" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901051420503&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050219 ADP Elite System Max 9000 Series Login Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20622" source="XF">adp-elite-gain-privileges(20622)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adp" name="elite_system_max_9000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0498" published="2005-05-02" name="CVE-2005-0498" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19422" source="XF">gigafast-backupcfg-plaintext-password(19422)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900986022760&amp;w=2" source="BUGTRAQ" adv="1">20050220 Gigafast/CompUSA router (model EE400-R) vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigafast_ethernet" name="gigafast_router">
        <vers num="ee400-r" />
        <vers num="ee410-r" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0499" published="2005-02-20" name="CVE-2005-0499" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19426" source="XF">gigafast-dns-queries-dos(19426)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900986022760&amp;w=2" source="BUGTRAQ" adv="1">20050220 Gigafast/CompUSA router (model EE400-R) vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigafast_ethernet" name="gigafast_router">
        <vers num="ee400-r" />
        <vers num="ee410-r" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0500" published="2005-05-02" name="CVE-2005-0500" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19452" source="XF">ie-title-bar-spoofing(19452)</ref>
      <ref url="http://www.securityfocus.com/bid/12602" source="BID">12602</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110895997201027&amp;w=2" source="FULLDISC" adv="1">20050221 WindowsXPSP2 script-initiated popup window</ref>
      <ref url="http://secunia.com/advisories/14335" source="SECUNIA">14335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0501" published="2005-05-02" name="CVE-2005-0501" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Bontago 1.1 and earlier allows remote attackers exeucte arbitrary code via a long nickname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19406" source="XF">bontago-nickname-bo(19406)</ref>
      <ref url="http://www.securityfocus.com/bid/12603" source="BID">12603</ref>
      <ref url="http://secunia.com/advisories/14350" source="SECUNIA" adv="1">14350</ref>
      <ref url="http://aluigi.altervista.org/adv/bontagobof-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/bontagobof-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digipen_institute_of_technology" name="bontago">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0502" published="2005-02-18" name="CVE-2005-0502" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19404" source="XF">xinkaa-web-directory-traversal(19404)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0189" source="VUPEN">ADV-2005-0189</ref>
      <ref url="http://www.securityfocus.com/bid/12606" source="BID">12606</ref>
      <ref url="http://secunia.com/advisories/14349" source="SECUNIA" adv="1">14349</ref>
      <ref url="http://aluigi.altervista.org/adv/xinkaa-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/xinkaa-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xinkaa_web_station" name="xinkaa_web_station">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0503" published="2005-02-21" name="CVE-2005-0503" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12604" source="BID" patch="1" adv="1">12604</ref>
      <ref url="http://secunia.com/advisories/13981" source="SECUNIA" patch="1" adv="1">13981</ref>
      <ref url="http://lists.freedesktop.org/archives/uim/2005-February/000996.html" source="MLIST" adv="1">[uim] 20050220 uim 0.4.5.1 released</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:046" source="MANDRAKE">MDKSA-2005:046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uim" name="uim">
        <vers num="0.4.5" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0504" published="2005-03-14" name="CVE-2005-0504" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12195" source="BID" patch="1" adv="1">12195</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.ubuntu.com/usn/usn-508-1" source="UBUNTU">USN-508-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-551.html" source="REDHAT">RHSA-2005:551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-529.html" source="REDHAT">RHSA-2005:529</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://securitytracker.com/id?1013273" source="SECTRACK">1013273</ref>
      <ref url="http://secunia.com/advisories/30112" source="SECUNIA">30112</ref>
      <ref url="http://secunia.com/advisories/26651" source="SECUNIA" adv="1">26651</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA" adv="1">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA" adv="1">20163</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA" adv="1">17002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9770" source="OVAL">oval:org.mitre.oval:def:9770</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" source="FULLDISC">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0237.html" source="REDHAT">RHSA-2008:0237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.99" edition="pre1" />
        <vers num="2.3.99" edition="pre2" />
        <vers num="2.3.99" edition="pre3" />
        <vers num="2.3.99" edition="pre4" />
        <vers num="2.3.99" edition="pre5" />
        <vers num="2.3.99" edition="pre6" />
        <vers num="2.3.99" edition="pre7" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers prev="1" num="2.6.21" edition="rc7" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0505" published="2005-03-14" name="CVE-2005-0505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers has "potentially serious" impact, related to LDAP logins.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19419" source="XF" patch="1" adv="1">irm-ldap-security-bypass(19419)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=306629" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=306629</ref>
      <ref url="http://secunia.com/advisories/14342" source="SECUNIA" patch="1" adv="1">14342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stackworks_enterprises" name="information_resource_manager">
        <vers num="1.4.3" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0506" published="2005-03-14" name="CVE-2005-0506" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-041_Sensitive_Info_Leak.pdf" source="CONFIRM" adv="1">http://support.avaya.com/elmodocs2/security/ASA-2005-041_Sensitive_Info_Leak.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910486128709&amp;w=2" source="BUGTRAQ" adv="1">20050222 Re: Avaya IP Office Phone Manager - Sensitive Information Cleartext Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110909733831694&amp;w=2" source="BUGTRAQ" adv="1">20050222 Avaya IP Office Phone Manager - Sensitive Information Cleartext</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip_office_phone_manager">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="ip_soft_phone">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0507" published="2005-03-14" name="CVE-2005-0507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SD Server 4.0.70 and earlier allows remote attackers to read arbitrary files via .. sequences in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14365" source="SECUNIA" patch="1" adv="1">14365</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110901639709476&amp;w=2" source="FULLDISC" patch="1" adv="1">20050221 SD Server 4.0.70 Directory Traversal Bug</ref>
      <ref url="http://www.gdsoftware.dk/" source="CONFIRM">http://www.gdsoftware.dk/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910535122762&amp;w=2" source="BUGTRAQ">20050222 SD Server 4.0.70 Directory Traversal Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gd_software" name="sd_server">
        <vers num="4.0.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0508" published="2005-03-14" name="CVE-2005-0508" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12619" source="BID" patch="1" adv="1">12619</ref>
      <ref url="http://secunia.com/advisories/14336" source="SECUNIA" patch="1" adv="1">14336</ref>
      <ref url="http://xml.apache.org/batik/#SecurityWarning" source="CONFIRM">http://xml.apache.org/batik/#SecurityWarning</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0509" published="2005-03-14" name="CVE-2005-0509" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "&lt;".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14325" source="SECUNIA" patch="1" adv="1">14325</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2" source="BUGTRAQ">20050217 XSS vulnerabilty in ASP.Net [with details]</ref>
      <ref url="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml" source="MISC">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp1" />
        <vers num="1.0" edition="sp2" />
        <vers num="1.1" edition="sp1" />
      </prod>
      <prod vendor="mono" name="mono">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0510" published="2005-03-14" name="CVE-2005-0510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14328" source="SECUNIA" patch="1" adv="1">14328</ref>
      <ref url="http://dcs.nac.uci.edu/~strombrg/fallback-reboot/" source="CONFIRM" adv="1">http://dcs.nac.uci.edu/~strombrg/fallback-reboot/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fallback-reboot" name="fallback-reboot">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0511" published="2005-02-21" name="CVE-2005-0511" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14326" source="SECUNIA" patch="1" adv="1">14326</ref>
      <ref url="http://www.vbulletin.com/forum/showthread.php?postid=819562" source="CONFIRM">http://www.vbulletin.com/forum/showthread.php?postid=819562</ref>
      <ref url="http://www.securityfocus.com/bid/12622" source="BID">12622</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910899415763&amp;w=2" source="BUGTRAQ" adv="1">20050222 [SCAN Associates Security Advisory] vbulletin 3.0.6 and below php code injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0_beta_2" />
        <vers num="2.0_beta_3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9_can" />
        <vers num="2.3.0" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="3.0.0" />
        <vers num="3.0.0_beta_2" />
        <vers num="3.0.0_can4" />
        <vers num="3.0.0_rc4" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0512" published="2005-02-21" name="CVE-2005-0512" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14337" source="SECUNIA" patch="1" adv="1">14337</ref>
      <ref url="http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip" source="CONFIRM" patch="1">http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo">
        <vers prev="1" num="4.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0513" published="2005-02-19" name="CVE-2005-0513" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying the pm_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2003-1086.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12597" source="BID" patch="1" adv="1">12597</ref>
      <ref url="http://www.securityfocus.com/bid/15473" source="BID">15473</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110883604531802&amp;w=2" source="FULLDISC" adv="1">20050219 pMachine Pro / pMachine Free Remote Code Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmachine" name="pmachine_pro">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0514" published="2005-02-22" name="CVE-2005-0514" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/716144" source="CERT-VN" patch="1" adv="1">VU#716144</ref>
      <ref url="http://www.mikx.de/index.php?p=6" source="MISC" patch="1" adv="1">http://www.mikx.de/index.php?p=6</ref>
      <ref url="http://secunia.com/advisories/14367" source="SECUNIA" patch="1" adv="1">14367</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html" source="FULLDISC" adv="1">20041223 Cross-Site Scripting - an industry-wide problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verity" name="verity_ultraseek">
        <vers num="5.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0515" published="2005-05-18" name="CVE-2005-0515" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary files by saving log files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.webroot.com/services/mfp_advisory.php" source="CONFIRM" patch="1" adv="1">http://www.webroot.com/services/mfp_advisory.php</ref>
      <ref url="http://www.securityfocus.com/bid/12842" source="BID" patch="1" adv="1">12842</ref>
      <ref url="http://secunia.com/secunia_research/2004-20/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2004-20/advisory/</ref>
      <ref url="http://secunia.com/advisories/13577" source="SECUNIA" patch="1" adv="1">13577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webroot_software" name="my_firewall_plus">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0516" published="2005-02-23" name="CVE-2005-0516" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14384" source="SECUNIA" patch="1" adv="1">14384</ref>
      <ref url="http://www.enyo.de/fw/security/notes/twiki-robustness.html" source="MISC" adv="1">http://www.enyo.de/fw/security/notes/twiki-robustness.html</ref>
      <ref url="http://static.enyo.de/fw/patches/twiki/imagegallery-robustness-20041128.diff" source="MISC" adv="1">http://static.enyo.de/fw/patches/twiki/imagegallery-robustness-20041128.diff</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110918725225288&amp;w=2" source="BUGTRAQ" adv="1">20050223 Robustness patch for TWiki, vulnerability in ImageGalleryPlugin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="twiki" name="imagegalleryplugin">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0517" published="2005-02-23" name="CVE-2005-0517" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013263" source="SECTRACK" adv="1">1013263</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peerftp_5" name="peerftp_5">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0518" published="2005-02-23" name="CVE-2005-0518" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013266" source="SECTRACK" adv="1">1013266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exeem" name="exeem">
        <vers num="0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0519" published="2005-02-18" name="CVE-2005-0519" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.argosoft.com/ftpserver/changelist.aspx" source="CONFIRM" patch="1" adv="1">http://www.argosoft.com/ftpserver/changelist.aspx</ref>
      <ref url="http://secunia.com/advisories/14172" source="SECUNIA" patch="1">14172</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17939" source="XF">argosoft-ink-file-upload(17939)</ref>
      <ref url="http://www.securityfocus.com/bid/12487" source="BID">12487</ref>
      <ref url="http://www.osvdb.org/13614" source="OSVDB">13614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="ftp_server">
        <vers num="1.4.1.1" />
        <vers num="1.4.1.2" />
        <vers num="1.4.1.3" />
        <vers num="1.4.1.4" />
        <vers num="1.4.1.5" />
        <vers num="1.4.1.6" />
        <vers num="1.4.1.7" />
        <vers num="1.4.1.8" />
        <vers num="1.4.1.9" />
        <vers num="1.4.2" />
        <vers num="1.4.2.1" />
        <vers num="1.4.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0520" published="2005-02-23" name="CVE-2005-0520" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.argosoft.com/ftpserver/changelist.aspx" source="CONFIRM" patch="1" adv="1">http://www.argosoft.com/ftpserver/changelist.aspx</ref>
      <ref url="http://secunia.com/advisories/14372" source="SECUNIA" patch="1" adv="1">14372</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19442" source="XF">argosoft-site-copy-files(19442)</ref>
      <ref url="http://www.securityfocus.com/bid/12632" source="BID">12632</ref>
      <ref url="http://www.osvdb.org/14061" source="OSVDB">14061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="ftp_server">
        <vers num="1.4.1.1" />
        <vers num="1.4.1.2" />
        <vers num="1.4.1.3" />
        <vers num="1.4.1.4" />
        <vers num="1.4.1.5" />
        <vers num="1.4.1.6" />
        <vers num="1.4.1.7" />
        <vers num="1.4.1.8" />
        <vers num="1.4.1.9" />
        <vers num="1.4.2" />
        <vers num="1.4.2.1" />
        <vers num="1.4.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0521" published="2005-02-23" name="CVE-2005-0521" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013269" source="SECTRACK" adv="1">1013269</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0522" published="2005-05-02" name="CVE-2005-0522" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013270" source="SECTRACK">1013270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="chat_anywhere">
        <vers num="2.72a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0523" published="2005-05-02" name="CVE-2005-0523" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-719" source="DEBIAN" patch="1">DSA-719</ref>
      <ref url="http://www.securityfocus.com/bid/12635" source="BID">12635</ref>
      <ref url="http://www.securiteam.com/exploits/5WP082KEUW.html" source="MISC">http://www.securiteam.com/exploits/5WP082KEUW.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prozilla" name="prozilla_download_accelerator">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.5.1" />
        <vers num="1.3.5.2" />
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0524" published="2005-05-02" name="CVE-2005-0524" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/394797" source="IDEFENSE" patch="1" adv="1">20050331 PHP getimagesize() Multiple Denial of Service Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1013619" source="SECTRACK" patch="1">1013619</ref>
      <ref url="http://secunia.com/advisories/14792" source="SECUNIA" patch="1">14792</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19920" source="XF">php-phphandleiff-dos(19920)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0305" source="VUPEN">ADV-2005-0305</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-406.html" source="REDHAT">RHSA-2005:406</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-405.html" source="REDHAT">RHSA-2005:405</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml" source="GENTOO">GLSA-200504-15</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9310" source="OVAL">oval:org.mitre.oval:def:9310</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
      <ref url="http://www.osvdb.org/15183" source="OSVDB">15183</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.2.2" />
        <vers num="4.3.10" />
        <vers num="4.3.9" />
        <vers num="5.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0525" published="2005-05-02" name="CVE-2005-0525" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-708" source="DEBIAN" patch="1">DSA-708</ref>
      <ref url="http://secunia.com/advisories/14792" source="SECUNIA" patch="1">14792</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0305" source="VUPEN">ADV-2005-0305</ref>
      <ref url="http://www.securityfocus.com/archive/1/394797" source="IDEFENSE" adv="1">20050331 PHP getimagesize() Multiple Denial of Service Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-406.html" source="REDHAT">RHSA-2005:406</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-405.html" source="REDHAT">RHSA-2005:405</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml" source="GENTOO">GLSA-200504-15</ref>
      <ref url="http://www.debian.org/security/2005/dsa-729" source="DEBIAN">DSA-729</ref>
      <ref url="http://securitytracker.com/id?1013619" source="SECTRACK">1013619</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11703" source="OVAL">oval:org.mitre.oval:def:11703</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
      <ref url="http://www.osvdb.org/15184" source="OSVDB">15184</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.2.2" />
        <vers num="4.3.10" />
        <vers num="4.3.9" />
        <vers num="5.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0526" published="2005-05-02" name="CVE-2005-0526" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PBLang 4.65 allow remote attackers to inject arbitrary web script or HTML via (1) the search string to search.php, (2) the subject of a PM, which is processed by pm.php, or (3) the body of a PM, which is processed by pmpshow.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013277" source="SECTRACK">1013277</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917768511595&amp;w=2" source="BUGTRAQ">20050222 Software PBLang 4.65 pm.php XSS vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917702708589&amp;w=2" source="BUGTRAQ">20050222 Software PBLang 4.65 pmpshow.php XSS vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917641105486&amp;w=2" source="BUGTRAQ">20050222 Software PBLang 4.65 search.php XSS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pblang" name="pblang">
        <vers num="4.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0527" published="2005-05-02" name="CVE-2005-0527" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1">GLSA-200503-10</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-27.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-27.html</ref>
      <ref url="http://www.mikx.de/?p=11" source="MISC">http://www.mikx.de/?p=11</ref>
      <ref url="http://securitytracker.com/id?1013301" source="SECTRACK">1013301</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11772" source="OVAL">oval:org.mitre.oval:def:11772</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935267500395&amp;w=2" source="BUGTRAQ">20050225 Firescrolling [Firefox 1.0]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100031" source="OVAL" sig="1">oval:org.mitre.oval:def:100031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0528" reject="1" published="2005-12-31" name="CVE-2005-0528" modified="2008-09-10" discovered="2004-01-05">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0985.  Reason: This candidate is a duplicate of CVE-2003-0985.  Notes: All CVE users should reference CVE-2003-0985 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0529" published="2005-05-02" name="CVE-2005-0529" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html" source="MISC" patch="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2" source="FULLDISC" patch="1">20050215 linux kernel 2.6 fun. windoze is a joke</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE">SUSE-SA:2005:018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8994" source="OVAL">oval:org.mitre.oval:def:8994</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@4201818eC6aMn0x3GY_9rw3ueb2ZWQ" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@4201818eC6aMn0x3GY_9rw3ueb2ZWQ</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" />
        <vers num="2.6.11_rc1_bk6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0530" published="2005-05-02" name="CVE-2005-0530" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Signedness error in the copy_from_read_buf function in n_tty.c for Linux kernel 2.6.10 and 2.6.11rc1 allows local users to read kernel memory via a negative argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html" source="MISC" patch="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2" source="FULLDISC" patch="1">20050215 linux kernel 2.6 fun. windoze is a joke</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE">SUSE-SA:2005:018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10960" source="OVAL">oval:org.mitre.oval:def:10960</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@420181322LZmhPTewcCOLkubGwOL3w" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@420181322LZmhPTewcCOLkubGwOL3w</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" />
        <vers num="2.6.11_rc1_bk6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0531" published="2005-05-02" name="CVE-2005-0531" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The atm_get_addr function in addr.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4 may allow local users to trigger a buffer overflow via negative arguments.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html" source="MISC" patch="1" adv="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2" source="FULLDISC" patch="1" adv="1">20050215 linux kernel 2.6 fun. windoze is a joke</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/gnupatch@4208e1fcfccuD-eH2OGM5mBhihmQ3A" source="CONFIRM" patch="1">http://linux.bkbits.net:8080/linux-2.6/gnupatch@4208e1fcfccuD-eH2OGM5mBhihmQ3A</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" patch="1">CLA-2005:930</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10095" source="OVAL">oval:org.mitre.oval:def:10095</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0532" published="2005-05-02" name="CVE-2005-0532" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The reiserfs_copy_from_user_to_file_region function in reiserfs/file.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4, when running on 64-bit architectures, may allow local users to trigger a buffer overflow as a result of casting discrepancies between size_t and int data types.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html" source="MISC" patch="1" adv="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2" source="FULLDISC" patch="1" adv="1">20050215 linux kernel 2.6 fun. windoze is a joke</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@42018227TkNpHlX6BefnItV_GqMmzQ" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@42018227TkNpHlX6BefnItV_GqMmzQ</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0533" published="2005-05-02" name="CVE-2005-0533" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+VSAPI+ARJ+parsing+could+allow+Remote+Code+execution" source="CONFIRM" patch="1">http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+VSAPI+ARJ+parsing+could+allow+Remote+Code+execution</ref>
      <ref url="http://www.securityfocus.com/bid/12643" source="BID" patch="1">12643</ref>
      <ref url="http://securitytracker.com/id?1013290" source="SECTRACK" patch="1" adv="1">1013290</ref>
      <ref url="http://securitytracker.com/id?1013289" source="SECTRACK" patch="1" adv="1">1013289</ref>
      <ref url="http://secunia.com/advisories/14396" source="SECUNIA" patch="1" adv="1">14396</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/189" source="ISS" adv="1">20050224 Trend Micro AntiVirus Library Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="client-server-messaging_suite_smb">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
      </prod>
      <prod vendor="trend_micro" name="client-server_suite_smb">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
      </prod>
      <prod vendor="trend_micro" name="control_manager">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
        <vers num="gold" edition=":solaris" />
        <vers num="gold" edition=":as_400" />
        <vers num="gold" edition=":windows_nt" />
        <vers num="gold" edition=":s_390" />
        <vers num="netware" />
      </prod>
      <prod vendor="trend_micro" name="interscan_emanager">
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":hp" />
        <vers num="3.5.2" edition="" />
        <vers num="3.5.2" edition=":windows" />
        <vers num="3.51" />
        <vers num="3.51_j" />
        <vers num="3.6" edition="" />
        <vers num="3.6" edition=":linux" />
        <vers num="3.6" edition=":sun" />
      </prod>
      <prod vendor="trend_micro" name="interscan_messaging_security_suite">
        <vers num="3.81" />
        <vers num="5.5" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
        <vers num="gold" edition=":solaris" />
        <vers num="gold" edition=":linux" />
      </prod>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":unix" />
        <vers num="3.0.1" edition=":linux" />
        <vers num="3.4" edition="" />
        <vers num="3.4" edition=":windows_nt" />
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":windows_nt" />
        <vers num="3.51" edition="" />
        <vers num="3.51" edition=":windows_nt" />
        <vers num="3.52" edition="" />
        <vers num="3.52" edition=":windows_nt" />
        <vers num="3.52_build1466" edition="" />
        <vers num="3.52_build1466" edition=":windows_nt" />
        <vers num="3.6" edition="" />
        <vers num="3.6" edition=":windows_nt" />
        <vers num="3.6" edition=":solaris" />
        <vers num="3.6" edition=":unix" />
        <vers num="3.6" edition=":hp_ux" />
        <vers num="3.6.5" edition="" />
        <vers num="3.6.5" edition=":linux" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":windows_nt" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
        <vers num="gold" edition=":aix" />
        <vers num="gold" edition=":smb" />
        <vers num="gold" edition=":linux_for_smb" />
        <vers num="gold" edition=":windows_nt_for_smb" />
      </prod>
      <prod vendor="trend_micro" name="interscan_web_security_suite">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":solaris" />
        <vers num="gold" edition=":linux" />
        <vers num="gold" edition=":windows" />
      </prod>
      <prod vendor="trend_micro" name="interscan_webmanager">
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="trend_micro" name="interscan_webprotect">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":isa" />
      </prod>
      <prod vendor="trend_micro" name="officescan">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":corporate" />
        <vers num="corporate_3.0" edition="" />
        <vers num="corporate_3.0" edition=":windows_nt_server" />
        <vers num="corporate_3.1.1" edition="" />
        <vers num="corporate_3.1.1" edition=":windows_nt_server" />
        <vers num="corporate_3.11" edition="" />
        <vers num="corporate_3.11" edition=":windows_nt_server" />
        <vers num="corporate_3.13" edition="" />
        <vers num="corporate_3.13" edition=":windows_nt_server" />
        <vers num="corporate_3.5" edition="" />
        <vers num="corporate_3.5" edition=":windows_nt_server" />
        <vers num="corporate_3.54" />
        <vers num="corporate_5.02" />
        <vers num="corporate_5.5" />
        <vers num="corporate_5.58" />
        <vers num="corporate_6.5" />
      </prod>
      <prod vendor="trend_micro" name="pc-cillin">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="6.0" />
      </prod>
      <prod vendor="trend_micro" name="portalprotect">
        <vers num="1.0" />
      </prod>
      <prod vendor="trend_micro" name="scanmail">
        <vers num="2.51" edition="" />
        <vers num="2.51" edition=":domino" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":domino" />
        <vers num="3.8" edition="" />
        <vers num="3.8" edition=":microsoft_exchange" />
        <vers num="3.81" edition="" />
        <vers num="3.81" edition=":microsoft_exchange" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":microsoft_exchange" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":lotus_domino_on_aix" />
        <vers num="gold" edition=":lotus_domino_on_s_390" />
        <vers num="gold" edition=":lotus_domino_on_solaris" />
        <vers num="gold" edition=":lotus_domino_on_as_400" />
        <vers num="gold" edition=":lotus_domino_on_windows" />
      </prod>
      <prod vendor="trend_micro" name="scanmail_emanager">
        <vers num="" />
      </prod>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="1.25_2007-02-16" edition="" />
        <vers num="1.25_2007-02-16" edition=":linux" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":linux" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":linux" />
        <vers num="5.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0534" published="2005-05-02" name="CVE-2005-0534" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=307067" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=307067</ref>
      <ref url="http://securitytracker.com/id?1013260" source="SECTRACK" patch="1" adv="1">1013260</ref>
      <ref url="http://secunia.com/advisories/14360" source="SECUNIA" patch="1" adv="1">14360</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4_beta1" />
        <vers num="1.4_beta2" />
        <vers num="1.4_beta3" />
        <vers num="1.4_beta4" />
        <vers num="1.4_beta5" />
        <vers num="1.4_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0535" published="2005-02-22" name="CVE-2005-0535" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013260" source="SECTRACK" patch="1" adv="1">1013260</ref>
      <ref url="http://secunia.com/advisories/14360" source="SECUNIA" patch="1" adv="1">14360</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0536" published="2005-05-02" name="CVE-2005-0536" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to image deletion.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=307067" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=307067</ref>
      <ref url="http://securitytracker.com/id?1013260" source="SECTRACK" patch="1" adv="1">1013260</ref>
      <ref url="http://secunia.com/advisories/14360" source="SECUNIA" patch="1" adv="1">14360</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4_beta1" />
        <vers num="1.4_beta2" />
        <vers num="1.4_beta3" />
        <vers num="1.4_beta4" />
        <vers num="1.4_beta5" />
        <vers num="1.4_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0537" published="2005-02-21" name="CVE-2005-0537" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013268" source="SECTRACK" adv="1">1013268</ref>
      <ref url="http://secunia.com/advisories/14369" source="SECUNIA" adv="1">14369</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910607229970&amp;w=2" source="BUGTRAQ" adv="1">20050221 [NOBYTES.COM: #5] iGeneric eShop 1.2 - Information Disclosure &amp; Possible SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="free_shopping_cart">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0538" published="2005-05-02" name="CVE-2005-0538" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in (1) GinpPictureServlet.java and (2) PicCollection.java in ginp (Java Photo Gallery Web Application) before 0.22 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=307518" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=307518</ref>
      <ref url="http://secunia.com/advisories/14373" source="SECUNIA" adv="1">14373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ginp" name="ginp">
        <vers num="0.20" />
        <vers num="0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0539" published="2005-05-02" name="CVE-2005-0539" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://techsupport.services.ibm.com/server/hmc/power5/fixes/ptf_MH00220.html" source="CONFIRM" patch="1">http://techsupport.services.ibm.com/server/hmc/power5/fixes/ptf_MH00220.html</ref>
      <ref url="http://secunia.com/advisories/14377" source="SECUNIA" patch="1" adv="1">14377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="hardware_management_console">
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0540" published="2005-05-02" name="CVE-2005-0540" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to obtain sensitive information via a direct request to the /about.html page.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/14073" source="OSVDB">14073</ref>
      <ref url="http://www.cirt.net/advisories/alterpath_disclosure.shtml" source="MISC" adv="1">http://www.cirt.net/advisories/alterpath_disclosure.shtml</ref>
      <ref url="http://secunia.com/advisories/14378" source="SECUNIA" adv="1">14378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2" source="FULLDISC" adv="1">20050224 Cyclades AlterPath Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyclades" name="alterpath_manager">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0541" published="2005-05-02" name="CVE-2005-0541" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">consoleConnect.jsp in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to connect to arbitrary consoles by modifying the consolename parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/14075" source="OSVDB">14075</ref>
      <ref url="http://www.cirt.net/advisories/alterpath_console.shtml" source="MISC" adv="1">http://www.cirt.net/advisories/alterpath_console.shtml</ref>
      <ref url="http://secunia.com/advisories/14378" source="SECUNIA" adv="1">14378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2" source="FULLDISC" adv="1">20050224 Cyclades AlterPath Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyclades" name="alterpath_manager">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0542" published="2005-05-02" name="CVE-2005-0542" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">saveUser.do in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows local users to gain privileges by setting the adminUser parameter to true.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/14074" source="OSVDB">14074</ref>
      <ref url="http://www.cirt.net/advisories/alterpath_privesc.shtml" source="MISC" adv="1">http://www.cirt.net/advisories/alterpath_privesc.shtml</ref>
      <ref url="http://secunia.com/advisories/14378" source="SECUNIA" adv="1">14378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2" source="FULLDISC" adv="1">20050224 Cyclades AlterPath Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyclades" name="alterpath_manager">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0543" published="2005-02-24" name="CVE-2005-0543" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19462" source="XF" patch="1" adv="1">phpmyadmin-multiple-php-xss(19462)</ref>
      <ref url="http://www.securityfocus.com/bid/12644" source="BID" patch="1" adv="1">12644</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-07</ref>
      <ref url="http://secunia.com/advisories/14382" source="SECUNIA" patch="1" adv="1">14382</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110929725801154&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050224 [SECURITYREASON.COM] phpMyAdmin 2.6.1 Remote file inclusion and XSS cXIb8O3.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.6.0_pl2" />
        <vers num="2.6.0_pl3" />
        <vers num="2.6.1" />
        <vers num="2.6.1_rc1" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0544" published="2005-05-02" name="CVE-2005-0544" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-07</ref>
      <ref url="http://secunia.com/advisories/14382" source="SECUNIA" patch="1" adv="1">14382</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149383&amp;group_id=23067&amp;atid=377408" source="CONFIRM" adv="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149383&amp;group_id=23067&amp;atid=377408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0545" published="2005-05-02" name="CVE-2005-0545" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive.  NOTE: this issue has been disputed in a followup post.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12641" source="BID">12641</ref>
      <ref url="http://www.securityfocus.com/archive/1/391332" source="BUGTRAQ" adv="1">20050223 Office 10 applications &amp; flashdrives can be used to browse restricted drives</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935549821930&amp;w=2" source="BUGTRAQ" adv="1">20050225 Re: Office 10 applications &amp; flashdrives can be used to browse restricted</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0546" published="2005-05-02" name="CVE-2005-0546" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotate extension, (2) an off-by-one error in "cached header handling," (3) a stack-based buffer overflow in fetchnews, or (4) a stack-based buffer overflow in imapd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-29.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-29</ref>
      <ref url="http://secunia.com/advisories/14383" source="SECUNIA" patch="1" adv="1">14383</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972236203397&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050228 [USN-87-1] Cyrus IMAP server vulnerability</ref>
      <ref url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.info-cyrus&amp;msg=33723" source="MLIST" patch="1">[info-cyrus] 20050214 Cyrus IMAPd 2.2.11 Released</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10674" source="OVAL">oval:org.mitre.oval:def:10674</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000937" source="CONECTIVA" adv="1">CLA-2005:937</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=82404" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=82404</ref>
      <ref url="http://www.securityfocus.com/bid/12636" source="BID">12636</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430294/100/0/threaded" source="FEDORA">FLSA:156290</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-408.html" source="REDHAT">RHSA-2005:408</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:051" source="MANDRAKE">MDKSA-2005:051</ref>
      <ref url="http://securitytracker.com/id?1013278" source="SECTRACK">1013278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyrus" name="imapd">
        <vers num="2.0.17" />
        <vers num="2.1.16" />
        <vers num="2.1.17" />
        <vers num="2.1.18" />
        <vers num="2.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0547" published="2005-02-24" name="CVE-2005-0547" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12651" source="BID" patch="1" adv="1">12651</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19467" source="XF">hp-ux-ftpd-gain-access(19467)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5464" source="OVAL">oval:org.mitre.oval:def:5464</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927245211549&amp;w=2" source="HP">HPSBUX01119</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927245211549&amp;w=2" source="HP" adv="1">HPSBUX01119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
        <vers num="11.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0548" published="2005-03-07" name="CVE-2005-0548" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000230.1-1" source="SUNALERT">1000230</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57737-1" source="SUNALERT" adv="1">57737</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205163531628&amp;w=2" source="BUGTRAQ" adv="1">20050328 Multiple XSS issues in Sun AnswerBook2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris_answerbook2">
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0549" published="2005-05-02" name="CVE-2005-0549" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57737-1" source="SUNALERT" patch="1" adv="1">57737</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000230.1-1" source="SUNALERT">1000230</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205163531628&amp;w=2" source="BUGTRAQ" adv="1">20050328 Multiple XSS issues in Sun AnswerBook2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris_answerbook2">
        <vers prev="1" num="1.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0550" published="2005-05-02" name="CVE-2005-0550" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx" source="MS" patch="1" adv="1">MS05-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4832" source="OVAL" sig="1">oval:org.mitre.oval:def:4832</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4397" source="OVAL" sig="1">oval:org.mitre.oval:def:4397</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2043" source="OVAL" sig="1">oval:org.mitre.oval:def:2043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1271" source="OVAL" sig="1">oval:org.mitre.oval:def:1271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0551" published="2005-05-02" name="CVE-2005-0551" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx" source="MS" patch="1" adv="1">MS05-018</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=230&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050412 Microsoft Windows CSRSS.EXE Stack Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:777" source="OVAL" sig="1">oval:org.mitre.oval:def:777</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3544" source="OVAL" sig="1">oval:org.mitre.oval:def:3544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:266" source="OVAL" sig="1">oval:org.mitre.oval:def:266</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1822" source="OVAL" sig="1">oval:org.mitre.oval:def:1822</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0553" published="2005-05-02" name="CVE-2005-0553" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html" source="CERT" patch="1" adv="1">TA05-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/774338" source="CERT-VN" patch="1" adv="1">VU#774338</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19831" source="XF" patch="1">ie-dhtml-bo(19831)</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-020.mspx" source="MS" patch="1" adv="1">MS05-020</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=228&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050412 Microsoft Internet Explorer DHTML Engine Race Condition Vulnerability</ref>
      <ref url="http://secunia.com/advisories/14922/" source="SECUNIA" patch="1" adv="1">14922</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4985" source="OVAL" sig="1">oval:org.mitre.oval:def:4985</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4874" source="OVAL" sig="1">oval:org.mitre.oval:def:4874</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3752" source="OVAL" sig="1">oval:org.mitre.oval:def:3752</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3100" source="OVAL" sig="1">oval:org.mitre.oval:def:3100</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1695" source="OVAL" sig="1">oval:org.mitre.oval:def:1695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp3" />
        <vers num="5.01" edition="sp4" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0554" published="2005-05-02" name="CVE-2005-0554" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html" source="CERT" patch="1" adv="1">TA05-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/756122" source="CERT-VN" patch="1" adv="1">VU#756122</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-020.mspx" source="MS" patch="1" adv="1">MS05-020</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=229&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050412 Microsoft Windows Internet Explorer Long Hostname Heap Corruption Vulnerability</ref>
      <ref url="http://secunia.com/advisories/14922/" source="SECUNIA" patch="1" adv="1">14922</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:789" source="OVAL" sig="1">oval:org.mitre.oval:def:789</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3817" source="OVAL" sig="1">oval:org.mitre.oval:def:3817</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2559" source="OVAL" sig="1">oval:org.mitre.oval:def:2559</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2253" source="OVAL" sig="1">oval:org.mitre.oval:def:2253</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1196" source="OVAL" sig="1">oval:org.mitre.oval:def:1196</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0555" published="2005-04-12" name="CVE-2005-0555" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html" source="CERT">TA05-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/222050" source="CERT-VN">VU#222050</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-020.mspx" source="MS" patch="1" adv="1">MS05-020</ref>
      <ref url="http://secunia.com/advisories/14922/" source="SECUNIA" patch="1" adv="1">14922</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19842" source="XF">ie-content-advisor-bo(19842)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4674" source="OVAL" sig="1">oval:org.mitre.oval:def:4674</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3926" source="OVAL" sig="1">oval:org.mitre.oval:def:3926</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3157" source="OVAL" sig="1">oval:org.mitre.oval:def:3157</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2786" source="OVAL" sig="1">oval:org.mitre.oval:def:2786</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2077" source="OVAL" sig="1">oval:org.mitre.oval:def:2077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0558" published="2005-05-02" name="CVE-2005-0558" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19828" source="XF" patch="1">word-document-bo(19828)</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-023.mspx" source="MS" patch="1" adv="1">MS05-023</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4234" source="OVAL" sig="1">oval:org.mitre.oval:def:4234</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2685" source="OVAL" sig="1">oval:org.mitre.oval:def:2685</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2415" source="OVAL" sig="1">oval:org.mitre.oval:def:2415</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1236" source="OVAL" sig="1">oval:org.mitre.oval:def:1236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0560" published="2005-05-02" name="CVE-2005-0560" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html" source="CERT" patch="1" adv="1">TA05-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/275193" source="CERT-VN" patch="1" adv="1">VU#275193</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-021.mspx" source="MS" patch="1" adv="1">MS05-021</ref>
      <ref url="http://secunia.com/advisories/14920/" source="SECUNIA" patch="1" adv="1">14920</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/193" source="ISS">20050412 Microsoft Exchange Remote Compromise</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=15467" source="OSVDB">15467</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111393947713420&amp;w=2" source="BUGTRAQ" adv="1">20050419 MS05-021 Microsoft Exchange X-LINK2STATE Heap Overflow PoC</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4032" source="OVAL" sig="1">oval:org.mitre.oval:def:4032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0562" published="2005-04-12" name="CVE-2005-0562" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html" source="CERT" patch="1" adv="1">TA05-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/633446" source="CERT-VN" patch="1" adv="1">VU#633446</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19950" source="XF" patch="1" adv="1">msn-messenger-gif-execute-code (19950)</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-022.mspx" source="MS" patch="1" adv="1">MS05-022</ref>
      <ref url="http://secunia.com/advisories/14915/" source="SECUNIA" patch="1" adv="1">14915</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4927" source="OVAL" sig="1">oval:org.mitre.oval:def:4927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="msn_messenger">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0563" published="2005-06-14" name="CVE-2005-0563" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("jav&amp;#X41sc&amp;#0010;ript:") in an IMG tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-029.mspx" source="MS" patch="1" adv="1">MS05-029</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=261&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050614 Microsoft Outlook Web Access Cross-Site Scripting Vulnerability</ref>
      <ref url="http://secunia.com/advisories/15697" source="SECUNIA">15697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0564" published="2005-07-12" name="CVE-2005-0564" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-193A.html" source="CERT">TA05-193A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/218621" source="CERT-VN">VU#218621</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-035.mspx" source="MS" patch="1" adv="1">MS05-035</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=281&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050712 Microsoft Word 2000 and Word 2002 Font Parsing Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1331" source="OVAL" sig="1">oval:org.mitre.oval:def:1331</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1190" source="OVAL" sig="1">oval:org.mitre.oval:def:1190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
        <vers num="2002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0565" published="2005-05-02" name="CVE-2005-0565" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to reference a PHP file whose name contains a .gif.php extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19482" source="XF" patch="1">phpwebsite-announce-execute-code(19482)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-04</ref>
      <ref url="http://secunia.com/advisories/14399" source="SECUNIA" patch="1" adv="1">14399</ref>
      <ref url="http://securitytracker.com/id?1013298" source="SECTRACK" adv="1">1013298</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110928565530828&amp;w=2" source="BUGTRAQ">20050224 phpWebSite-0.10.0_exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers num="0.10.0" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.3.1" />
        <vers num="0.9.3.2" />
        <vers num="0.9.3.3" />
        <vers num="0.9.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0566" published="2005-01-22" name="CVE-2005-0566" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/620862" source="CERT-VN" patch="1" adv="1">VU#620862</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19015" source="XF" patch="1" adv="1">golden-ftp-rnto-bo(19015)</ref>
      <ref url="http://www.securityfocus.com/bid/12333" source="BID" patch="1" adv="1">12333</ref>
      <ref url="http://www.goldenftpserver.com" source="MISC" patch="1" adv="1">http://www.goldenftpserver.com</ref>
      <ref url="http://secunia.com/advisories/13966/" source="SECUNIA" patch="1" adv="1">13966</ref>
      <ref url="http://securitytracker.com/id?1012973" source="SECTRACK">1012973</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031098.html" source="FULLDISC" adv="1">20050122 several BO's in goldenftpd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kmint21_software" name="golden_ftp_server">
        <vers num="1.00b" />
        <vers num="1.20b" />
        <vers num="1.30b" />
        <vers num="1.31b" />
        <vers num="2.02b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0567" published="2005-05-02" name="CVE-2005-0567" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19465" source="XF" patch="1">phpmyadmin-file-include(19465)</ref>
      <ref url="http://www.securityfocus.com/bid/12645" source="BID" patch="1">12645</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149381&amp;group_id=23067&amp;atid=377408" source="CONFIRM" patch="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149381&amp;group_id=23067&amp;atid=377408</ref>
      <ref url="http://secunia.com/advisories/14382/" source="SECUNIA" patch="1" adv="1">14382</ref>
      <ref url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-1" source="CONFIRM" adv="1">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110929725801154&amp;w=2" source="BUGTRAQ" adv="1">20050224 [SECURITYREASON.COM] phpMyAdmin 2.6.1 Remote file inclusion and XSS cXIb8O3.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0568" published="2005-05-02" name="CVE-2005-0568" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which results in an invalid pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12650" source="BID">12650</ref>
      <ref url="http://securitytracker.com/id?1013291" source="SECTRACK" adv="1">1013291</ref>
      <ref url="http://secunia.com/advisories/13289" source="SECUNIA" adv="1">13289</ref>
      <ref url="http://aluigi.altervista.org/adv/sof2guidboom-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/sof2guidboom-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927288423807&amp;w=2" source="BUGTRAQ">20050224 In-game cl_guid crash in Soldier of Fortune II 1.03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raven_software" name="soldier_of_fortune_2">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0569" published="2005-05-02" name="CVE-2005-0569" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19473" source="XF" patch="1">punbb-multiple-sql-injection(19473)</ref>
      <ref url="http://www.securityfocus.com/bid/12652" source="BID" patch="1">12652</ref>
      <ref url="http://secunia.com/advisories/14538" source="SECUNIA" patch="1" adv="1">14538</ref>
      <ref url="http://secunia.com/advisories/14394" source="SECUNIA" patch="1" adv="1">14394</ref>
      <ref url="http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt" source="CONFIRM">http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927754230666&amp;w=2" source="BUGTRAQ" adv="1">20050224 Multiple vulns in punBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0570" published="2005-05-02" name="CVE-2005-0570" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user's password to NULL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19483" source="XF" patch="1">punbb-profile-dos(19483)</ref>
      <ref url="http://www.securityfocus.com/bid/12652" source="BID" patch="1">12652</ref>
      <ref url="http://secunia.com/advisories/14394" source="SECUNIA" patch="1" adv="1">14394</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927754230666&amp;w=2" source="BUGTRAQ" adv="1">20050224 Multiple vulns in punBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0571" published="2005-05-02" name="CVE-2005-0571" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19478" source="XF" patch="1">punbb-file-disclosure(19478)</ref>
      <ref url="http://www.punbb.org/download/patch/punbb-1.2.1_to_1.2.2.patch" source="CONFIRM" patch="1">http://www.punbb.org/download/patch/punbb-1.2.1_to_1.2.2.patch</ref>
      <ref url="http://secunia.com/advisories/14394" source="SECUNIA" patch="1" adv="1">14394</ref>
      <ref url="http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt" source="CONFIRM">http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927754230666&amp;w=2" source="BUGTRAQ" adv="1">20050224 Multiple vulns in punBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0572" published="2005-05-02" name="CVE-2005-0572" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module parameter, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-04</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19480" source="XF">phpwebsite-search-path-disclosure(19480)</ref>
      <ref url="http://neossecurity.net/Advisories/Advisory-05.txt" source="MISC" adv="1">http://neossecurity.net/Advisories/Advisory-05.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935172116369&amp;w=2" source="BUGTRAQ" adv="1">20050225 phpWebSite 0.10.0 Full Path disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers num="0.10.0" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.3.1" />
        <vers num="0.9.3.2" />
        <vers num="0.9.3.3" />
        <vers num="0.9.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0573" published="2005-05-02" name="CVE-2005-0573" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gaim 1.1.3 on Windows systems allows remote attackers to cause a denial of service (client crash) via a file transfer in which the filename contains "(" or ")" (parenthesis) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013300" source="SECTRACK" adv="1">1013300</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110928380421841&amp;w=2" source="FULLDISC" adv="1">20050224 GAIM exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0574" published="2005-05-02" name="CVE-2005-0574" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in CIS WebServer 3.5.13 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12662" source="BID">12662</ref>
      <ref url="http://www.securityfocus.com/archive/1/391560" source="BUGTRAQ" adv="1">20050225 CIS WebServer Directory Traversal Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cupidsystems" name="cis_webserver">
        <vers num="3.5.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0575" published="2005-05-02" name="CVE-2005-0575" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12671" source="BID">12671</ref>
      <ref url="http://secunia.com/advisories/14400" source="SECUNIA" adv="1">14400</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110943766505666&amp;w=2" source="BUGTRAQ" adv="1">20050225 Knet &lt;= 1.04c Buffer Overflow Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stormy_studios" name="knet">
        <vers num="1.0" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4b" />
        <vers num="1.4c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0576" published="2005-05-02" name="CVE-2005-0576" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12656" source="BID" patch="1">12656</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57738-1" source="SUNALERT" patch="1" adv="1">57738</ref>
      <ref url="http://secunia.com/advisories/14381" source="SECUNIA" patch="1" adv="1">14381</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0577" published="2005-05-02" name="CVE-2005-0577" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Format string vulnerability in DNA MKBold-MKItalic 0.06_1 and earlier allows remote attackers to execute arbitrary code via crafted BDF font files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.freshports.org/x11-fonts/mkbold-mkitalic/" source="CONFIRM" patch="1">http://www.freshports.org/x11-fonts/mkbold-mkitalic/</ref>
      <ref url="http://secunia.com/advisories/14398" source="SECUNIA" patch="1" adv="1">14398</ref>
      <ref url="http://www.vuxml.org/freebsd/32d4f0f1-85c3-11d9-b6dc-0007e900f747.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/32d4f0f1-85c3-11d9-b6dc-0007e900f747.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dna" name="mkbold-mkitalic">
        <vers prev="1" num="0.06_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0578" published="2005-05-02" name="CVE-2005-0578" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Firefox before 1.0.1 and Mozilla Suite before 1.7.6 use a predictable filename for the plugin temporary directory, which allows local users to delete arbitrary files of other users via a symlink attack on the plugtmp directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-28.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-28.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10954" source="OVAL">oval:org.mitre.oval:def:10954</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0579" published="2005-02-25" name="CVE-2005-0579" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linuxcompatible.org/story42495.html" source="SUSE" adv="1">SUSE-SR:2005:006</ref>
      <ref url="http://mail.kde.org/pipermail/freenx-knx/2005-February/000734.html" source="MLIST" adv="1">[FreeNX-kNX] 20050217 Security: Serious bug in authority handling found and fixed</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freenx" name="freenx">
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0580" published="2005-02-25" name="CVE-2005-0580" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-30.xml" source="GENTOO" adv="1">GLSA-200502-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="krzysztof_dabrowski" name="cmd5checkpw">
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0581" published="2005-05-02" name="CVE-2005-0581" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=215&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050302 Computer Associates License Client/Server GCR Checksum Buffer Overflow</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=214&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050302 Computer Associates License Client/Server GCR Network Buffer Overflow</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=213&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050302 Computer Associates License Client/Server GETCONFIG Buffer Overflow</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=210&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050302 Computer Associates License Client and Server Invalid Command Buffer Overflow</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp" source="CONFIRM" patch="1" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979326828704&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050302 License Patches Are Now Available To Address Buffer Overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="license_software">
        <vers num="0.1.0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0582" published="2005-05-02" name="CVE-2005-0582" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=211&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050302 Computer Associates License Client PUTOLF Buffer Overflow</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp" source="CONFIRM" patch="1" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979326828704&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050302 License Patches Are Now Available To Address Buffer Overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="license_software">
        <vers num="0.1.0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0583" published="2005-05-02" name="CVE-2005-0583" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to create arbitrary files via .. (dot dot) sequences in a PUTOLF request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=212&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050302 Computer Associates License Client PUTOLF Directory Traversal</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp" source="CONFIRM" patch="1" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979326828704&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050302 License Patches Are Now Available To Address Buffer Overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="license_software">
        <vers num="0.1.0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0584" published="2005-05-02" name="CVE-2005-0584" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=277574" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=277574</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-24.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-24.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" adv="1">GLSA-200503-30</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11191" source="OVAL">oval:org.mitre.oval:def:11191</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100034" source="OVAL" sig="1">oval:org.mitre.oval:def:100034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0585" published="2005-03-25" name="CVE-2005-0585" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-23.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-23.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://secunia.com/secunia_research/2004-15/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2004-15/advisory/</ref>
      <ref url="http://secunia.com/advisories/13599" source="SECUNIA" patch="1" adv="1">13599</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9924" source="OVAL">oval:org.mitre.oval:def:9924</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100035" source="OVAL" sig="1">oval:org.mitre.oval:def:100035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0586" published="2005-05-02" name="CVE-2005-0586" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://secunia.com/advisories/13258" source="SECUNIA" patch="1" adv="1">13258</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-22.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-22.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11152" source="OVAL">oval:org.mitre.oval:def:11152</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100036" source="OVAL" sig="1">oval:org.mitre.oval:def:100036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0587" published="2005-03-25" name="CVE-2005-0587" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-21.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-21.html</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100037" source="OVAL" sig="1">oval:org.mitre.oval:def:100037</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0588" published="2005-05-02" name="CVE-2005-0588" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=271209" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=271209</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-20.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-20.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10682" source="OVAL">oval:org.mitre.oval:def:10682</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100038" source="OVAL" sig="1">oval:org.mitre.oval:def:100038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0589" published="2005-05-02" name="CVE-2005-0589" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=270697" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=270697</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-19.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-19.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10825" source="OVAL">oval:org.mitre.oval:def:10825</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100039" source="OVAL" sig="1">oval:org.mitre.oval:def:100039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0590" published="2005-05-02" name="CVE-2005-0590" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=268059" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=268059</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-17.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-17.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10010" source="OVAL">oval:org.mitre.oval:def:10010</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100041" source="OVAL" sig="1">oval:org.mitre.oval:def:100041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0591" published="2005-05-02" name="CVE-2005-0591" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=260560" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=260560</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-16.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-16.html</ref>
      <ref url="http://www.mikx.de/index.php?p=7" source="MISC" adv="1">http://www.mikx.de/index.php?p=7</ref>
      <ref url="http://www.mikx.de/firespoofing/" source="MISC">http://www.mikx.de/firespoofing/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10039" source="OVAL">oval:org.mitre.oval:def:10039</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547286002188&amp;w=2" source="BUGTRAQ" adv="1">20050111 Firespoofing [Firefox 1.0]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18864" source="XF">web-browser-modal-spoofing(18864)</ref>
      <ref url="http://www.securityfocus.com/bid/12234" source="BID">12234</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://secunia.com/advisories/13786" source="SECUNIA">13786</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100042" source="OVAL" sig="1">oval:org.mitre.oval:def:100042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0592" published="2005-03-25" name="CVE-2005-0592" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=241440" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=241440</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-15.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-15.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" adv="1">GLSA-200503-10</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10606" source="OVAL">oval:org.mitre.oval:def:10606</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100043" source="OVAL" sig="1">oval:org.mitre.oval:def:100043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0593" published="2005-03-04" name="CVE-2005-0593" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=277564" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=277564</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=276720" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=276720</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=268483" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=268483</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=258048" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=258048</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-14.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-14.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" adv="1">GLSA-200503-30</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9533" source="OVAL">oval:org.mitre.oval:def:9533</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100044" source="OVAL" sig="1">oval:org.mitre.oval:def:100044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0594" published="2005-05-04" name="CVE-2005-0594" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/354486" source="CERT-VN">VU#354486</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE">APPLE-SA-2005-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0595" published="2005-05-02" name="CVE-2005-0595" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers execute arbitrary code via a long mfcisapicommand parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12673" source="BID" patch="1">12673</ref>
      <ref url="http://secunia.com/advisories/14405" source="SECUNIA" patch="1" adv="1">14405</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0599.html" source="FULLDISC" patch="1">20050226 Badblue HTTP Server, ext.dll buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="working_resources_inc." name="badblue">
        <vers num="2.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0596" published="2005-05-02" name="CVE-2005-0596" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PHP 4 (PHP4) allows attackers to cause a denial of service (daemon crash) by using the readfile function on a file whose size is a multiple of the page size.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12665" source="BID">12665</ref>
      <ref url="http://www.linuxcompatible.org/story42495.html" source="SUSE" adv="1">SUSE-SR:2005:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0597" published="2005-05-02" name="CVE-2005-0597" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 5.0 before 5.0.17.6 and 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (process restart) via a "crafted TCP connection."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14395" source="SECUNIA" patch="1">14395</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19466" source="XF">cisco-tcp-acns-dos(19466)</ref>
      <ref url="http://www.securityfocus.com/bid/12648" source="BID">12648</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml" source="CISCO" adv="1">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0598" published="2005-02-24" name="CVE-2005-0598" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/579240" source="CERT-VN">VU#579240</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19469" source="XF" patch="1" adv="1">cisco-realserver-realsubscriber-dos(19469)</ref>
      <ref url="http://www.securityfocus.com/bid/12648" source="BID" patch="1" adv="1">12648</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml" source="CISCO" patch="1" adv="1">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/14395" source="SECUNIA" patch="1" adv="1">14395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num="(acns)" />
        <vers num="4.0.3" />
        <vers num="4.1.1" />
        <vers num="4.1.3" />
        <vers num="4.2" />
        <vers num="4.2.11" />
        <vers num="4.2.9" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.3" />
        <vers num="5.0.5" />
        <vers num="5.1" />
      </prod>
      <prod vendor="cisco" name="content_delivery_manager">
        <vers num="4630" />
        <vers num="4650" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4630">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4650">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4670">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_engine">
        <vers num="507" />
        <vers num="507_2.2_.0" />
        <vers num="507_3.1" />
        <vers num="507_4.0" />
        <vers num="507_4.1" />
        <vers num="510" />
        <vers num="560" />
        <vers num="560_2.2_.0" />
        <vers num="560_3.1" />
        <vers num="560_4.0" />
        <vers num="560_4.1" />
        <vers num="565" />
        <vers num="590" />
        <vers num="590_2.2_.0" />
        <vers num="590_3.1" />
        <vers num="590_4.0" />
        <vers num="590_4.1" />
        <vers num="7320" />
        <vers num="7320_2.2_.0" />
        <vers num="7320_3.1" />
        <vers num="7320_4.0" />
        <vers num="7320_4.1" />
        <vers num="7325" />
      </prod>
      <prod vendor="cisco" name="content_engine_module_for_cisco_router">
        <vers num="2600_series" />
        <vers num="2800_series" />
        <vers num="3600_series" />
        <vers num="3700_series" />
        <vers num="3800_series" />
      </prod>
      <prod vendor="cisco" name="content_router_4430">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_router_4450">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_router_4430">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0599" published="2005-05-02" name="CVE-2005-0599" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, or 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (CPU consumption) via malformed IP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14395" source="SECUNIA" patch="1">14395</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19468" source="XF">cisco-ip-packet-dos(19468)</ref>
      <ref url="http://www.securityfocus.com/bid/12648" source="BID">12648</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml" source="CISCO" adv="1">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num="4.0.3" />
        <vers num="4.1.1" />
        <vers num="4.1.3" />
        <vers num="4.2" />
        <vers num="4.2.11" />
        <vers num="4.2.9" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.3" />
        <vers num="5.0.5" />
        <vers prev="1" num="5.1.11.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0600" published="2005-02-24" name="CVE-2005-0600" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19470" source="XF" patch="1" adv="1">cisco-acns-dos(19470)</ref>
      <ref url="http://www.securityfocus.com/bid/12648" source="BID" patch="1" adv="1">12648</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml" source="CISCO" patch="1" adv="1">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/14395" source="SECUNIA" patch="1" adv="1">14395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num="(acns)" />
        <vers num="4.0.3" />
        <vers num="4.1.1" />
        <vers num="4.1.3" />
        <vers num="4.2" />
        <vers num="4.2.11" />
        <vers num="4.2.9" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.3" />
        <vers num="5.0.5" />
        <vers num="5.1" />
      </prod>
      <prod vendor="cisco" name="content_delivery_manager">
        <vers num="4630" />
        <vers num="4650" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4630">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4650">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4670">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_engine">
        <vers num="507" />
        <vers num="507_2.2_.0" />
        <vers num="507_3.1" />
        <vers num="507_4.0" />
        <vers num="507_4.1" />
        <vers num="510" />
        <vers num="560" />
        <vers num="560_2.2_.0" />
        <vers num="560_3.1" />
        <vers num="560_4.0" />
        <vers num="560_4.1" />
        <vers num="565" />
        <vers num="590" />
        <vers num="590_2.2_.0" />
        <vers num="590_3.1" />
        <vers num="590_4.0" />
        <vers num="590_4.1" />
        <vers num="7320" />
        <vers num="7320_2.2_.0" />
        <vers num="7320_3.1" />
        <vers num="7320_4.0" />
        <vers num="7320_4.1" />
        <vers num="7325" />
      </prod>
      <prod vendor="cisco" name="content_engine_module_for_cisco_router">
        <vers num="2600_series" />
        <vers num="2800_series" />
        <vers num="3600_series" />
        <vers num="3700_series" />
        <vers num="3800_series" />
      </prod>
      <prod vendor="cisco" name="content_router_4430">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_router_4450">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_router_4430">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0601" published="2005-05-02" name="CVE-2005-0601" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14395" source="SECUNIA" patch="1">14395</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19471" source="XF">cisco-acns-gain-access(19471)</ref>
      <ref url="http://www.securityfocus.com/bid/12648" source="BID">12648</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml" source="CISCO" adv="1">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num="4.0.3" />
        <vers num="4.1.1" />
        <vers num="4.1.3" />
        <vers num="4.2" />
        <vers num="4.2.11" />
        <vers num="4.2.9" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.3" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0602" published="2005-05-02" name="CVE-2005-0602" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/3866" source="VUPEN">ADV-2007-3866</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110960796331943&amp;w=2" source="BUGTRAQ">20050228 7a69Adv#22 - UNIX unzip keep setuid and setgid files</ref>
      <ref url="http://www.trustix.org/errata/2005/0053/" source="TRUSTIX">2005-0053</ref>
      <ref url="http://www.securityfocus.com/bid/14447" source="BID">14447</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:197" source="MANDRIVA">MDKSA-2005:197</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200844-1" source="SUNALERT">200844</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103150-1" source="SUNALERT">103150</ref>
      <ref url="http://secunia.com/advisories/27684" source="SECUNIA">27684</ref>
      <ref url="http://secunia.com/advisories/17342" source="SECUNIA">17342</ref>
      <ref url="http://secunia.com/advisories/17045" source="SECUNIA">17045</ref>
    </refs>
    <vuln_soft>
      <prod vendor="info-zip" name="unzip">
        <vers num="5.50" />
        <vers prev="1" num="5.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0603" published="2005-02-28" name="CVE-2005-0603" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?t=267563" source="CONFIRM" patch="1" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?t=267563</ref>
      <ref url="http://secunia.com/advisories/14413" source="SECUNIA" patch="1" adv="1">14413</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110943646112950&amp;w=2" source="BUGTRAQ" adv="1">20050225 -==phpBB 2.0.12 Full path disclosure==-</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0604" published="2005-05-02" name="CVE-2005-0604" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.hat-squad.com/en/000160.html" source="MISC" adv="1">http://www.hat-squad.com/en/000160.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110961644621528&amp;w=2" source="BUGTRAQ">20050228 [Hat-Squad] GFI L.N.S.S 5.0 Insecure Credential Storage</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gfi" name="languard_network_security_scanner">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0605" published="2005-03-02" name="CVE-2005-0605" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12714" source="BID" patch="1" adv="1">12714</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-331.html" source="REDHAT" patch="1" adv="1">RHSA-2005:331</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-15</ref>
      <ref url="http://www.debian.org/security/2005/dsa-723" source="DEBIAN" patch="1" adv="1">DSA-723</ref>
      <ref url="http://securitytracker.com/id?1013339" source="SECTRACK" patch="1" adv="1">1013339</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-08</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=83655" source="CONFIRM" patch="1" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=83655</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=83598" source="CONFIRM" patch="1" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=83598</ref>
      <ref url="https://bugs.freedesktop.org/attachment.cgi?id=1909" source="CONFIRM" adv="1">https://bugs.freedesktop.org/attachment.cgi?id=1909</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-412.html" source="REDHAT">RHSA-2005:412</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10411" source="OVAL">oval:org.mitre.oval:def:10411</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-97-1" source="UBUNTU">USN-97-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-92-1" source="UBUNTU">USN-92-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-473.html" source="REDHAT">RHSA-2005:473</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-198.html" source="REDHAT">RHSA-2005:198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-044.html" source="REDHAT">RHSA-2005:044</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html" source="FEDORA">FLSA-2006:152803</ref>
      <ref url="http://secunia.com/advisories/19624" source="SECUNIA">19624</ref>
      <ref url="http://secunia.com/advisories/18316" source="SECUNIA">18316</ref>
      <ref url="http://secunia.com/advisories/18049" source="SECUNIA">18049</ref>
      <ref url="http://secunia.com/advisories/14460" source="SECUNIA">14460</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U" source="SGI">20060403-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.57/SCOSA-2005.57.txt" source="SCO">SCOSA-2005.57</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.5/SCOSA-2006.5.txt" source="SCO">SCOSA-2006.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lesstif" name="lesstif">
        <vers num="0.93.94" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="x.org" name="x11r6">
        <vers num="6.7.0" />
        <vers num="6.8" />
        <vers num="6.8.1" />
      </prod>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2.11" />
        <vers num="4.0.3" />
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
        <vers num="4.3.0.1" />
        <vers num="4.3.0.2" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":junior" />
        <vers num="2.3" edition=":compact" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="10.2" edition="" />
        <vers num="10.2" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":i386" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":sparc" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.0" edition=":ppc" />
        <vers num="7.0" edition="alpha" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":spa" />
        <vers num="7.1" edition=":sparc" />
        <vers num="7.1" edition=":x86" />
        <vers num="7.1" edition="alpha" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":i386" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":ppc" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":sparc" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0606" published="2005-05-02" name="CVE-2005-0606" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12658" source="BID" patch="1">12658</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=6032" source="CONFIRM" patch="1">http://www.cubecart.com/site/forums/index.php?showtopic=6032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20637" source="XF">cubecart-multiple-xss(20637)</ref>
      <ref url="http://securitytracker.com/id?1013304" source="SECTRACK">1013304</ref>
      <ref url="http://secunia.com/advisories/14416" source="SECUNIA">14416</ref>
      <ref url="http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html" source="MISC">http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0607" published="2005-05-02" name="CVE-2005-0607" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=6032" source="CONFIRM" patch="1">http://www.cubecart.com/site/forums/index.php?showtopic=6032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20638" source="XF">cubecart-multiple-path-disclosure(20638)</ref>
      <ref url="http://securitytracker.com/id?1013304" source="SECTRACK">1013304</ref>
      <ref url="http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0608" published="2005-02-28" name="CVE-2005-0608" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14302" source="SECUNIA" patch="1" adv="1">14302</ref>
      <ref url="http://djeyl.net/forum/index.php?showtopic=41440" source="CONFIRM" patch="1" adv="1">http://djeyl.net/forum/index.php?showtopic=41440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmod" name="webmod">
        <vers num="0.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0610" published="2005-04-12" name="CVE-2005-0610" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or (3) create arbitrary zero-byte files via the pkgdb.fixme temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/22f00553-a09d-11d9-a788-0001020eed82.html" source="MISC" patch="1" adv="1">http://www.vuxml.org/freebsd/22f00553-a09d-11d9-a788-0001020eed82.html</ref>
      <ref url="http://secunia.com/advisories/14903" source="SECUNIA" patch="1" adv="1">14903</ref>
      <ref url="http://www.securityfocus.com/bid/13106" source="BID" adv="1">13106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0611" published="2005-05-02" name="CVE-2005-0611" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-265.html" source="REDHAT">RHSA-2005:265</ref>
      <ref url="http://service.real.com/help/faq/security/050224_player/EN/" source="CONFIRM">http://service.real.com/help/faq/security/050224_player/EN/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11419" source="OVAL">oval:org.mitre.oval:def:11419</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vulnwatch&amp;m=110977858619314&amp;w=2" source="VULNWATCH">20050302 RealOne Player / Real .WAV Heap Overflow File Format Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979465912834&amp;w=2" source="BUGTRAQ">20050302 RealOne Player / Real .WAV Heap Overflow File Format Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-271.html" source="REDHAT">RHSA-2005:271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_player">
        <vers num="" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="" edition=":enterprise" />
        <vers num="10.0" />
        <vers num="10.5" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0612" published="2005-05-02" name="CVE-2005-0612" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/public/technotes/cisco-sa-20050202-ipvc.shtml" source="CISCO" patch="1">20050202 Default SNMP Community Strings in Cisco IP/VC Products</ref>
      <ref url="http://secunia.com/advisories/14122" source="SECUNIA" patch="1">14122</ref>
      <ref url="http://www.securityfocus.com/bid/12424" source="BID">12424</ref>
      <ref url="http://securitytracker.com/id?1013067" source="SECTRACK">1013067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ipvc-3510-mcu">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ipvc-3520-gw-2b">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ipvc-3520-gw-2b2v">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ipvc-3520-gw-2v">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ipvc-3520-gw-4v">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ipvc-3525-gw-1p">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ipvc-3530-vta">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0613" published="2005-02-28" name="CVE-2005-0613" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12676" source="BID" patch="1" adv="1">12676</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fckeditor" name="fckeditor">
        <vers num="2.0_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0614" published="2005-05-02" name="CVE-2005-0614" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?t=267563" source="CONFIRM" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?t=267563</ref>
      <ref url="http://secunia.com/advisories/14413" source="SECUNIA">14413</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110999268130739&amp;w=2" source="BUGTRAQ">20050304 phpBB 2.0.12 Session Handling Administrator Authentication Bypass</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970201920206&amp;w=2" source="BUGTRAQ">20050301 phpBB &lt;= 2.0.12 UID Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="1.0.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0615" published="2005-05-02" name="CVE-2005-0615" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote attackers to execute arbitrary SQL code via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013324" source="SECTRACK" patch="1">1013324</ref>
      <ref url="http://news.postnuke.com/Article2669.html" source="CONFIRM" patch="1" adv="1">http://news.postnuke.com/Article2669.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110962819232255&amp;w=2" source="BUGTRAQ">20050228 [SECURITYREASON.COM] PostNuke Critical SQL Injection 0.760-RC2=>x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.760_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0616" published="2005-02-28" name="CVE-2005-0616" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6) Version, or (7) Home page variables.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013324" source="SECTRACK" patch="1" adv="1">1013324</ref>
      <ref url="http://news.postnuke.com/Article2669.html" source="CONFIRM" patch="1" adv="1">http://news.postnuke.com/Article2669.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110962768300373&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050228 [SECURITYREASON.COM] PostNuke Critical XSS 0.760-RC2=>x cXIb8O3.2</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0617" published="2005-05-02" name="CVE-2005-0617" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in dl-search.php in PostNuke 0.750 and 0.760-RC2 allows remote attackers to execute arbitrary SQL commands via the show parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013324" source="SECTRACK" patch="1">1013324</ref>
      <ref url="http://news.postnuke.com/Article2669.html" source="CONFIRM" patch="1" adv="1">http://news.postnuke.com/Article2669.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110962710805864&amp;w=2" source="BUGTRAQ">20050228 [SECURITYREASON.COM] PostNuke SQL Injection 0.760-RC2=>x cXIb8O3.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
        <vers num="0.760_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0618" published="2005-05-02" name="CVE-2005-0618" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted network.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2005.02.28.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2005.02.28.html</ref>
      <ref url="http://secunia.com/advisories/14428" source="SECUNIA">14428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nexland" name="pro800turbo">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200r">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="gateway_security_360">
        <vers prev="1" num="857" />
      </prod>
      <prod vendor="symantec" name="gateway_security_460">
        <vers prev="1" num="857" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0619" published="2005-02-28" name="CVE-2005-0619" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/14212" source="OSVDB" adv="1">14212</ref>
      <ref url="http://securitytracker.com/id?1013316" source="SECTRACK" adv="1">1013316</ref>
      <ref url="http://secunia.com/advisories/14455" source="SECUNIA" adv="1">14455</ref>
      <ref url="http://milw0rm.com/exploits/846" source="MILW0RM">846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bfriendly.com" name="einstein">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0620" published="2005-03-02" name="CVE-2005-0620" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14455" source="SECUNIA" adv="1">14455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bfriendly.com" name="einstein">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0621" published="2005-05-02" name="CVE-2005-0621" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) signed integers for size values, (2) an invalid model, (3) a "newpos" value that is less than or equal to a size value, or (4) partial packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14435" source="SECUNIA" adv="1">14435</ref>
      <ref url="http://aluigi.altervista.org/adv/scrapboom-adv.txt" source="MISC">http://aluigi.altervista.org/adv/scrapboom-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110961578504928&amp;w=2" source="FULLDISC">20050228 Server termination in Scrapland 1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enlight_software" name="scrapland">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0622" published="2005-03-01" name="CVE-2005-0622" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.security.org.sg/vuln/raidenhttpd1132.html" source="MISC" patch="1" adv="1">http://www.security.org.sg/vuln/raidenhttpd1132.html</ref>
      <ref url="http://secunia.com/advisories/14453" source="SECUNIA" patch="1" adv="1">14453</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969702013313&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050301 [SIG^2 G-TEC] RaidenHTTPD Server Buffer Overflow and CGI Source Disclosure Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raidenhttpd" name="raidenhttpd">
        <vers num="1.1.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0623" published="2005-03-01" name="CVE-2005-0623" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.security.org.sg/vuln/raidenhttpd1132.html" source="MISC" patch="1" adv="1">http://www.security.org.sg/vuln/raidenhttpd1132.html</ref>
      <ref url="http://secunia.com/advisories/14453" source="SECUNIA" patch="1" adv="1">14453</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969702013313&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050301 [SIG^2 G-TEC] RaidenHTTPD Server Buffer Overflow and CGI Source Disclosure Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raidenhttpd" name="raidenhttpd">
        <vers num="1.1.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0624" published="2005-02-28" name="CVE-2005-0624" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19504" source="XF" patch="1" adv="1">reportbug-file-world-readable(19504)</ref>
      <ref url="http://secunia.com/advisories/14422/" source="SECUNIA" patch="1" adv="1">14422</ref>
      <ref url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6600" source="CONFIRM" adv="1">https://bugzilla.ubuntu.com/show_bug.cgi?id=6600</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972153627388&amp;w=2" source="BUGTRAQ" adv="1">20050228 [USN-88-1] reportbug information disclosure</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="reportbug">
        <vers num="2.60" />
        <vers num="2.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0625" published="2005-02-28" name="CVE-2005-0625" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19520" source="XF" patch="1" adv="1">reportbug-smtppasswd-information-disclosure(19520)</ref>
      <ref url="http://secunia.com/advisories/14422/" source="SECUNIA" patch="1" adv="1">14422</ref>
      <ref url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6717" source="CONFIRM" adv="1">https://bugzilla.ubuntu.com/show_bug.cgi?id=6717</ref>
      <ref url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6600" source="MISC" adv="1">https://bugzilla.ubuntu.com/show_bug.cgi?id=6600</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407" source="MISC" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972153627388&amp;w=2" source="BUGTRAQ">20050228 [USN-88-1] reportbug information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="reportbug">
        <vers num="2.60" />
        <vers num="2.61" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0626" published="2005-03-08" name="CVE-2005-0626" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19581" source="XF" patch="1" adv="1">squid-set-cookie-race-condition(19581)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-93-1" source="UBUNTU">USN-93-1</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookie" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookie</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-415.html" source="REDHAT">RHSA-2005:415</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11169" source="OVAL">oval:org.mitre.oval:def:11169</ref>
      <ref url="http://www.securityfocus.com/bid/12716" source="BID">12716</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0627" published="2005-05-02" name="CVE-2005-0627" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows local users to execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12695" source="BID" patch="1">12695</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-01.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-01</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=75181" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=75181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trolltech" name="qt">
        <vers num="3.0" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0628" published="2005-03-01" name="CVE-2005-0628" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12689" source="BID" adv="1">12689</ref>
      <ref url="http://secunia.com/advisories/14418" source="SECUNIA" adv="1">14418</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971101826900&amp;w=2" source="BUGTRAQ" adv="1">20050301 Forumwa search.php xss vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="demof" name="forumwa">
        <vers num="v1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0629" published="2005-03-01" name="CVE-2005-0629" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19546" source="XF" adv="1">427bb-profile-xss(19546)</ref>
      <ref url="http://www.securityfocus.com/bid/12693" source="BID" adv="1">12693</ref>
      <ref url="http://securitytracker.com/id?1013337" source="SECTRACK" adv="1">1013337</ref>
      <ref url="http://secunia.com/advisories/14434" source="SECUNIA" adv="1">14434</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970911514167&amp;w=2" source="BUGTRAQ" adv="1">20050301 427BB profile.php XSS vulnerability.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970474726113&amp;w=2" source="BUGTRAQ" adv="1">20050301 427BB profile.php XSS vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="427bb" name="fourtwosevenbb">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0630" published="2005-03-01" name="CVE-2005-0630" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19544" source="XF" adv="1">pblang-sendpm-obtain-information(19544)</ref>
      <ref url="http://www.securityfocus.com/bid/12690" source="BID" adv="1">12690</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971002211589&amp;w=2" source="BUGTRAQ" adv="1">20050301 Software PBLang 4.63 sendpm.php reply file read vulnerability</ref>
      <ref url="http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=40&amp;page=1" source="CONFIRM">http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=40&amp;page=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pblang" name="pblang">
        <vers num="4.0" />
        <vers num="4.56_4.5_rc2" />
        <vers num="4.6" />
        <vers num="4.63" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0631" published="2005-03-01" name="CVE-2005-0631" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19552" source="XF" adv="1">pblang-delpm-delete-messages(19552)</ref>
      <ref url="http://www.securityfocus.com/bid/12694" source="BID" adv="1">12694</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970738214608&amp;w=2" source="BUGTRAQ" adv="1">20050301 Software PBLang 4.63 delpm.php authentication vulnerability</ref>
      <ref url="http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=42&amp;page=1" source="CONFIRM">http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=42&amp;page=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pblang" name="pblang">
        <vers num="4.0" />
        <vers num="4.56_4.5_rc2" />
        <vers num="4.6" />
        <vers num="4.63" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0632" published="2005-03-01" name="CVE-2005-0632" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013345" source="SECTRACK" patch="1" adv="1">1013345</ref>
      <ref url="http://secunia.com/advisories/14449" source="SECUNIA" patch="1" adv="1">14449</ref>
      <ref url="http://www.securityfocus.com/bid/12696" source="BID" adv="1">12696</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110989169008570&amp;w=2" source="BUGTRAQ" adv="1">20050303 PHP News &lt;= 1.2.4 - Remote File Inclusion Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971663824719&amp;w=2" source="BUGTRAQ" adv="1">20050301 PHP News &lt;= 1.2.4 - Remote File Inclusion (VXSfx)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnews" name="phpnews">
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0633" published="2005-03-02" name="CVE-2005-0633" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12703" source="BID" patch="1" adv="1">12703</ref>
      <ref url="http://www.securiteam.com/exploits/5KP030KF5E.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/exploits/5KP030KF5E.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111023000624809&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050306 See-security advisory: Trillian Basic 3.0 PNG Processing Buffer overflow</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0221" source="VUPEN">ADV-2005-0221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_studios" name="trillian">
        <vers num="3.0" />
      </prod>
      <prod vendor="cerulean_studios" name="trillian_pro">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0634" published="2005-05-02" name="CVE-2005-0634" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/4936" source="VUPEN">ADV-2006-4936</ref>
      <ref url="http://www.securityfocus.com/bid/12704" source="BID">12704</ref>
      <ref url="http://www.securityfocus.com/archive/1/391987" source="BUGTRAQ" adv="1">20050302 Golden Ftp server 1.29 Username remote Buffer Overflow</ref>
      <ref url="http://secunia.com/advisories/23323" source="SECUNIA">23323</ref>
      <ref url="http://retrogod.altervista.org/golden_heap.html" source="MISC">http://retrogod.altervista.org/golden_heap.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kmint21_software" name="golden_ftp_server">
        <vers num="1.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0635" published="2005-05-02" name="CVE-2005-0635" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12711" source="BID">12711</ref>
      <ref url="http://www.securityfocus.com/archive/1/391960" source="BUGTRAQ" adv="1">20050302 Foxmail server "USER" command Multiple remote buffer overflow</ref>
      <ref url="http://securitytracker.com/id?1013356" source="SECTRACK" adv="1">1013356</ref>
      <ref url="http://secunia.com/advisories/14145" source="SECUNIA" adv="1">14145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxmail" name="foxmail_email_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0636" published="2005-03-02" name="CVE-2005-0636" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12711" source="BID" adv="1">12711</ref>
      <ref url="http://www.securityfocus.com/archive/1/391960" source="BUGTRAQ" adv="1">20050302 Foxmail server "USER" command Multiple remote buffer overflow</ref>
      <ref url="http://securitytracker.com/id?1013356" source="SECTRACK" adv="1">1013356</ref>
      <ref url="http://secunia.com/advisories/14145" source="SECUNIA" adv="1">14145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxmail" name="foxmail_email_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0637" published="2005-05-02" name="CVE-2005-0637" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The copy functions in locore.s such as copyout in OpenBSD 3.5 and 3.6, and possibly other BSD based operating systems, may allow attackers to exceed certain address boundaries and modify kernel memory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19531" source="XF" patch="1">openbsd-copy-functions(19531)</ref>
      <ref url="http://www.securityfocus.com/bid/12825" source="BID" patch="1">12825</ref>
      <ref url="http://www.openbsd.org/errata35.html#locore" source="OPENBSD" patch="1">20050228 028: SECURITY FIX: February 28, 2005</ref>
      <ref url="http://www.openbsd.org/errata.html#copy" source="OPENBSD" patch="1">20050316 012: SECURITY FIX: March 16, 2005   amd64 only</ref>
      <ref url="http://securitytracker.com/id?1013333" source="SECTRACK" patch="1" adv="1">1013333</ref>
      <ref url="http://secunia.com/advisories/14432" source="SECUNIA" patch="1" adv="1">14432</ref>
      <ref url="http://www.openbsd.org/errata.html#copy" source="OPENBSD">20050228 011: SECURITY FIX: February 28, 2005   i386 only</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0638" published="2005-03-02" name="CVE-2005-0638" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14459" source="SECUNIA" patch="1" adv="1">14459</ref>
      <ref url="http://www.debian.org/security/2005/dsa-695" source="DEBIAN" adv="1">DSA-695</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-05.xml" source="GENTOO" adv="1">GLSA-200503-05</ref>
      <ref url="http://secunia.com/advisories/14462" source="SECUNIA" adv="1">14462</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10898" source="OVAL">oval:org.mitre.oval:def:10898</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=79762" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=79762</ref>
      <ref url="http://www.securityfocus.com/bid/12712" source="BID">12712</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433935/30/5010/threaded" source="FEDORA">FLSA-2006:152923</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-332.html" source="REDHAT">RHSA-2005:332</ref>
      <ref url="http://www.osvdb.org/14365" source="OSVDB">14365</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-134_RHSA-2005-332.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-134_RHSA-2005-332.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xli" name="xli">
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":junior" />
        <vers num="2.3" edition=":compact" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":i386" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":sparc" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.0" edition=":ppc" />
        <vers num="7.0" edition="alpha" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":spa" />
        <vers num="7.1" edition=":sparc" />
        <vers num="7.1" edition=":x86" />
        <vers num="7.1" edition="alpha" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":i386" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":ppc" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":sparc" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0639" published="2005-03-02" name="CVE-2005-0639" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14459" source="SECUNIA" patch="1" adv="1">14459</ref>
      <ref url="http://www.debian.org/security/2005/dsa-695" source="DEBIAN" adv="1">DSA-695</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-05.xml" source="GENTOO" adv="1">GLSA-200503-05</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=79762" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=79762</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xli" name="xli">
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":junior" />
        <vers num="2.3" edition=":compact" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":i386" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":sparc" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.0" edition=":ppc" />
        <vers num="7.0" edition="alpha" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":spa" />
        <vers num="7.1" edition=":sparc" />
        <vers num="7.1" edition=":x86" />
        <vers num="7.1" edition="alpha" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":i386" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":ppc" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":sparc" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0640" published="2005-03-02" name="CVE-2005-0640" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323" source="CONFIRM" patch="1" adv="1">http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323</ref>
      <ref url="http://secunia.com/advisories/14454" source="SECUNIA" patch="1" adv="1">14454</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="unicenter_asset_management">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0641" published="2005-03-02" name="CVE-2005-0641" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14454" source="SECUNIA" patch="1" adv="1">14454</ref>
      <ref url="http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323" source="CONFIRM" adv="1">http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="unicenter_asset_management">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0642" published="2005-05-02" name="CVE-2005-0642" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Query Designer for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to execute arbitrary SQL via an imported file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323" source="CONFIRM">http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323</ref>
      <ref url="http://secunia.com/advisories/14454" source="SECUNIA">14454</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="unicenter_asset_management">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0643" published="2005-05-02" name="CVE-2005-0643" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10243" source="BID">10243</ref>
      <ref url="http://secunia.com/advisories/14628" source="SECUNIA">14628</ref>
      <ref url="http://images.mcafee.com/misc/McAfee_Security_Bulletin_05-march-17.pdf" source="CONFIRM" adv="1">http://images.mcafee.com/misc/McAfee_Security_Bulletin_05-march-17.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0644" published="2005-05-02" name="CVE-2005-0644" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of CVE-2005-0643.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/361180" source="CERT-VN" adv="1">VU#361180</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/190" source="ISS" adv="1">20050317 McAfee AntiVirus Library Stack Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/12832" source="BID">12832</ref>
      <ref url="http://www.securityfocus.com/bid/10243" source="BID">10243</ref>
      <ref url="http://securitytracker.com/id?1013463" source="SECTRACK">1013463</ref>
      <ref url="http://secunia.com/advisories/14628" source="SECUNIA">14628</ref>
      <ref url="http://images.mcafee.com/misc/McAfee_Security_Bulletin_05-march-17.pdf" source="CONFIRM" adv="1">http://images.mcafee.com/misc/McAfee_Security_Bulletin_05-march-17.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0645" published="2005-05-02" name="CVE-2005-0645" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in show.inc.php in cuteNews 1.3.6 allows remote attackers to inject arbitrary HTML, web script, and PHP code via the (1) CLIENT-IP or (2) X-FORWARDED-FOR header in an HTTP POST request to show_news.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kernelpanik.org/docs/kernelpanik/cutenews.txt" source="MISC">http://www.kernelpanik.org/docs/kernelpanik/cutenews.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969774502370&amp;w=2" source="BUGTRAQ">20050301 Kernelpanik Labs Digest 2005-2</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0646" published="2005-05-02" name="CVE-2005-0646" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kernelpanik.org/docs/kernelpanik/panews.txt" source="MISC">http://www.kernelpanik.org/docs/kernelpanik/panews.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969774502370&amp;w=2" source="BUGTRAQ">20050301 Kernelpanik Labs Digest 2005-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="panews">
        <vers num="2.0.4b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0647" published="2005-05-02" name="CVE-2005-0647" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kernelpanik.org/docs/kernelpanik/panews.txt" source="MISC">http://www.kernelpanik.org/docs/kernelpanik/panews.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969774502370&amp;w=2" source="BUGTRAQ">20050301 Kernelpanik Labs Digest 2005-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="panews">
        <vers num="2.0.4b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0648" published="2005-05-02" name="CVE-2005-0648" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013315" source="SECTRACK">1013315</ref>
      <ref url="http://pixel-apes.com/safehtml/feed" source="CONFIRM">http://pixel-apes.com/safehtml/feed</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixel-apes_group" name="safehtml">
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0649" published="2005-05-02" name="CVE-2005-0649" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13869" source="SECUNIA">13869</ref>
      <ref url="http://pixel-apes.com/safehtml/feed" source="CONFIRM">http://pixel-apes.com/safehtml/feed</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixel-apes_group" name="safehtml">
        <vers prev="1" num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0650" published="2005-05-02" name="CVE-2005-0650" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) the pages parameter to divers.php (incorrectly referred to as "drivers.php" by some sources), (2) in the search feature text area, (3) forum name, (4) site name or (5) the maximum avatar size in the option section, (5) new category or (6) new forum fields in the forum section.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19556" source="XF">projectbb-multiple-xss(19556)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0223" source="VUPEN">ADV-2005-0223</ref>
      <ref url="http://www.securityfocus.com/bid/12709" source="BID">12709</ref>
      <ref url="http://securitytracker.com/id?1013332" source="SECTRACK">1013332</ref>
      <ref url="http://secunia.com/advisories/14533" source="SECUNIA">14533</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031893610270&amp;w=2" source="BUGTRAQ">20050308 failles dans ProjectBB v0.4.5.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="projectbb" name="projectbb">
        <vers num="0.4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0651" published="2005-05-02" name="CVE-2005-0651" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to execute arbitrary SQL commands via (1) liste or (2) desc parameters to divers.php (incorrectly referred to as "drivers.php" by some sources), (3) the search feature text area, (4) post name in the post creation feature, (5) City, (6) Homepage, (7) ICQ, (8) AOL, (9) Yahoo!, (10) MSN, or (11) e-mail fields in the profile feature or (12) the new field in the moderator section.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19557" source="XF">projectbb-mulitple-sql-injection(19557)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0223" source="VUPEN">ADV-2005-0223</ref>
      <ref url="http://www.securityfocus.com/bid/12710" source="BID">12710</ref>
      <ref url="http://securitytracker.com/id?1013332" source="SECTRACK">1013332</ref>
      <ref url="http://secunia.com/advisories/14533" source="SECUNIA">14533</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031893610270&amp;w=2" source="BUGTRAQ">20050308 failles dans ProjectBB v0.4.5.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="projectbb" name="projectbb">
        <vers num="0.4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0652" published="2005-05-02" name="CVE-2005-0652" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19566" source="XF">openvms-gain-access(19566)</ref>
      <ref url="http://secunia.com/advisories/14444" source="SECUNIA">14444</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110980700101451&amp;w=2" source="HP">SSRT4866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openvms">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":vax" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":vax" />
        <vers num="7.3-1" edition="" />
        <vers num="7.3-1" edition=":alpha" />
        <vers num="7.3-2" edition="" />
        <vers num="7.3-2" edition=":alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0653" published="2005-05-02" name="CVE-2005-0653" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml" source="GENTOO" patch="1">GLSA-200503-07</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=83792" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=83792</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0654" published="2005-05-02" name="CVE-2005-0654" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gifload.exe in GIMP 2.0.5, 2.2.3, and possibly 2.2.4 allows remote attackers or local users to cause a denial of service (application crash) via the image descriptor (1) height or (2) width fields set to zero.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110995346018830&amp;w=2" source="BUGTRAQ">20050304 GIMP gifload.exe GIF file (image width)*(image height)==0 DOS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_gimp_team" name="gimp">
        <vers num="2.0.5" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0655" published="2005-05-02" name="CVE-2005-0655" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">auraCMS 1.5 allows remote attackers to obtain sensitive information via an HTTP request with an invalid id parameter to (1) teman.php, (2) hal.php, or (3) arsip.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013357" source="SECTRACK">1013357</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979842315750&amp;w=2" source="BUGTRAQ">20050302 Vulnerabilities in Aura CMS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arif_supriyanto" name="auracms">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0656" published="2005-05-02" name="CVE-2005-0656" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in auraCMS 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) hits parameter to hits.php, (2) query parameter to index.php, or (3) theCount parameter to counter.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013357" source="SECTRACK">1013357</ref>
      <ref url="http://secunia.com/advisories/14458" source="SECUNIA">14458</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979842315750&amp;w=2" source="BUGTRAQ">20050302 Vulnerabilities in Aura CMS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arif_supriyanto" name="auracms">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0657" published="2005-05-02" name="CVE-2005-0657" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Computalynx CProxy 3.3.x and 3.4.x through 3.4.4 allows remote attackers to read arbitrary files or cause a denial of service (application crash) via a .. (dot dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19574" source="XF">computalynx-cproxy-get-dos(19574)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19573" source="XF">computalynx-cproxy-directory-traversal(19573)</ref>
      <ref url="http://secunia.com/advisories/14461" source="SECUNIA">14461</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110980096304013&amp;w=2" source="BUGTRAQ">20050302 Security Advisory: Computalynx CProxy Server Multiple Remote Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computalynx" name="cproxy">
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0658" published="2005-05-02" name="CVE-2005-0658" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in a third party extension to TYPO3 allows remote attackers to execute arbitrary SQL commands via the category_uid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14465" source="SECUNIA" patch="1">14465</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996536620069&amp;w=2" source="BUGTRAQ">20050304 Re: TYPO3 SQL Injection vunerabilitie</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110995289619649&amp;w=2" source="BUGTRAQ">20050304 RE: TYPO3 SQL Injection vunerabilitie</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110987892618892&amp;w=2" source="BUGTRAQ">20050303 TYPO3 SQL Injection vunerabilitie</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmw_linklist" name="cmw_linklist">
        <vers prev="1" num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0659" published="2005-05-02" name="CVE-2005-0659" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013377" source="SECTRACK">1013377</ref>
      <ref url="http://neosecurityteam.net/Advisories/Advisory-09.txt" source="MISC">http://neosecurityteam.net/Advisories/Advisory-09.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996579900134&amp;w=2" source="BUGTRAQ">20050304 -==phpBB 2.0.13 Full path disclosure==-</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="1.0.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0660" published="2005-05-02" name="CVE-2005-0660" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013349" source="SECTRACK">1013349</ref>
      <ref url="http://secunia.com/advisories/14464" source="SECUNIA">14464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adalis" name="d-forum">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0661" published="2005-05-02" name="CVE-2005-0661" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14450" source="SECUNIA" patch="1">14450</ref>
      <ref url="http://securitytracker.com/id?1013351" source="SECTRACK">1013351</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers num="2.0.3" />
        <vers num="2.1.5" />
        <vers num="2.2.1" />
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0662" published="2005-05-02" name="CVE-2005-0662" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14414" source="SECUNIA" patch="1">14414</ref>
      <ref url="http://www.osvdb.org/14308" source="OSVDB">14308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0663" published="2005-05-02" name="CVE-2005-0663" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14414" source="SECUNIA" patch="1">14414</ref>
      <ref url="http://www.osvdb.org/14308" source="OSVDB">14308</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19051" source="XF">mercuryboard-index-sql-injection(19051)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0664" published="2005-05-02" name="CVE-2005-0664" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.ubuntu.com/show_bug.cgi?id=7152" source="MISC" patch="1">https://bugzilla.ubuntu.com/show_bug.cgi?id=7152</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-17.xml" source="GENTOO" patch="1">GLSA-200503-17</ref>
      <ref url="http://www.debian.org/security/2005/dsa-709" source="DEBIAN" patch="1">DSA-709</ref>
      <ref url="http://securitytracker.com/id?1013398" source="SECTRACK" patch="1">1013398</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2565" source="VUPEN">ADV-2005-2565</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0240" source="VUPEN">ADV-2005-0240</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-91-1" source="UBUNTU">USN-91-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-300.html" source="REDHAT">RHSA-2005:300</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102041-1" source="SUNALERT">102041</ref>
      <ref url="http://secunia.com/advisories/17705" source="SECUNIA">17705</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10832" source="OVAL">oval:org.mitre.oval:def:10832</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:064" source="MANDRAKE">MDKSA-2005:064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libexif" name="libexif">
        <vers num="0.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0665" published="2005-05-02" name="CVE-2005-0665" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Format string vulnerability in xv before 3.10a allows remote attackers to execute arbitrary code via format string specifiers in a filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-09.xml" source="GENTOO">GLSA-200503-09</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=83686" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=83686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_bradley" name="xv">
        <vers num="3.10a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0666" published="2005-05-02" name="CVE-2005-0666" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12729" source="BID">12729</ref>
      <ref url="http://www.securityfocus.com/archive/1/392348" source="BUGTRAQ">20050305 PaX privilege elevation security bug</ref>
      <ref url="http://secunia.com/advisories/14489" source="SECUNIA">14489</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_pax_team" name="pax_linux">
        <vers num="2.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.24" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" />
        <vers num="2.4.28" />
        <vers num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0667" published="2005-03-07" name="CVE-2005-0667" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-303.html" source="REDHAT" patch="1" adv="1">RHSA-2005:303</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-26.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-26</ref>
      <ref url="http://sylpheed.good-day.net/changelog.html.en" source="CONFIRM" patch="1" adv="1">http://sylpheed.good-day.net/changelog.html.en</ref>
      <ref url="http://sylpheed.good-day.net/changelog-devel.html.en" source="CONFIRM" patch="1" adv="1">http://sylpheed.good-day.net/changelog-devel.html.en</ref>
      <ref url="http://secunia.com/advisories/14491" source="SECUNIA" patch="1" adv="1">14491</ref>
      <ref url="http://securitytracker.com/id?1013376" source="SECTRACK" adv="1">1013376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sylpheed" name="sylpheed">
        <vers num="0.8.11" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="0.9.99" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="sylpheed-claws" name="sylpheed-claws">
        <vers num="1.0.2" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":compact" />
        <vers num="2.3" edition=":junior" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0668" published="2005-03-04" name="CVE-2005-0668" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.bemberg.de/server-side/index.htm" source="CONFIRM" patch="1" adv="1">http://www.bemberg.de/server-side/index.htm</ref>
      <ref url="http://securitytracker.com/id?1013370" source="SECTRACK" patch="1" adv="1">1013370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="christian_hilgers" name="http_anti_virus_proxy_(havp)">
        <vers prev="1" num="0.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0669" published="2005-05-02" name="CVE-2005-0669" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq_id in the faq mod, (2) the id parameter in the pages mod, (3) the id parameter in the siteinfo module, (4) the topic_id parameter in the articles module, (5) the ord_id in the orders module, (6) the dom_id parameter in the domains module, or (7) the invd_id parameter in the invoices module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14439" source="SECUNIA" patch="1">14439</ref>
      <ref url="http://forums.phpcoin.com/index.php?showtopic=4116" source="CONFIRM" patch="1">http://forums.phpcoin.com/index.php?showtopic=4116</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19571" source="XF">phpcoin-id-sql-injection(19571)</ref>
      <ref url="http://www.securityfocus.com/bid/12686" source="BID">12686</ref>
      <ref url="http://securitytracker.com/id?1013329" source="SECTRACK">1013329</ref>
      <ref url="http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.html" source="MISC">http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.html</ref>
      <ref url="http://forums.phpcoin.com/index.php?showtopic=4118" source="CONFIRM">http://forums.phpcoin.com/index.php?showtopic=4118</ref>
      <ref url="http://forums.phpcoin.com/index.php?showtopic=4101" source="CONFIRM">http://forums.phpcoin.com/index.php?showtopic=4101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coinsoft_technologies" name="phpcoin">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0670" published="2005-05-02" name="CVE-2005-0670" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e parameter to login.php, (4) the o parameter to login.php, and possibly other scripts.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14439" source="SECUNIA" patch="1">14439</ref>
      <ref url="http://forums.phpcoin.com/index.php?showtopic=4116" source="CONFIRM" patch="1">http://forums.phpcoin.com/index.php?showtopic=4116</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19572" source="XF">phpcoin-xss(19572)</ref>
      <ref url="http://www.securityfocus.com/bid/12686" source="BID">12686</ref>
      <ref url="http://securitytracker.com/id?1013329" source="SECTRACK">1013329</ref>
      <ref url="http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.html" source="MISC">http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.html</ref>
      <ref url="http://forums.phpcoin.com/index.php?showtopic=4118" source="CONFIRM">http://forums.phpcoin.com/index.php?showtopic=4118</ref>
      <ref url="http://forums.phpcoin.com/index.php?showtopic=4101" source="CONFIRM">http://forums.phpcoin.com/index.php?showtopic=4101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coinsoft_technologies" name="phpcoin">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0671" published="2005-03-03" name="CVE-2005-0671" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12727" source="BID" patch="1" adv="1">12727</ref>
      <ref url="http://secunia.com/advisories/14483" source="SECUNIA" patch="1" adv="1">14483</ref>
      <ref url="http://securitytracker.com/id?1013361" source="SECTRACK" adv="1">1013361</ref>
      <ref url="http://aluigi.altervista.org/adv/ca3dex-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/ca3dex-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca3de" name="ca3de">
        <vers prev="1" num="march_2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0672" published="2005-05-02" name="CVE-2005-0672" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via text strings that are not null terminated, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12727" source="BID">12727</ref>
      <ref url="http://securitytracker.com/id?1013361" source="SECTRACK">1013361</ref>
      <ref url="http://secunia.com/advisories/14483" source="SECUNIA">14483</ref>
      <ref url="http://aluigi.altervista.org/adv/ca3dex-adv.txt" source="MISC">http://aluigi.altervista.org/adv/ca3dex-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca3de" name="ca3de">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0673" published="2005-05-02" name="CVE-2005-0673" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) allowsmilies parameters to inject HTML into signatures for personal messages, possibly when they are processed by privmsg.php or viewtopic.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14475" source="SECUNIA" patch="1">14475</ref>
      <ref url="http://securitytracker.com/id?1013362" source="SECTRACK">1013362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0674" published="2005-03-03" name="CVE-2005-0674" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the News module for paBox 1.6 allows remote attackers to inject arbitrary web script or HTML via the text hidden parameter in an HTTP POST request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12719" source="BID" adv="1">12719</ref>
      <ref url="http://securitytracker.com/id?1013363" source="SECTRACK" adv="1">1013363</ref>
      <ref url="http://secunia.com/advisories/14474" source="SECUNIA" adv="1">14474</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110987537431541&amp;w=2" source="BUGTRAQ" adv="1">20050303 [XSS] paBox 1.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pabox">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0675" published="2005-05-02" name="CVE-2005-0675" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (1) list or (2) frommethod parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013365" source="SECTRACK">1013365</ref>
      <ref url="http://secunia.com/advisories/9497" source="SECUNIA">9497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="zorum">
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0676" published="2005-05-04" name="CVE-2005-0676" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013365" source="SECTRACK" adv="1">1013365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="zorum">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0677" published="2005-05-02" name="CVE-2005-0677" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013365" source="SECTRACK">1013365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="zorum">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0678" published="2005-05-02" name="CVE-2005-0678" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the script_root to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.stadtaus.com/forum/t-1579.html" source="CONFIRM" patch="1">http://www.stadtaus.com/forum/t-1579.html</ref>
      <ref url="http://secunia.com/advisories/14505" source="SECUNIA" patch="1">14505</ref>
      <ref url="http://securitytracker.com/id?1013378" source="SECTRACK">1013378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996489800035&amp;w=2" source="BUGTRAQ" adv="1">20050304 PHP Form Mail Script (2.3) - Arbitrary File Inclusion (VXSfx)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stadtaus" name="form_mail_script">
        <vers prev="1" num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0679" published="2005-05-02" name="CVE-2005-0679" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7 before 20050305 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.  NOTE: it was later reported that 2.4 is also affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.stadtaus.com/forum/t-1579.html" source="CONFIRM" patch="1" adv="1">http://www.stadtaus.com/forum/t-1579.html</ref>
      <ref url="http://securitytracker.com/id?1013390" source="SECTRACK" patch="1">1013390</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19630" source="XF">tellafriend-scriptroot-file-include(19630)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/474954/100/0/threaded" source="BUGTRAQ">20070727 Friend Script 2.5 - 2.4 Remote File &amp;#304;nclude</ref>
      <ref url="http://www.osvdb.org/14628" source="OSVDB">14628</ref>
      <ref url="http://arfis.wordpress.com/2007/09/13/rfi-02-openelibrary/" source="MISC">http://arfis.wordpress.com/2007/09/13/rfi-02-openelibrary/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stadtaus" name="tell_a_friend_script">
        <vers prev="1" num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0680" published="2005-03-07" name="CVE-2005-0680" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.stadtaus.com/forum/t-1579.html" source="CONFIRM" patch="1" adv="1">http://www.stadtaus.com/forum/t-1579.html</ref>
      <ref url="http://secunia.com/advisories/14513" source="SECUNIA" patch="1" adv="1">14513</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996056601719&amp;w=2" source="BUGTRAQ" adv="1">20050304 Download Center Lite (DCL) - Arbitrary File Inclusion (VXSfx)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0681" published="2005-03-06" name="CVE-2005-0681" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013380" source="SECTRACK" adv="1">1013380</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19594" source="XF">nokia-symbian-dos(19594)</ref>
      <ref url="http://www.securityfocus.com/bid/12743" source="BID">12743</ref>
      <ref url="http://www.securiteam.com/securitynews/5PP0V00G1S.html" source="MISC">http://www.securiteam.com/securitynews/5PP0V00G1S.html</ref>
      <ref url="http://www.osvdb.org/14574" source="OSVDB">14574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="series">
        <vers num="60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0682" published="2005-05-02" name="CVE-2005-0682" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14515" source="SECUNIA" patch="1" adv="1">14515</ref>
      <ref url="http://drupal.org/files/drupal-4.5-xss-fix.patch" source="CONFIRM" patch="1">http://drupal.org/files/drupal-4.5-xss-fix.patch</ref>
      <ref url="http://drupal.org/drupal-4.5.2" source="CONFIRM" patch="1" adv="1">http://drupal.org/drupal-4.5.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.5.0" />
        <vers num="4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0683" reject="1" published="2005-05-02" name="CVE-2005-0683" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0659.  Reason: This candidate is a duplicate of CVE-2005-0659.  Notes: All CVE users should reference CVE-2005-0659 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-0684" published="2005-04-25" name="CVE-2005-0684" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=235&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050425 MySQL MaxDB Webtool Remote Lock-Token Stack Overflow Vulnerability</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=234&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050425 MySQL MaxDB Webtool Remote Stack Overflow Vulnerability</ref>
      <ref url="http://dev.mysql.com/doc/maxdb/changes/changes_7.5.00.26.html#WebDAV" source="CONFIRM" patch="1" adv="1">http://dev.mysql.com/doc/maxdb/changes/changes_7.5.00.26.html#WebDAV</ref>
      <ref url="http://www.securityfocus.com/bid/13368" source="BID">13368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00" />
        <vers num="7.5.00.08" />
        <vers num="7.5.00.11" />
        <vers num="7.5.00.12" />
        <vers num="7.5.00.14" />
        <vers num="7.5.00.15" />
        <vers num="7.5.00.16" />
        <vers num="7.5.00.18" />
        <vers num="7.5.00.19" />
        <vers num="7.5.00.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0685" published="2005-03-08" name="CVE-2005-0685" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete arbitrary directory objects by modifying the selectedObjectsCSV parameter to displaydeletenavigator.jsp, and conduct other unauthorized activities via the (4) showDeleteView, (5) showWebFolderView, (6) showLibraryView, (7) showMyLibraryView, (8) singleSelectObject, (9) processRadioSelection, (10) processCheckboxSelection, (11) singleSelectObject, (12) addToSelectedObjects, or (13) removeFromSelectedObjects commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19632" source="XF" patch="1" adv="1">pe-access-validation-dos(19632)</ref>
      <ref url="http://www.securityfocus.com/bid/12752" source="BID" patch="1" adv="1">12752</ref>
      <ref url="http://security.honour.ca/outstartpsi.txt" source="MISC" patch="1" adv="1">http://security.honour.ca/outstartpsi.txt</ref>
      <ref url="http://secunia.com/advisories/14542" source="SECUNIA" patch="1" adv="1">14542</ref>
      <ref url="http://www.securityfocus.com/archive/1/392623" source="BUGTRAQ" adv="1">20050308 PE Multiple Remote Access Validation Vulnerabilities (Participate Systems Inc. / Outstart Inc.)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="outstart" name="participate_enterprise">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0686" published="2005-03-07" name="CVE-2005-0686" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in mlterm 2.5.0 through 2.9.1, with gdk-pixbuf support enabled, allows remote attackers to execute arbitrary code via a large image file that is used as a background.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://sourceforge.net/project/shownotes.php?release_id=310416" source="CONFIRM" patch="1" adv="1">https://sourceforge.net/project/shownotes.php?release_id=310416</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mlterm" name="mlterm">
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
        <vers num="2.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0687" published="2005-03-06" name="CVE-2005-0687" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via format string specifiers in a reply address, which is not properly handled when printing the header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-12</ref>
      <ref url="http://secunia.com/advisories/14487" source="SECUNIA" patch="1" adv="1">14487</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=83541" source="MISC" patch="1" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=83541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hashcash" name="hashcash">
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0688" published="2005-03-05" name="CVE-2005-0688" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/3983" source="VUPEN">ADV-2006-3983</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded" source="HP">HPSBST02161</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" source="MS" adv="1">MS05-019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111005099504081&amp;w=2" source="BUGTRAQ" adv="1">20050305 Windows Server 2003 and XP SP2 LAND attack vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded" source="HP">HPSBST02161</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx" source="MS">MS06-064</ref>
      <ref url="http://secunia.com/advisories/22341" source="SECUNIA">22341</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4978" source="OVAL" sig="1">oval:org.mitre.oval:def:4978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:482" source="OVAL" sig="1">oval:org.mitre.oval:def:482</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1685" source="OVAL" sig="1">oval:org.mitre.oval:def:1685</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1288" source="OVAL" sig="1">oval:org.mitre.oval:def:1288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0689" published="2005-03-07" name="CVE-2005-0689" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12738" source="BID" adv="1">12738</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111030957413411&amp;w=2" source="BUGTRAQ" adv="1">20050308 Re: Remote Command Execution</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111021730710779&amp;w=2" source="BUGTRAQ" adv="1">20050307 Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jimmy" name="the_includer">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0690" published="2005-03-07" name="CVE-2005-0690" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12739" source="BID" patch="1" adv="1">12739</ref>
      <ref url="http://secway.org/Advisory/ad20050303.txt" source="MISC" adv="1">http://secway.org/Advisory/ad20050303.txt</ref>
      <ref url="http://secunia.com/advisories/14436" source="SECUNIA" adv="1">14436</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026585431080&amp;w=2" source="BUGTRAQ" adv="1">20050308 Re: Gene6 FTP Server Local Privilege Escalation Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022496826680&amp;w=2" source="BUGTRAQ" adv="1">20050307 Gene6 FTP Server Local Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gene6" name="g6_ftp_server">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0691" published="2005-03-06" name="CVE-2005-0691" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://waraxe.us/ftopic-542-0-days0-orderasc-.html" source="MISC" adv="1">http://waraxe.us/ftopic-542-0-days0-orderasc-.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022633903239&amp;w=2" source="BUGTRAQ" adv="1">20050307 Remote Testing SocialMPN Remote File Inclusion by y3dips</ref>
    </refs>
    <vuln_soft>
      <prod vendor="socialmpn" name="socialmpn">
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0692" published="2005-03-06" name="CVE-2005-0692" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14492" source="SECUNIA" patch="1" adv="1">14492</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022851900028&amp;w=2" source="BUGTRAQ" adv="1">20050306 PHP-FUSION 5.* XSS VULNERABILITY</ref>
      <ref url="http://www.php-fusion.co.uk/news.php?readmore=183" source="CONFIRM">http://www.php-fusion.co.uk/news.php?readmore=183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0693" published="2005-03-07" name="CVE-2005-0693" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12733" source="BID" adv="1">12733</ref>
      <ref url="http://aluigi.altervista.org/adv/chasercool-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/chasercool-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jowood_productions" name="chaser">
        <vers num="1.0" />
        <vers num="1.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0694" published="2005-03-07" name="CVE-2005-0694" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14522" source="SECUNIA" patch="1" adv="1">14522</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026083314947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050307 Hosting Controller Multiple Unauthenticated information disclose</ref>
      <ref url="http://isun.shabgard.org/hc2.txt" source="MISC" patch="1" adv="1">http://isun.shabgard.org/hc2.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="1.1" />
        <vers num="1.3" />
        <vers num="1.4.1" />
        <vers num="1.4b" />
        <vers num="6.1" />
        <vers num="6.1_hotfix_1.4" />
        <vers num="6.1_hotfix_1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0695" published="2005-03-07" name="CVE-2005-0695" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14522" source="SECUNIA" patch="1" adv="1">14522</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026083314947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050307 Hosting Controller Multiple Unauthenticated information disclose</ref>
      <ref url="http://isun.shabgard.org/hc2.txt" source="MISC" patch="1" adv="1">http://isun.shabgard.org/hc2.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="1.1" />
        <vers num="1.3" />
        <vers num="1.4.1" />
        <vers num="1.4b" />
        <vers num="6.1" />
        <vers num="6.1_hotfix_1.4" />
        <vers num="6.1_hotfix_1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0696" published="2005-03-08" name="CVE-2005-0696" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12755" source="BID" patch="1" adv="1">12755</ref>
      <ref url="http://secunia.com/advisories/14526" source="SECUNIA" patch="1" adv="1">14526</ref>
      <ref url="https://www.securinfos.info/english/security-advisories-alerts/20060225_ArGoSoft.FTP.Server_Heap.Overflow.html" source="MISC">https://www.securinfos.info/english/security-advisories-alerts/20060225_ArGoSoft.FTP.Server_Heap.Overflow.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426081/100/0/threaded" source="BUGTRAQ">20060225 ArGoSoft FTP server remote heap overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/392653" source="BUGTRAQ" adv="1">20050308 ArGoSoft FTP Server 1.4.2.8 Buffer Overflow</ref>
      <ref url="http://securitytracker.com/id?1015681" source="SECTRACK">1015681</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042523.html" source="FULLDISC">20060225 ArGoSoft FTP server remote heap overflow</ref>
      <ref url="http://securityreason.com/securityalert/494" source="SREASON">494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="ftp_server">
        <vers num="1.4.2.29" />
        <vers num="1.4.2.8" />
        <vers num="1.4.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0697" published="2005-03-07" name="CVE-2005-0697" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the process_picture function xp_publish.php in CopperExport 0.2.1 allows remote attackers to execute arbitrary SQL commands, possibly via the (1) title, (2) caption, or (3) keywords parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zzamboni.org/copperexport/" source="CONFIRM" patch="1" adv="1">http://www.zzamboni.org/copperexport/</ref>
      <ref url="http://secunia.com/advisories/14401" source="SECUNIA" patch="1" adv="1">14401</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brt" name="copperexport">
        <vers num="0.1" />
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0698" published="2005-03-07" name="CVE-2005-0698" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12747" source="BID" adv="1">12747</ref>
      <ref url="http://www.securityfocus.com/archive/1/392552" source="BUGTRAQ" adv="1">20050307 phpWebLog &lt;= 0.5.3 arbitrary file inclusion (VXSfx)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_hines" name="phpweblog">
        <vers num="0.4.2" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0699" published="2005-03-08" name="CVE-2005-0699" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12759" source="BID" patch="1" adv="1">12759</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-306.html" source="REDHAT" patch="1" adv="1">RHSA-2005:306</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00018.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-16.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-16</ref>
      <ref url="http://www.securityfocus.com/archive/1/392659" source="BUGTRAQ" adv="1">20050308 Ethereal remote buffer overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10147" source="OVAL">oval:org.mitre.oval:def:10147</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053" source="MANDRAKE">MDKSA-2005:053</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-03-04" source="MISC">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-03-04</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083125521813&amp;w=2" source="BUGTRAQ">20050314 Ethereal 0.10.9 and below remote root exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111038641832400&amp;w=2" source="BUGTRAQ">20050309 RE: Ethereal remote buffer overflow - addon</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="compact_2.3" />
        <vers num="junior_2.3" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0700" published="2005-03-07" name="CVE-2005-0700" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12745" source="BID" adv="1">12745</ref>
      <ref url="http://www.frsirt.com/exploits/20050307.aztek.c.php" source="MISC" adv="1">http://www.frsirt.com/exploits/20050307.aztek.c.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0701" published="2005-03-07" name="CVE-2005-0701" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.."  (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.argeniss.com/research/ARGENISS-ADV-030501.txt" source="MISC" patch="1" adv="1">http://www.argeniss.com/research/ARGENISS-ADV-030501.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111023635928211&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050307 - Argeniss - Oracle Database Server Directory transversal</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032273.html" source="FULLDISC" patch="1" adv="1">20050307 - Argeniss - Oracle Database Server Directory transversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0702" published="2005-03-07" name="CVE-2005-0702" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpmyfaq.de/advisory_2005-03-06.php" source="CONFIRM" patch="1" adv="1">http://www.phpmyfaq.de/advisory_2005-03-06.php</ref>
      <ref url="http://secunia.com/advisories/14516" source="SECUNIA" patch="1" adv="1">14516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyfaq" name="phpmyfaq">
        <vers num="1.4" />
        <vers num="1.4_alpha1" />
        <vers num="1.4_alpha2" />
        <vers num="1.4a" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0703" published="2005-03-07" name="CVE-2005-0703" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, has an "unauthenticated account," which allows remote attackers to modify system configuration, a different vulnerability than CVE-2005-1179.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf</ref>
      <ref url="http://secunia.com/advisories/14507" source="SECUNIA" patch="1" adv="1">14507</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_165">
        <vers num="" edition=":pro" />
        <vers num="7.47.30.000" edition="" />
        <vers num="7.47.30.000" edition=":pro" />
        <vers num="7.47.33.008" edition="" />
        <vers num="7.47.33.008" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_175">
        <vers num="" edition=":pro" />
        <vers num="7.47.30.000" edition="" />
        <vers num="7.47.30.000" edition=":pro" />
        <vers num="7.47.33.008" edition="" />
        <vers num="7.47.33.008" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_2128">
        <vers num="" edition=":pro_color" />
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_2636">
        <vers num="" edition=":pro_color" />
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_32_color">
        <vers num="" edition=":pro" />
        <vers num="0.001.00.060" edition="" />
        <vers num="0.001.00.060" edition=":pro" />
        <vers num="0.001.02.081" edition="" />
        <vers num="0.001.02.081" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_35">
        <vers num="" edition=":pro" />
        <vers num="3.028.11.000" edition="" />
        <vers num="3.028.11.000" edition=":pro" />
        <vers num="3.97.20.032" edition="" />
        <vers num="3.97.20.032" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_3545">
        <vers num="" edition=":pro_color" />
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_40_color">
        <vers num="" edition=":pro" />
        <vers num="0.001.00.060" edition="" />
        <vers num="0.001.00.060" edition=":pro" />
        <vers num="0.001.02.081" edition="" />
        <vers num="0.001.02.081" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_45">
        <vers num="" edition=":pro" />
        <vers num="3.028.11.000" edition="" />
        <vers num="3.028.11.000" edition=":pro" />
        <vers num="3.97.20.032" edition="" />
        <vers num="3.97.20.032" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_55">
        <vers num="" edition=":pro" />
        <vers num="3.028.11.000" edition="" />
        <vers num="3.028.11.000" edition=":pro" />
        <vers num="3.97.20.032" edition="" />
        <vers num="3.97.20.032" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_65">
        <vers num="" edition=":pro" />
        <vers num="1.001.00.060" edition="" />
        <vers num="1.001.00.060" edition=":pro" />
        <vers num="1.001.02.084" edition="" />
        <vers num="1.001.02.084" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_75">
        <vers num="" edition=":pro" />
        <vers num="1.001.00.060" edition="" />
        <vers num="1.001.00.060" edition=":pro" />
        <vers num="1.001.02.084" edition="" />
        <vers num="1.001.02.084" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_90">
        <vers num="" edition=":pro" />
        <vers num="1.001.00.060" edition="" />
        <vers num="1.001.00.060" edition=":pro" />
        <vers num="1.001.02.084" edition="" />
        <vers num="1.001.02.084" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_m165">
        <vers num="6.47.30.000" />
        <vers num="6.47.33.008" />
        <vers num="8.47.30.000" />
        <vers num="8.47.33.008" />
      </prod>
      <prod vendor="xerox" name="workcentre_m175">
        <vers num="6.47.30.000" />
        <vers num="6.47.33.008" />
        <vers num="8.47.30.000" />
        <vers num="8.47.33.008" />
      </prod>
      <prod vendor="xerox" name="workcentre_m35">
        <vers num="2.28.11.000" />
        <vers num="2.97.20.032" />
        <vers num="4.84.16.000" />
      </prod>
      <prod vendor="xerox" name="workcentre_m45">
        <vers num="2.28.11.000" />
        <vers num="2.97.20.032" />
        <vers num="4.84.16.000" />
      </prod>
      <prod vendor="xerox" name="workcentre_m55">
        <vers num="2.28.11.000" />
        <vers num="2.97.20.032" />
        <vers num="4.84.16.000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0704" published="2005-05-02" name="CVE-2005-0704" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Etheric dissector in Ethereal 0.10.7 through 0.10.9 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml" source="GENTOO" patch="1">GLSA-200503-16</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-306.html" source="REDHAT">RHSA-2005:306</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00018.html" source="CONFIRM" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10447" source="OVAL">oval:org.mitre.oval:def:10447</ref>
      <ref url="http://www.securityfocus.com/bid/12762" source="BID">12762</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053" source="MANDRAKE">MDKSA-2005:053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0705" published="2005-05-02" name="CVE-2005-0705" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The GPRS-LLC dissector in Ethereal 0.10.7 through 0.10.9, with the "ignore cipher bit" option enabled. allows remote attackers to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml" source="GENTOO" patch="1">GLSA-200503-16</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-306.html" source="REDHAT">RHSA-2005:306</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00018.html" source="CONFIRM" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10565" source="OVAL">oval:org.mitre.oval:def:10565</ref>
      <ref url="http://www.securityfocus.com/bid/12762" source="BID">12762</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053" source="MANDRAKE">MDKSA-2005:053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0706" published="2005-05-02" name="CVE-2005-0706" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in discdb.c for grip 3.1.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the cddb lookup to return more matches than expected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-21.xml" source="GENTOO" patch="1">GLSA-200503-21</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00188.html" source="FEDORA">FEDORA-2008-11956</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00490.html" source="FEDORA">FEDORA-2008-9521</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00429.html" source="FEDORA">FEDORA-2008-9604</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19648" source="XF">grip-cddb-bo(19648)</ref>
      <ref url="http://www.securityfocus.com/bid/12770" source="BID">12770</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0005.html" source="REDHAT">RHSA-2009:0005</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-304.html" source="REDHAT">RHSA-2005:304</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834724&amp;group_id=3714&amp;atid=103714" source="MISC" adv="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834724&amp;group_id=3714&amp;atid=103714</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1160134&amp;group_id=3714&amp;atid=303714" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1160134&amp;group_id=3714&amp;atid=303714</ref>
      <ref url="http://secunia.com/advisories/33824" source="SECUNIA">33824</ref>
      <ref url="http://secunia.com/advisories/33389" source="SECUNIA">33389</ref>
      <ref url="http://secunia.com/advisories/32803" source="SECUNIA">32803</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10768" source="OVAL">oval:org.mitre.oval:def:10768</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152919" source="FEDORA">FLSA:152919</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html" source="CONFIRM">http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grip" name="grip">
        <vers num="2.9.6" />
        <vers num="3.1.2" />
        <vers num="3.1.4" />
        <vers num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0707" published="2005-05-02" name="CVE-2005-0707" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP daemon (IMAP4d32.exe) for Ipswitch Collaboration Suite (ICS) before 8.15 Hotfix 1 allows remote authenticated users to execute arbitrary code via a long EXAMINE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013410" source="SECTRACK" patch="1">1013410</ref>
      <ref url="http://secunia.com/advisories/14546" source="SECUNIA" patch="1">14546</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19655" source="XF">ipswitch-imail-imapexamine-bo(19655)</ref>
      <ref url="http://www.securityfocus.com/bid/12780" source="BID">12780</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=216&amp;type=vulnerabilities" source="IDEFENSE">20050310 Ipswitch Collaboration Suite IMAP EXAMINE Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ipswitch_collaboration_suite">
        <vers prev="1" num="8.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0708" published="2005-05-02" name="CVE-2005-0708" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="dragonflybsd" name="dragonflybsd">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0709" published="2005-05-02" name="CVE-2005-0709" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0009/" source="TRUSTIX" patch="1">2005-0009</ref>
      <ref url="http://www.securityfocus.com/bid/12781" source="BID" patch="1">12781</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_mysql.html" source="SUSE" patch="1">SUSE-SA:2005:019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-19.xml" source="GENTOO" patch="1">GLSA-200503-19</ref>
      <ref url="http://www.debian.org/security/2005/dsa-707" source="DEBIAN" patch="1">DSA-707</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-96-1" source="UBUNTU">USN-96-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-348.html" source="REDHAT">RHSA-2005:348</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-334.html" source="REDHAT">RHSA-2005:334</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:060" source="MANDRAKE">MDKSA-2005:060</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1" source="SUNALERT">101864</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10479" source="OVAL">oval:org.mitre.oval:def:10479</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066115808506&amp;w=2" source="BUGTRAQ">20050310 Mysql CREATE FUNCTION libc arbitrary code execution.</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0084.html" source="VULNWATCH">20050310 Mysql CREATE FUNCTION libc arbitrary code execution.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23.49" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.18" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.21" />
        <vers num="4.0.23" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
        <vers num="4.1.10" />
        <vers num="4.1.2" edition="alpha" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0710" published="2005-05-02" name="CVE-2005-0710" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12781" source="BID" patch="1">12781</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_mysql.html" source="SUSE" patch="1">SUSE-SA:2005:019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-19.xml" source="GENTOO" patch="1">GLSA-200503-19</ref>
      <ref url="http://www.debian.org/security/2005/dsa-707" source="DEBIAN" patch="1">DSA-707</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19658" source="XF">mysql-udfinit-gain-access(19658)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-96-1" source="UBUNTU">USN-96-1</ref>
      <ref url="http://www.trustix.org/errata/2005/0009/" source="TRUSTIX">2005-0009</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-348.html" source="REDHAT">RHSA-2005:348</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-334.html" source="REDHAT">RHSA-2005:334</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10180" source="OVAL">oval:org.mitre.oval:def:10180</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065974004648&amp;w=2" source="BUGTRAQ">20050310 Mysql CREATE FUNCTION mysql.func table arbitrary library injection</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0083.html" source="VULNWATCH">20050310 Mysql CREATE FUNCTION mysql.func table arbitrary library injection</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:060" source="MANDRAKE">MDKSA-2005:060</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1" source="SUNALERT">101864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23.49" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.18" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.21" />
        <vers num="4.0.23" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
        <vers num="4.1.10" />
        <vers num="4.1.2" edition="alpha" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0711" published="2005-05-02" name="CVE-2005-0711" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0009/" source="TRUSTIX" patch="1">2005-0009</ref>
      <ref url="http://www.securityfocus.com/bid/12781" source="BID" patch="1">12781</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-334.html" source="REDHAT" patch="1">RHSA-2005:334</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_mysql.html" source="SUSE" patch="1">SUSE-SA:2005:019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-19.xml" source="GENTOO" patch="1">GLSA-200503-19</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-96-1" source="UBUNTU">USN-96-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-348.html" source="REDHAT">RHSA-2005:348</ref>
      <ref url="http://www.debian.org/security/2005/dsa-707" source="DEBIAN">DSA-707</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9591" source="OVAL">oval:org.mitre.oval:def:9591</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0082.html" source="VULNWATCH">20050310 Mysql insecure temporary file creation with CREATE TEMPORARY TABLE privilege escalation</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:060" source="MANDRAKE">MDKSA-2005:060</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1" source="SUNALERT">101864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23.49" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.18" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.21" />
        <vers num="4.0.23" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
        <vers num="4.1.10" />
        <vers num="4.1.2" edition="alpha" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0712" published="2005-05-02" name="CVE-2005-0712" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE">APPLE-SA-2005-03-21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.1" />
        <vers num="10.2" />
        <vers num="10.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0713" published="2005-03-21" name="CVE-2005-0713" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-03-21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0714" reject="1" published="2005-05-02" name="CVE-2005-0714" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0340.  Reason: This candidate is a reservation duplicate of CVE-2005-0340.  Notes: All CVE users should reference CVE-2005-0340 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0715" published="2005-03-21" name="CVE-2005-0715" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local users to read the contents of a Drop Box.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-03-21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0716" published="2005-03-21" name="CVE-2005-0716" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=219&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050321 Mac OS X CF_CHARSET_PATH Buffer Overflow Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://www.securityfocus.com/bid/13224" source="BID">13224</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0718" published="2005-04-14" name="CVE-2005-0718" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.uk.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-post" source="CONFIRM" adv="1">http://www1.uk.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-post</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-111-1" source="UBUNTU">USN-111-1</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1224" source="CONFIRM" adv="1">http://www.squid-cache.org/bugs/show_bug.cgi?id=1224</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-415.html" source="REDHAT">RHSA-2005:415</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11562" source="OVAL">oval:org.mitre.oval:def:11562</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" adv="1">CLA-2005:931</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19919" source="XF">squid-put-post-dos(19919)</ref>
      <ref url="http://www.securityfocus.com/bid/13166" source="BID">13166</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-489.html" source="REDHAT">RHSA-2005:489</ref>
      <ref url="http://secunia.com/advisories/12508" source="SECUNIA">12508</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0.patch1" />
        <vers num="2.0.patch2" />
        <vers num="2.0.pre1" />
        <vers num="2.0.release" />
        <vers num="2.0_patch2" />
        <vers num="2.1.patch1" />
        <vers num="2.1.patch2" />
        <vers num="2.1.pre1" />
        <vers num="2.1.pre3" />
        <vers num="2.1.pre4" />
        <vers num="2.1.release" />
        <vers num="2.1_patch2" />
        <vers num="2.2.devel3" />
        <vers num="2.2.devel4" />
        <vers num="2.2.pre1" />
        <vers num="2.2.pre2" />
        <vers num="2.2.stable1" />
        <vers num="2.2.stable2" />
        <vers num="2.2.stable3" />
        <vers num="2.2.stable4" />
        <vers num="2.2.stable5" />
        <vers num="2.3.devel2" />
        <vers num="2.3.devel3" />
        <vers num="2.3.stable1" />
        <vers num="2.3.stable2" />
        <vers num="2.3.stable3" />
        <vers num="2.3.stable4" />
        <vers num="2.3.stable5" />
        <vers num="2.3_.stable4" />
        <vers num="2.3_.stable5" />
        <vers num="2.3_stable5" />
        <vers num="2.4" />
        <vers num="2.4.stable1" />
        <vers num="2.4.stable2" />
        <vers num="2.4.stable3" />
        <vers num="2.4.stable4" />
        <vers num="2.4.stable6" />
        <vers num="2.4.stable7" />
        <vers num="2.4_.stable2" />
        <vers num="2.4_.stable6" />
        <vers num="2.4_.stable7" />
        <vers num="2.4_stable7" />
        <vers num="2.5.6" />
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
        <vers num="2.5_stable9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0719" published="2005-03-09" name="CVE-2005-0719" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the systems message queue in HP Tru64 Unix 4.0F PK8 through 5.1B-2/PK4 allows local users to cause a denial of service (process crash) for processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and xntpd.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19642" source="XF" patch="1" adv="1">tru64-system-message-dos(19642)</ref>
      <ref url="http://www.securityfocus.com/bid/12768" source="BID" patch="1" adv="1">12768</ref>
      <ref url="http://secunia.com/advisories/14549/" source="SECUNIA" patch="1" adv="1">14549</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040492127482&amp;w=2" source="HP" patch="1" adv="1">HPSBTU01109</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040492127482&amp;w=2" source="HP">HPSBTU01109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="tru64">
        <vers num="4.0f" edition="pk8" />
        <vers num="4.0g" edition="pk4" />
        <vers num="5.1a" edition="pk6" />
        <vers num="5.1b1" edition="pk3" />
        <vers num="5.1b1" edition="pk4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0720" published="2005-03-08" name="CVE-2005-0720" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19616" source="XF" adv="1">mcnews-skinfile-file-include(19616)</ref>
      <ref url="http://www.securityfocus.com/bid/12776" source="BID">12776</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/476277/100/0/threaded" source="BUGTRAQ">20070811 mcNews (skinfile) Remote File Include Vulnerability</ref>
      <ref url="http://secunia.com/advisories/14528" source="SECUNIA" adv="1">14528</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111025679324892&amp;w=2" source="BUGTRAQ" adv="1">20050307 PHP mcNews &lt;= 1.3 arbitrary file inclusion (VXSfx)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcnews" name="mcnews">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0721" published="2005-05-02" name="CVE-2005-0721" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in modules.php in eXPerience2 allows remote attackers to execute arbitrary PHP code by modifying the file parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111030766324600&amp;w=2" source="BUGTRAQ">20050307 Multiples Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamearena" name="experience2">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0722" published="2005-03-07" name="CVE-2005-0722" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111030766324600&amp;w=2" source="BUGTRAQ" adv="1">20050307 Multiples Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="experience2" name="experience2">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0723" published="2005-03-08" name="CVE-2005-0723" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using pafiledb.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031801802851&amp;w=2" source="BUGTRAQ" adv="1">20050308 Multiple vulnerabilities in paFileDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0724" published="2005-05-02" name="CVE-2005-0724" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or (12) admin.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031801802851&amp;w=2" source="BUGTRAQ" patch="1">20050308 Multiple vulnerabilities in paFileDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0725" published="2005-03-08" name="CVE-2005-0725" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19660" source="XF" adv="1">wfsections-wfsfiles-sql-injection(19660)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111049618519821&amp;w=2" source="BUGTRAQ" adv="1">20050308 Wfsection 1.07 vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wf-sections" name="wf-sections">
        <vers num="1.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0726" published="2005-05-02" name="CVE-2005-0726" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111056135818279&amp;w=2" source="BUGTRAQ">20050311 UBB.threads 6 SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0727" reject="1" published="2005-05-02" name="CVE-2005-0727" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0735.  Reason: This candidate is a duplicate of CVE-2005-0735.  Notes: All CVE users should reference CVE-2005-0727 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2005-0728" reject="1" published="2005-05-02" name="CVE-2005-0728" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0736.  Reason: This candidate is a duplicate of CVE-2005-0736.  Notes: All CVE users should reference CVE-2005-0736 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-0729" published="2005-05-02" name="CVE-2005-0729" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Xpand Rally 1.1.0.0 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19649" source="XF">xpandrally-message-format-string(19649)</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5DP0G00F5Q.html" source="MISC">http://www.securiteam.com/windowsntfocus/5DP0G00F5Q.html</ref>
      <ref url="http://secunia.com/advisories/14545" source="SECUNIA" adv="1">14545</ref>
      <ref url="http://aluigi.altervista.org/adv/xprallyfs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/xprallyfs-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="techland" name="xpand_rally">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0730" published="2005-05-02" name="CVE-2005-0730" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service via a request to a file on the floppy drive, as demonstrated using A:\a.txt.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19647" source="XF">active-webcam-dos(19647)</ref>
      <ref url="http://secway.org/advisory/ad20050104.txt" source="MISC">http://secway.org/advisory/ad20050104.txt</ref>
      <ref url="http://secunia.com/advisories/14553" source="SECUNIA">14553</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html" source="FULLDISC">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="py_software" name="active_webcam">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0731" published="2005-03-10" name="CVE-2005-0731" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Filelist.html.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19650" source="XF" adv="1">active-webcam-filelist-dos(19650)</ref>
      <ref url="http://secway.org/advisory/ad20050104.txt" source="MISC" adv="1">http://secway.org/advisory/ad20050104.txt</ref>
      <ref url="http://secunia.com/advisories/14553" source="SECUNIA" adv="1">14553</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html" source="FULLDISC" adv="1">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="py_software" name="active_webcam">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0732" published="2005-05-02" name="CVE-2005-0732" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to obtain the full path of the web server via a request for a non-existent filename, which leaks the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19652" source="XF">active-webcam-path-disclosure(19652)</ref>
      <ref url="http://secway.org/advisory/ad20050104.txt" source="MISC">http://secway.org/advisory/ad20050104.txt</ref>
      <ref url="http://secunia.com/advisories/14553" source="SECUNIA">14553</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html" source="FULLDISC">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="py_software" name="active_webcam">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0733" published="2005-05-02" name="CVE-2005-0733" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to determine the existence of files via an HTTP request with a full pathname, which produces different messages whether the file exists or not.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19654" source="XF">active-webcam-file-disclosure(19654)</ref>
      <ref url="http://secway.org/advisory/ad20050104.txt" source="MISC">http://secway.org/advisory/ad20050104.txt</ref>
      <ref url="http://secunia.com/advisories/14553" source="SECUNIA">14553</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html" source="FULLDISC">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="py_software" name="active_webcam">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0734" published="2005-05-02" name="CVE-2005-0734" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19653" source="XF">active-webcam-memory-dos(19653)</ref>
      <ref url="http://secway.org/advisory/ad20050104.txt" source="MISC">http://secway.org/advisory/ad20050104.txt</ref>
      <ref url="http://secunia.com/advisories/14553" source="SECUNIA">14553</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html" source="FULLDISC">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="py_software" name="active_webcam">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0735" published="2005-05-02" name="CVE-2005-0735" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12761" source="BID">12761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newsscript.co.uk" name="newsscript">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0736" published="2005-03-09" name="CVE-2005-0736" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12763" source="BID" patch="1" adv="1">12763</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032314.html" source="FULLDISC" patch="1" adv="1">20050309 overwriting low kernel memory</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1" source="UBUNTU">USN-95-1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9870" source="OVAL">oval:org.mitre.oval:def:9870</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@422dd06a1p5PsyFhoGAJseinjEq3ew?nav=index.html%7CChangeSet@-1d" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@422dd06a1p5PsyFhoGAJseinjEq3ew?nav=index.html|ChangeSet@-1d</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0737" published="2005-05-02" name="CVE-2005-0737" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12750" source="BID">12750</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Mar/0284.html" source="FULLDISC">20050308 Yahoo! Messenger Offline Mode Status Remote Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.0.1046" />
        <vers num="5.0.1065" />
        <vers num="5.0.1232" />
        <vers num="5.5" />
        <vers num="5.5.1249" />
        <vers num="5.6" />
        <vers num="5.6.0.1347" />
        <vers num="5.6.0.1351" />
        <vers num="5.6.0.1355" />
        <vers num="5.6.0.1356" />
        <vers num="5.6.0.1358" />
        <vers num="6.0" />
        <vers num="6.0.0.1643" />
        <vers num="6.0.0.1750" />
        <vers num="6.0.0.1921" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0738" published="2005-05-02" name="CVE-2005-0738" modified="2008-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/?kbid=891504" source="MSKB" patch="1">891504</ref>
      <ref url="http://secunia.com/advisories/14543" source="SECUNIA" adv="1">14543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2003" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0739" published="2005-05-02" name="CVE-2005-0739" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00018.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref>
      <ref url="http://www.debian.org/security/2005/dsa-718" source="DEBIAN" patch="1">DSA-718</ref>
      <ref url="http://www.securityfocus.com/bid/12762" source="BID">12762</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-306.html" source="REDHAT">RHSA-2005:306</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053" source="MANDRAKE">MDKSA-2005:053</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml" source="GENTOO">GLSA-200503-16</ref>
      <ref url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-03-05" source="MISC">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-03-05</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9687" source="OVAL">oval:org.mitre.oval:def:9687</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066805726551&amp;w=2" source="BUGTRAQ">20050312 Ethereal remote buffer overflow #2</ref>
      <ref url="http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&amp;rev=13707" source="MISC">http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&amp;rev=13707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0740" published="2005-01-13" name="CVE-2005-0740" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12250" source="BID" patch="1" adv="1">12250</ref>
      <ref url="http://www.openbsd.org/errata35.html" source="OPENBSD" patch="1" adv="1">20050111 027: RELIABILITY FIX: January 11, 2005</ref>
      <ref url="http://securitytracker.com/id?1012861" source="SECTRACK" patch="1" adv="1">1012861</ref>
      <ref url="http://secunia.com/advisories/13819" source="SECUNIA">13819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0741" published="2005-03-08" name="CVE-2005-0741" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12756" source="BID" patch="1" adv="1">12756</ref>
      <ref url="http://securitytracker.com/id?1013420" source="SECTRACK" adv="1">1013420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="2.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0742" published="2005-05-02" name="CVE-2005-0742" modified="2010-03-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57742-1" source="SUNALERT" patch="1">57742</ref>
      <ref url="http://www.securityfocus.com/bid/12775" source="BID">12775</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200314-1" source="SUNALERT">200314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_application_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":platform" />
        <vers num="7.0" edition="ur1" />
        <vers num="7.0" edition="ur1:enterprise" />
        <vers num="7.0" edition="ur1:standard" />
        <vers num="7.0" edition="ur4" />
        <vers num="7.0" edition="ur5" />
        <vers num="7.0" edition="ur5:standard" />
        <vers num="7.0" edition="ur5:platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0743" published="2005-05-02" name="CVE-2005-0743" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xoops.org/modules/news/article.php?storyid=2114" source="CONFIRM" patch="1">http://www.xoops.org/modules/news/article.php?storyid=2114</ref>
      <ref url="http://www.securityfocus.com/bid/12754" source="BID" patch="1">12754</ref>
      <ref url="http://www.securityfocus.com/archive/1/392626" source="BUGTRAQ" patch="1">20050308 [SCAN Associates Security Advisory] xoops 2.0.9.2 and below weak file extension validation</ref>
      <ref url="http://secunia.com/advisories/14520" source="SECUNIA" patch="1" adv="1">14520</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19634" source="XF">xoops-uploader-file-upload(19634)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops">
        <vers num="1.0_rc1" />
        <vers num="1.0_rc3" />
        <vers num="1.0_rc3.0.5" />
        <vers num="1.3.10" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.5" />
        <vers num="2.0.5.1" />
        <vers num="2.0.5.2" />
        <vers num="2.0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0744" published="2005-05-02" name="CVE-2005-0744" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication cookie from the browser.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096885.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096885.htm</ref>
      <ref url="http://secunia.com/advisories/14527" source="SECUNIA" patch="1" adv="1">14527</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19646" source="XF" adv="1">ichain-gain-access(19646)</ref>
      <ref url="http://securitytracker.com/id?1013406" source="SECTRACK">1013406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="ichain">
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0745" published="2005-03-09" name="CVE-2005-0745" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14544" source="SECUNIA" adv="1">14544</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Mar/0168.html" source="BUGTRAQ" adv="1">20050307 Re: Lingo VoIP ATA / UTStarcom iAN-02EX remote access vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="utstarcom" name="ian-02ex_voip_ata">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0746" published="2005-05-02" name="CVE-2005-0746" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19643" source="XF">ichain-path-disclosure(19643)</ref>
      <ref url="http://www.securityfocus.com/bid/12766" source="BID">12766</ref>
      <ref url="http://www.infobyte.com.ar/adv/ISR-03.html" source="MISC">http://www.infobyte.com.ar/adv/ISR-03.html</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm</ref>
      <ref url="http://securitytracker.com/id?1013407" source="SECTRACK">1013407</ref>
      <ref url="http://secunia.com/advisories/14537" source="SECUNIA">14537</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091102023359&amp;w=2" source="BUGTRAQ" adv="1">20050315 [ISR] - Novell iChain Mini FTP Server Unauthorized Remote Path Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="ichain">
        <vers num="2.2" edition="sp1" />
        <vers num="2.2" edition="sp1a" />
        <vers num="2.2" edition="sp2" />
        <vers num="2.2" edition="sp3" />
        <vers num="2.2.113" />
        <vers num="2.3" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0747" published="2005-03-08" name="CVE-2005-0747" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ApplyYourself i-Class allows remote attackers to obtain sensitive information about their own applications by reusing the hidden ID field, as demonstrated using the id parameter to ApplicantDecision.asp.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013400" source="SECTRACK" patch="1" adv="1">1013400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="applyyourself" name="i-class">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0748" published="2005-03-10" name="CVE-2005-0748" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14550" source="SECUNIA" patch="1" adv="1">14550</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19651" source="XF" adv="1">webinsta-initdb-file-include(19651)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0248" source="VUPEN" adv="1">ADV-2005-0248</ref>
      <ref url="http://www.securityfocus.com/bid/12773" source="BID" adv="1">12773</ref>
      <ref url="http://securitytracker.com/id?1013409" source="SECTRACK" adv="1">1013409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webinsta" name="webinsta_mailing_manager">
        <vers num="1.3d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0749" published="2005-04-01" name="CVE-2005-0749" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14713/" source="SECUNIA" patch="1" adv="1">14713</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19867" source="XF" adv="1">kernel-loadelflibrary-dos(19867)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-103-1" source="UBUNTU">USN-103-1</ref>
      <ref url="http://www.securityfocus.com/bid/12935" source="BID">12935</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-551.html" source="REDHAT">RHSA-2005:551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-529.html" source="REDHAT">RHSA-2005:529</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10640" source="OVAL">oval:org.mitre.oval:def:10640</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6" source="CONFIRM" adv="1">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.24" />
        <vers num="2.0.25" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
        <vers num="2.0.29" />
        <vers num="2.0.3" />
        <vers num="2.0.30" />
        <vers num="2.0.31" />
        <vers num="2.0.32" />
        <vers num="2.0.33" />
        <vers num="2.0.34" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.0.9.9" />
        <vers num="2.1" />
        <vers num="2.1.89" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.27" edition="rc2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.99" edition="pre1" />
        <vers num="2.3.99" edition="pre2" />
        <vers num="2.3.99" edition="pre3" />
        <vers num="2.3.99" edition="pre4" />
        <vers num="2.3.99" edition="pre5" />
        <vers num="2.3.99" edition="pre6" />
        <vers num="2.3.99" edition="pre7" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" edition="pre3" />
        <vers num="2.4.30" edition="rc2" />
        <vers num="2.4.30" edition="rc3" />
        <vers num="2.4.31" edition="pre1" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers prev="1" num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0750" published="2005-03-27" name="CVE-2005-0750" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19844" source="XF" patch="1" adv="1">kernel-bluezsockcreate-integer-underflow(19844)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" patch="1" adv="1">RHSA-2005:284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-283.html" source="REDHAT" patch="1" adv="1">RHSA-2005:283</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11719" source="OVAL">oval:org.mitre.oval:def:11719</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111204562102633&amp;w=2" source="BUGTRAQ" adv="1">20050327 local root security bug in linux >= 2.4.6 &lt;= 2.4.30-rc1 and 2.6.x.y &lt;= 2.6.11.5</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032913.html" source="FULLDISC" adv="1">20050327 local root security bug in linux >= 2.4.6 &lt;= 2.4.30-rc1 and 2.6.x.y &lt;= 2.6.11.5</ref>
      <ref url="http://www.securityfocus.com/bid/12911" source="BID">12911</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.20" />
        <vers num="2.4.21" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.24" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" />
        <vers num="2.4.28" />
        <vers num="2.4.29" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="9.3" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0751" reject="1" published="2005-06-09" name="CVE-2005-0751" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-0752" published="2005-04-18" name="CVE-2005-0752" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-34.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-34.html</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10279" source="OVAL">oval:org.mitre.oval:def:10279</ref>
      <ref url="http://www.securityfocus.com/bid/13228" source="BID">13228</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100024" source="OVAL" sig="1">oval:org.mitre.oval:def:100024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0753" published="2005-04-18" name="CVE-2005-0753" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20148" source="XF" patch="1" adv="1">cvs-bo(20148)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-387.html" source="REDHAT" patch="1" adv="1">RHSA-2005:387</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_24_cvs.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:024</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-16.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-16</ref>
      <ref url="http://secunia.com/advisories/14976/" source="SECUNIA" patch="1" adv="1">14976</ref>
      <ref url="http://www.debian.org/security/2005/dsa-742" source="DEBIAN">DSA-742</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9688" source="OVAL">oval:org.mitre.oval:def:9688</ref>
      <ref url="http://bugs.gentoo.org/attachment.cgi?id=54352&amp;action=view" source="MISC" adv="1">http://bugs.gentoo.org/attachment.cgi?id=54352&amp;action=view</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10" />
        <vers num="1.10.6" />
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0754" published="2005-04-22" name="CVE-2005-0754" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13313" source="BID" patch="1" adv="1">13313</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050420-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050420-1.txt</ref>
      <ref url="http://secunia.com/advisories/15060" source="SECUNIA" patch="1" adv="1">15060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111419664411051&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050422 [KDE Security Advisory]: Kommander untrusted code execution</ref>
      <ref url="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.0-kdewebdev-kommander.diff" source="CONFIRM" adv="1">ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.0-kdewebdev-kommander.diff</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="quanta">
        <vers num="3.1" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.4" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
        <vers num="5.04" edition="" />
        <vers num="5.04" edition=":i386" />
        <vers num="5.04" edition=":amd64" />
        <vers num="5.04" edition=":powerpc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0755" published="2005-04-19" name="CVE-2005-0755" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-392.html" source="REDHAT" patch="1" adv="1">RHSA-2005:392</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-363.html" source="REDHAT" patch="1" adv="1">RHSA-2005:363</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-April/msg00040.html" source="FEDORA" patch="1" adv="1">FEDORA-2005-329</ref>
      <ref url="http://service.real.com/help/faq/security/050419_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/050419_player/EN/</ref>
      <ref url="http://pb.specialised.info/all/adv/real-ram-adv.txt" source="MISC" patch="1" adv="1">http://pb.specialised.info/all/adv/real-ram-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401615202987&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050420 RealNetworks RealPlayer/RealOne Player/Helix Player Remote Heap Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-394.html" source="REDHAT">RHSA-2005:394</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11205" source="OVAL">oval:org.mitre.oval:def:11205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_player">
        <vers prev="1" num="10.0.3" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":german" />
        <vers num="10.0" edition=":" />
        <vers num="10.0" edition="::english" />
        <vers num="10.0" edition="::japanese" />
        <vers num="10.0_6.0.12.690" />
        <vers num="10.0_beta" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":win32" />
        <vers num="8.0" edition=":mac_os" />
        <vers num="8.0" edition=":unix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0756" published="2005-06-08" name="CVE-2005-0756" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ptrace in Linux kernel 2.6.8.1 does not properly verify addresses on the amd64 platform, which allows local users to cause a denial of service (kernel crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN" adv="1">ADV-2005-1878</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-137-1" source="UBUNTU">USN-137-1</ref>
      <ref url="http://www.securityfocus.com/bid/13891" source="BID">13891</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded" source="FEDORA">FLSA:157459-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://www.debian.org/security/2005/dsa-921" source="DEBIAN">DSA-921</ref>
      <ref url="http://secunia.com/advisories/18059" source="SECUNIA" adv="1">18059</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA" adv="1">18056</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA" adv="1">17073</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA" adv="1">17002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11119" source="OVAL">oval:org.mitre.oval:def:11119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0757" published="2005-05-18" name="CVE-2005-0757" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not properly handle certain offsets, which allows local users to cause a denial of service (system crash) via certain actions on an ext3 file system with extended attributes enabled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-294.html" source="REDHAT" patch="1" adv="1">RHSA-2005:294</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11406" source="OVAL">oval:org.mitre.oval:def:11406</ref>
      <ref url="http://www.securityfocus.com/bid/13680" source="BID">13680</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://www.debian.org/security/2005/dsa-921" source="DEBIAN">DSA-921</ref>
      <ref url="http://secunia.com/advisories/18059" source="SECUNIA">18059</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0758" published="2005-05-13" name="CVE-2005-0758" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200505-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200505-05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20539" source="XF">gzip-zgrep-file-installation(20539)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.ubuntu.com/usn/usn-158-1" source="UBUNTU">USN-158-1</ref>
      <ref url="http://www.securityfocus.com/bid/13582" source="BID">13582</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-474.html" source="REDHAT">RHSA-2005:474</ref>
      <ref url="http://www.osvdb.org/16371" source="OSVDB">16371</ref>
      <ref url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html" source="FEDORA">FLSA:158801</ref>
      <ref url="http://securitytracker.com/id?1013928" source="SECTRACK">1013928</ref>
      <ref url="http://secunia.com/advisories/19183" source="SECUNIA">19183</ref>
      <ref url="http://secunia.com/advisories/18100" source="SECUNIA">18100</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-357.html" source="REDHAT">RHSA-2005:357</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9797" source="OVAL">oval:org.mitre.oval:def:9797</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=90626" source="MISC" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=90626</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc" source="SGI">20060301-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt" source="SCO">SCOSA-2005.58</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.html" source="OPENPKG">OpenPKG-SA-2007.002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:027" source="MANDRIVA">MDKSA-2006:027</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:026" source="MANDRIVA">MDKSA-2006:026</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.555852" source="SLACKWARE">SSA:2006-262</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://secunia.com/advisories/22033" source="SECUNIA">22033</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1107" source="OVAL" sig="1">oval:org.mitre.oval:def:1107</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1081" source="OVAL" sig="1">oval:org.mitre.oval:def:1081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gzip">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0759" published="2005-03-23" name="CVE-2005-0759" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ImageMagick before 6.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image with an invalid tag.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2005-070.html" source="REDHAT" patch="1" adv="1">RHSA-2005:070</ref>
      <ref url="http://www.securityfocus.com/bid/12875" source="BID" patch="1" adv="1">12875</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:017</ref>
      <ref url="http://www.debian.org/security/2005/dsa-702" source="DEBIAN" patch="1" adv="1">DSA-702</ref>
      <ref url="http://securitytracker.com/id?1013550" source="SECTRACK" patch="1" adv="1">1013550</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11022" source="OVAL">oval:org.mitre.oval:def:11022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.4" />
        <vers num="5.5.6" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0760" published="2005-05-02" name="CVE-2005-0760" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TIFF decoder in ImageMagick before 6.0 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2005-070.html" source="REDHAT" patch="1">RHSA-2005:070</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html" source="SUSE" patch="1">SUSE-SA:2005:017</ref>
      <ref url="http://www.debian.org/security/2005/dsa-702" source="DEBIAN" patch="1">DSA-702</ref>
      <ref url="http://securitytracker.com/id?1013550" source="SECTRACK">1013550</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11184" source="OVAL">oval:org.mitre.oval:def:11184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.4" />
        <vers num="5.5.6" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0761" published="2005-03-23" name="CVE-2005-0761" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ImageMagick before 6.1.8 allows remote attackers to cause a denial of service (application crash) via a crafted PSD file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12876" source="BID" patch="1" adv="1">12876</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:017</ref>
      <ref url="http://securitytracker.com/id?1013550" source="SECTRACK" patch="1" adv="1">1013550</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-070.html" source="REDHAT" patch="1" adv="1">RHSA-2005:070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11150" source="OVAL">oval:org.mitre.oval:def:11150</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.4" />
        <vers num="5.5.6" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.2.5" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.1" />
        <vers num="6.1.1.6" />
        <vers num="6.1.2" />
        <vers num="6.1.3" />
        <vers num="6.1.4" />
        <vers num="6.1.5" />
        <vers num="6.1.6" />
        <vers num="6.1.7" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0762" published="2005-05-02" name="CVE-2005-0762" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html" source="SUSE" patch="1">SUSE-SA:2005:017</ref>
      <ref url="http://www.debian.org/security/2005/dsa-702" source="DEBIAN" patch="1">DSA-702</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-070.html" source="REDHAT" patch="1">RHSA-2005:070</ref>
      <ref url="http://securitytracker.com/id?1013550" source="SECTRACK">1013550</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9736" source="OVAL">oval:org.mitre.oval:def:9736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.4" />
        <vers num="5.5.6" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
        <vers num="6.0" />
        <vers num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0763" published="2005-05-02" name="CVE-2005-0763" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-698" source="DEBIAN" patch="1" adv="1">DSA-698</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-512.html" source="REDHAT">RHSA-2005:512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers prev="1" num="4.5.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0764" published="2005-05-02" name="CVE-2005-0764" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-23.xml" source="GENTOO" patch="1">GLSA-200503-23</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=84680" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=84680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="marc_lehmann" name="rxvt-unicode">
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.7" />
        <vers num="3.8" />
        <vers num="3.9" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0765" published="2005-03-12" name="CVE-2005-0765" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the JXTA dissector in Ethereal 0.10.9 allows remote attackers to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-16</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00018.html" source="CONFIRM" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10048" source="OVAL">oval:org.mitre.oval:def:10048</ref>
      <ref url="http://www.securityfocus.com/bid/12762" source="BID">12762</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053" source="MANDRAKE">MDKSA-2005:053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0766" published="2005-05-02" name="CVE-2005-0766" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00018.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml" source="GENTOO">GLSA-200503-16</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9866" source="OVAL">oval:org.mitre.oval:def:9866</ref>
      <ref url="http://www.securityfocus.com/bid/12762" source="BID">12762</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053" source="MANDRAKE">MDKSA-2005:053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0767" published="2005-03-15" name="CVE-2005-0767" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the Radeon DRI driver for Linux kernel 2.6.8.1 allows local users with DRI privileges to execute arbitrary code as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1" source="UBUNTU">USN-95-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10431" source="OVAL">oval:org.mitre.oval:def:10431</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945" source="CONECTIVA" adv="1">CLA-2005:945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0768" published="2005-05-02" name="CVE-2005-0768" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://unsecure.altervista.org/security/goodtechtelnet.htm" source="MISC">http://unsecure.altervista.org/security/goodtechtelnet.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111092012415193&amp;w=2" source="BUGTRAQ" adv="1">20050315 GoodTech Telnet Server Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goodtech_systems" name="goodtech_telnet_server">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows_nt" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0769" published="2005-05-02" name="CVE-2005-0769" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12792" source="BID" patch="1" adv="1">12792</ref>
      <ref url="http://secunia.com/advisories/14561" source="SECUNIA" patch="1" adv="1">14561</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19683" source="XF" adv="1">openslp-slp-bo(19683)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3879" source="VUPEN">ADV-2006-3879</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-98-1" source="UBUNTU">USN-98-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447537/100/0/threaded" source="HP">SSRT061149</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_15_openslp.html" source="SUSE">SUSE-SA:2005:015</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-25.xml" source="GENTOO">GLSA-200503-25</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447537/100/0/threaded" source="HP">SSRT061149</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:055" source="MANDRAKE">MDKSA-2005:055</ref>
      <ref url="http://secunia.com/advisories/22128" source="SECUNIA">22128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openslp" name="openslp">
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8_a" />
        <vers num="1.0.9_a" />
        <vers num="1.0_.0" />
        <vers num="1.1.5" />
        <vers num="1.2.1" />
        <vers num="1.2_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0770" published="2005-05-02" name="CVE-2005-0770" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in DataRescue Interactive Disassembler and Debugger (IDA) Pro 4.7.0.830 allows remote attackers or local users to cause a denial of service (CPU consumption or application crash) and possibly execute arbitrary code via format string specifiers in a dynamic link library (DLL) name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14610" source="SECUNIA" patch="1" adv="1">14610</ref>
      <ref url="http://www.datarescue.com/cgi-local/ultimatebb.cgi?ubb=get_topic;f=2;t=000155;p=0" source="CONFIRM">http://www.datarescue.com/cgi-local/ultimatebb.cgi?ubb=get_topic;f=2;t=000155;p=0</ref>
      <ref url="http://pb.specialised.info/all/adv/ida-debugger-adv.txt" source="MISC">http://pb.specialised.info/all/adv/ida-debugger-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100269512216&amp;w=2" source="BUGTRAQ">20050316 ADVISORY: DataRescue Interactive Disassembler Pro Debugger Format String Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datarescue" name="ida_pro">
        <vers num="4.7.0.830" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0771" published="2005-06-23" name="CVE-2005-0771" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP port 6106.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-180A.html" source="CERT" patch="1" adv="1">TA05-180A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/584505" source="CERT-VN" patch="1" adv="1">VU#584505</ref>
      <ref url="http://seer.support.veritas.com/docs/277429.htm" source="CONFIRM" patch="1">http://seer.support.veritas.com/docs/277429.htm</ref>
      <ref url="http://seer.support.veritas.com/docs/276605.htm" source="CONFIRM" patch="1" adv="1">http://seer.support.veritas.com/docs/276605.htm</ref>
      <ref url="http://securitytracker.com/id?1014273" source="SECTRACK" patch="1">1014273</ref>
      <ref url="http://secunia.com/advisories/15789" source="SECUNIA" patch="1" adv="1">15789</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=269&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20050623 Veritas Backup Exec Server Remote Registry Access Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="10.0_rev.5484" />
        <vers num="9.0_rev.4367" />
        <vers num="9.0_rev.4454" />
        <vers num="9.1_rev.4691" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0772" published="2005-06-28" name="CVE-2005-0772" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid (non-0) "Error Status" value, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=271&amp;type=vulnerabilities" source="IDEFENSE">20050623 Veritas Backup Exec Agent Error Status Remote DoS Vulnerability</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=270&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20050623 Veritas Backup Exec Remote Agent NDMLSRVR.DLL DoS Vulnerability</ref>
      <ref url="http://seer.support.veritas.com/docs/277485.htm" source="CONFIRM">http://seer.support.veritas.com/docs/277485.htm</ref>
      <ref url="http://seer.support.veritas.com/docs/276533.htm" source="CONFIRM">http://seer.support.veritas.com/docs/276533.htm</ref>
      <ref url="http://securitytracker.com/id?1014273" source="SECTRACK">1014273</ref>
      <ref url="http://secunia.com/advisories/15789" source="SECUNIA">15789</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="10.0" />
        <vers num="10.0_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0773" published="2005-06-18" name="CVE-2005-0773" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-180A.html" source="CERT" patch="1" adv="1">TA05-180A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/492105" source="CERT-VN" patch="1" adv="1">VU#492105</ref>
      <ref url="http://www.securityfocus.com/bid/14022" source="BID" patch="1">14022</ref>
      <ref url="http://seer.support.veritas.com/docs/277429.htm" source="CONFIRM" patch="1">http://seer.support.veritas.com/docs/277429.htm</ref>
      <ref url="http://seer.support.veritas.com/docs/276604.htm" source="CONFIRM" patch="1" adv="1">http://seer.support.veritas.com/docs/276604.htm</ref>
      <ref url="http://securitytracker.com/id?1014273" source="SECTRACK" patch="1">1014273</ref>
      <ref url="http://secunia.com/advisories/15789" source="SECUNIA" patch="1" adv="1">15789</ref>
      <ref url="http://www.osvdb.org/17624" source="OSVDB">17624</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=272&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20050623 Veritas Backup Exec Agent CONNECT_CLIENT_AUTH Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="10.0_rev.5484" />
        <vers num="10.0_rev.5484_sp1" />
        <vers num="9.0.4019" />
        <vers num="9.0.4170" />
        <vers num="9.0.4172" />
        <vers num="9.0.4174" />
        <vers num="9.0.4202" />
        <vers num="9.0_rev.4367" />
        <vers num="9.0_rev.4367_sp1" />
        <vers num="9.0_rev.4454" />
        <vers num="9.0_rev.4454_sp1" />
        <vers num="9.1.1067.2" />
        <vers num="9.1.1067.3" />
        <vers num="9.1.1127.1" />
        <vers num="9.1.1151.1" />
        <vers num="9.1.1152" />
        <vers num="9.1.1152.4" />
        <vers num="9.1.1154" />
        <vers num="9.1.306" />
        <vers num="9.1.307" />
        <vers num="9.1_rev.4691" />
        <vers num="9.1_rev.4691_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0774" published="2005-03-10" name="CVE-2005-0774" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in member.php and possibly other scripts in PhotoPost PHP 5.0 RC3 allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19675" source="XF" patch="1" adv="1">photopost-uid-sql-injection(19675)</ref>
      <ref url="http://secunia.com/advisories/14576" source="SECUNIA" patch="1" adv="1">14576</ref>
      <ref url="http://www.securityfocus.com/bid/12779" source="BID" adv="1">12779</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2" source="BUGTRAQ" adv="1">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="5.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0775" published="2005-05-02" name="CVE-2005-0775" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The reportpost action in misc.php for PhotoPost PHP 5.0 RC3 does not limit the logging data that is sent to the administrator, which allows remote attackers to send large amounts of email to the admistrator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2" source="BUGTRAQ" patch="1">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19676" source="XF" adv="1">photopost-email-security-bypass(19676)</ref>
      <ref url="http://www.securityfocus.com/bid/12779" source="BID">12779</ref>
      <ref url="http://secunia.com/advisories/14576" source="SECUNIA">14576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="5.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0776" published="2005-05-02" name="CVE-2005-0776" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users' photos.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2" source="BUGTRAQ" patch="1">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19677" source="XF">photopost-image-modification(19677)</ref>
      <ref url="http://www.securityfocus.com/bid/12779" source="BID">12779</ref>
      <ref url="http://secunia.com/advisories/14576" source="SECUNIA">14576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="5.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0777" published="2005-05-02" name="CVE-2005-0777" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP 5.0 RC3 allow remote attackers to inject arbitrary web script or HTML via (1) the check_tags function or (2) the editbio field in the user profile.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19678" source="XF" adv="1">photopost-editbio-xss(19678)</ref>
      <ref url="http://www.securityfocus.com/bid/12779" source="BID">12779</ref>
      <ref url="http://secunia.com/advisories/14576" source="SECUNIA">14576</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2" source="BUGTRAQ">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="5.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0778" published="2005-05-02" name="CVE-2005-0778" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19679" source="XF" adv="1">photopost-file-upload(19679)</ref>
      <ref url="http://www.securityfocus.com/bid/12779" source="BID">12779</ref>
      <ref url="http://secunia.com/advisories/14576" source="SECUNIA">14576</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2" source="BUGTRAQ">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="5.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0779" published="2005-05-02" name="CVE-2005-0779" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19674" source="XF">platinumftp-username-dos(19674)</ref>
      <ref url="http://www.securityfocus.com/bid/12790" source="BID">12790</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066232415249&amp;w=2" source="BUGTRAQ">20050312 PlatinumFTP 1.0.18 remote DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455609/100/0/threaded" source="BUGTRAQ">20070101 Re: PlatinumFTP 1.0.18 remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platinumftp" name="platinumftpserver">
        <vers num="1.0.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0780" published="2005-03-12" name="CVE-2005-0780" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066293914977&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050312 [SECURITYREASON.COM]  Mass Full Path Disclosure in paFileDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="1.1.3" />
        <vers num="2.1.1" />
        <vers num="3.0" />
        <vers num="3.0_beta_3.1" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0781" published="2005-05-02" name="CVE-2005-0781" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19688" source="XF">pafiledb-viewall-category-sql-injection(19688)</ref>
      <ref url="http://www.securityfocus.com/bid/12788" source="BID">12788</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065796525043&amp;w=2" source="BUGTRAQ">20050312 [SECURITYREASON.COM]  SQL injection and XSS in paFileDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="1.1.3" />
        <vers num="2.1.1" />
        <vers num="3.0" />
        <vers num="3.0_beta_3.1" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0782" published="2005-05-02" name="CVE-2005-0782" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19690" source="XF">pafiledb-viewall-category-xss(19690)</ref>
      <ref url="http://www.securityfocus.com/bid/12788" source="BID">12788</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111221940107161&amp;w=2" source="BUGTRAQ">20050330 PaFileDB Version 3.1 and below are exploitable via a XSS and a SQL injection vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065796525043&amp;w=2" source="BUGTRAQ">20050312 [SECURITYREASON.COM]  SQL injection and XSS in paFileDB</ref>
      <ref url="http://digitalparadox.org/advisories/pafdb.txt" source="MISC">http://digitalparadox.org/advisories/pafdb.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="1.1.3" />
        <vers num="2.1.1" />
        <vers num="3.0" />
        <vers num="3.0_beta_3.1" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0783" published="2005-05-02" name="CVE-2005-0783" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14554" source="SECUNIA" patch="1">14554</ref>
      <ref url="http://www.securityfocus.com/bid/12800" source="BID">12800</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083279031544&amp;w=2" source="BUGTRAQ">20050313 3 XSS Vulnerabilities in Phorum &lt;= 5.0.14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="5.0.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0784" published="2005-05-02" name="CVE-2005-0784" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14554" source="SECUNIA" patch="1">14554</ref>
      <ref url="http://www.securityfocus.com/bid/12800" source="BID">12800</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083279031544&amp;w=2" source="BUGTRAQ">20050313 3 XSS Vulnerabilities in Phorum &lt;= 5.0.14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="5.0.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0785" published="2005-05-02" name="CVE-2005-0785" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12756" source="BID" patch="1">12756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19671" source="XF" adv="1">yabb-usersrecentposts-xss(19671)</ref>
      <ref url="http://securitytracker.com/id?1013420" source="SECTRACK">1013420</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083400601759&amp;w=2" source="BUGTRAQ">20050313 YaBB2 rc1 XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="2.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0786" published="2005-03-14" name="CVE-2005-0786" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12801" source="BID" patch="1" adv="1">12801</ref>
      <ref url="http://secunia.com/advisories/14583" source="SECUNIA" patch="1" adv="1">14583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082702422979&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050313 SimpGB SQL Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19694" source="XF" adv="1">simpgb-gbnew-sql-injection(19694)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simpgb" name="simpgb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0787" published="2005-05-02" name="CVE-2005-0787" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Wine 20050211 and earlier creates temp files with world readable permissions and predictable file names, which allows local users to obtain sensitive information, such as passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zone-h.org/advisories/read/id=7300" source="MISC" patch="1">http://www.zone-h.org/advisories/read/id=7300</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082537009842&amp;w=2" source="BUGTRAQ" patch="1">20050314 [ZH2005-02SA] Insecure tmp file creation in Wine</ref>
      <ref url="http://bugs.winehq.org/show_bug.cgi?id=2715" source="MISC" patch="1">http://bugs.winehq.org/show_bug.cgi?id=2715</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19697" source="XF">wine-registry-information-disclosure(19697)</ref>
      <ref url="http://www.securityfocus.com/bid/12791" source="BID">12791</ref>
      <ref url="http://securitytracker.com/id?1013428" source="SECTRACK">1013428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wine" name="wine">
        <vers num="2005-02-11" />
        <vers num="2005-03-05" />
        <vers num="2005-03-10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0788" published="2005-03-14" name="CVE-2005-0788" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19693" source="XF" patch="1" adv="1">limewire-client-information-disclosure(19693)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-37</ref>
      <ref url="http://secunia.com/advisories/14555/" source="SECUNIA" patch="1" adv="1">14555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082448213238&amp;w=2" source="BUGTRAQ" adv="1">20050314 LimeWire Gnutella client two vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="limewire" name="limewire">
        <vers num="4.1.2" />
        <vers num="4.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0789" published="2005-03-14" name="CVE-2005-0789" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19695" source="XF" patch="1" adv="1">limewire-magnet-directory-traversal(19695)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-37</ref>
      <ref url="http://secunia.com/advisories/14555/" source="SECUNIA" patch="1" adv="1">14555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082448213238&amp;w=2" source="BUGTRAQ" adv="1">20050314 LimeWire Gnutella client two vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="limewire" name="limewire">
        <vers num="3.9.6" />
        <vers num="4.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0790" published="2005-03-14" name="CVE-2005-0790" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7) remotehtmlview.php, (8) click.php, (9) adcontent.php, which reveal the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc" source="MISC" adv="1">http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083286926490&amp;w=2" source="BUGTRAQ" adv="1">20050314 [SECURITYREASON.COM] phpAdsNew 2.0.4-pr1 Multiple vulnerabilities cXIb8O3.9</ref>
      <ref url="http://securitytracker.com/id?1013429" source="SECTRACK">1013429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpadsnew" name="phpadsnew">
        <vers num="2.0.4_pr1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0791" published="2005-03-14" name="CVE-2005-0791" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12803" source="BID" patch="1" adv="1">12803</ref>
      <ref url="http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc" source="MISC" patch="1" adv="1">http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc</ref>
      <ref url="http://secunia.com/advisories/14592" source="SECUNIA" patch="1" adv="1">14592</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083286926490&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050314 [SECURITYREASON.COM] phpAdsNew 2.0.4-pr1 Multiple vulnerabilities cXIb8O3.9</ref>
      <ref url="http://www.osvdb.org/14787" source="OSVDB">14787</ref>
      <ref url="http://securitytracker.com/id?1013429" source="SECTRACK">1013429</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0792" published="2005-03-15" name="CVE-2005-0792" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14602" source="SECUNIA" patch="1" adv="1">14602</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19709" source="XF" adv="1">zpanel-index-sql-injection(19709)</ref>
      <ref url="http://www.securityfocus.com/bid/12809" source="BID" adv="1">12809</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2" source="BUGTRAQ" adv="1">20050320 Re: Few remote bugs in zPanel</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2" source="BUGTRAQ" adv="1">20050315 Few remote bugs in zPanel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zpanel" name="zpanel">
        <vers num="2.0" />
        <vers num="2.5_beta" />
        <vers num="2.5_beta10" />
        <vers num="2.5_beta9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0793" published="2005-03-15" name="CVE-2005-0793" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12809" source="BID" adv="1">12809</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2" source="BUGTRAQ" adv="1">20050320 Re: Few remote bugs in zPanel</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2" source="BUGTRAQ" adv="1">20050315 Few remote bugs in zPanel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zpanel" name="zpanel">
        <vers num="2.0" />
        <vers num="2.5_beta" />
        <vers num="2.5_beta10" />
        <vers num="2.5_beta9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0794" published="2005-03-15" name="CVE-2005-0794" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14602" source="SECUNIA" patch="1" adv="1">14602</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2" source="BUGTRAQ" adv="1">20050320 Re: Few remote bugs in zPanel</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2" source="BUGTRAQ" adv="1">20050315 Few remote bugs in zPanel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zpanel" name="zpanel">
        <vers num="2.0" />
        <vers num="2.5_beta10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0795" published="2005-03-14" name="CVE-2005-0795" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.holacms.de/?content=changelog" source="CONFIRM" patch="1" adv="1">http://www.holacms.de/?content=changelog</ref>
      <ref url="http://secunia.com/advisories/14566" source="SECUNIA" patch="1" adv="1">14566</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0210.html" source="BUGTRAQ" adv="1">20050315 Virginity Security Advisory 2005-001 : Hola CMS - File destruction and System access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hola" name="holacms">
        <vers num="1.2.10" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.2a" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.4.9_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0796" published="2005-05-02" name="CVE-2005-0796" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14566" source="SECUNIA" patch="1">14566</ref>
      <ref url="http://www.holacms.de/?content=changelog" source="CONFIRM">http://www.holacms.de/?content=changelog</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090966815089&amp;w=2" source="BUGTRAQ">20050315 Virginity Security Advisory 2005-002 : Hola CMS - Another File destruction and System access</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0797" published="2005-03-15" name="CVE-2005-0797" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12811" source="BID" adv="1">12811</ref>
      <ref url="http://www.infobyte.com.ar/adv/ISR-04.html" source="MISC" adv="1">http://www.infobyte.com.ar/adv/ISR-04.html</ref>
      <ref url="http://secunia.com/advisories/14607" source="SECUNIA" adv="1">14607</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091027000721&amp;w=2" source="BUGTRAQ" adv="1">20050315 [ISR] - Novell iChain Mini FTP Server Valid User Disclosure Vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0798" published="2005-03-15" name="CVE-2005-0798" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.infobyte.com.ar/adv/ISR-05.html" source="MISC" adv="1">http://www.infobyte.com.ar/adv/ISR-05.html</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096887.htm" source="CONFIRM" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096887.htm</ref>
      <ref url="http://secunia.com/advisories/14607" source="SECUNIA" adv="1">14607</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091517007681&amp;w=2" source="BUGTRAQ" adv="1">20050315 [ISR] - Novell iChain Mini FTP Server Bruteforce Problem</ref>
      <ref url="http://www.osvdb.org/14648" source="OSVDB">14648</ref>
      <ref url="http://securitytracker.com/id?1013408" source="SECTRACK">1013408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="ichain">
        <vers num="2.2" edition="sp1" />
        <vers num="2.2" edition="sp1a" />
        <vers num="2.2" edition="sp2" />
        <vers num="2.2" edition="sp3" />
        <vers num="2.2.113" />
        <vers num="2.3" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0799" published="2005-03-15" name="CVE-2005-0799" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14564" source="SECUNIA" adv="1">14564</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091250923281&amp;w=2" source="BUGTRAQ">20050315 Denial of Service Vulnerability in MySQL Server for Windows</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=9148" source="CONFIRM" adv="1">http://bugs.mysql.com/bug.php?id=9148</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0800" published="2005-05-02" name="CVE-2005-0800" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111108900102438&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050317 PHP mcNews arbitrary file inclusion</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19726" source="XF" adv="1">mcnews-install-file-include(19726)</ref>
      <ref url="http://www.securityfocus.com/bid/12835" source="BID">12835</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/445606/100/0/threaded" source="BUGTRAQ">20060906 mcNews v1.3 - Remote File Include</ref>
      <ref url="http://secunia.com/advisories/14528" source="SECUNIA">14528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcnews" name="mcnews">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0801" published="2005-05-02" name="CVE-2005-0801" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in includer.cgi in The Includer allows remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) a full pathname in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111109052121557&amp;w=2" source="BUGTRAQ" adv="1">20050317 Another includer.cgi problem?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="includer.cgi" name="includer.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0802" published="2005-05-02" name="CVE-2005-0802" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19728" source="XF">acs-blog-search-xss(19728)</ref>
      <ref url="http://www.securityfocus.com/bid/12836" source="BID">12836</ref>
      <ref url="http://securitytracker.com/id?1013470" source="SECTRACK">1013470</ref>
      <ref url="http://secunia.com/advisories/14625/" source="SECUNIA">14625</ref>
      <ref url="http://www.osvdb.org/14861" source="OSVDB">14861</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111108840811698&amp;w=2" source="BUGTRAQ">20050317 XSS in ACS blog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp_press" name="acs_blog">
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0803" published="2005-05-02" name="CVE-2005-0803" modified="2011-07-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-312A.html" source="CERT">TA05-312A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/134756" source="CERT-VN">VU#134756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19727" source="XF">win-2000-gdi32dll-dos(19727)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2348" source="VUPEN" adv="1">ADV-2005-2348</ref>
      <ref url="http://www.securityfocus.com/bid/12834" source="BID">12834</ref>
      <ref url="http://www.osvdb.org/20580" source="OSVDB">20580</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS05-053.mspx" source="MS">MS05-053</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf</ref>
      <ref url="http://securitytracker.com/id?1015168" source="SECTRACK">1015168</ref>
      <ref url="http://secunia.com/advisories/17461" source="SECUNIA" adv="1">17461</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA" adv="1">17223</ref>
      <ref url="http://secunia.com/advisories/14631" source="SECUNIA">14631</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111108743527497&amp;w=2" source="BUGTRAQ">20050317 Windows 2000 GDI32.DLL GetEnhMetaFilePaletteEntries() API specially crafted EMF file DOS vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:671" source="OVAL" sig="1">oval:org.mitre.oval:def:671</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1240" source="OVAL" sig="1">oval:org.mitre.oval:def:1240</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1215" source="OVAL" sig="1">oval:org.mitre.oval:def:1215</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1152" source="OVAL" sig="1">oval:org.mitre.oval:def:1152</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1121" source="OVAL" sig="1">oval:org.mitre.oval:def:1121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0804" published="2005-05-02" name="CVE-2005-0804" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14627" source="SECUNIA" patch="1">14627</ref>
      <ref url="http://www.securityfocus.com/bid/12833" source="BID">12833</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111108519331738&amp;w=2" source="BUGTRAQ">20050317 See-security Advisory: Format string vulnerability in MailEnable 1.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_standard">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0805" published="2005-05-02" name="CVE-2005-0805" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly handled by imagegallery.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12839" source="BID" patch="1">12839</ref>
      <ref url="http://www.subdreamer.com/forum/showthread.php?t=2501" source="CONFIRM">http://www.subdreamer.com/forum/showthread.php?t=2501</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437983/100/200/threaded" source="BUGTRAQ">20060621 Re: possible SQL injection in Subdreamer</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111116479910230&amp;w=2" source="BUGTRAQ">20050318 possible SQL injection in Subdreamer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="subdreamer" name="subdreamer_light">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0806" published="2005-05-02" name="CVE-2005-0806" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-397.html" source="REDHAT">RHSA-2005:397</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10532" source="OVAL">oval:org.mitre.oval:def:10532</ref>
      <ref url="http://bugzilla.ximian.com/show_bug.cgi?id=72609" source="CONFIRM">http://bugzilla.ximian.com/show_bug.cgi?id=72609</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-166-1" source="UBUNTU">USN-166-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:059" source="MANDRAKE">MDKSA-2005:059</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0807" published="2005-05-02" name="CVE-2005-0807" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Cain &amp; Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID field that is not properly handled by the PSK sniffer filter, (2) the HTTP sniffer filter, or the (3) POP3, (4) SMTP, (5) IMAP, (6) NNTP, or (7) TDS sniffer filters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14630" source="SECUNIA" patch="1">14630</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19744" source="XF">cain-abel-http-filter-bo(19744)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19742" source="XF">cain-abel-ikepsk-bo(19742)</ref>
      <ref url="http://www.securityfocus.com/bid/12840" source="BID">12840</ref>
      <ref url="http://www.oxid.it/" source="CONFIRM">http://www.oxid.it/</ref>
      <ref url="http://securitytracker.com/id?1013476" source="SECTRACK">1013476</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111116097313427&amp;w=2" source="BUGTRAQ">20050318 Cain &amp; Abel PSK Sniffer Heap overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oxid" name="cain_and_abel">
        <vers num="2.5" />
        <vers num="2.5_beta21" />
        <vers num="2.5_beta29" />
        <vers num="2.5_beta34" />
        <vers num="2.5_beta36" />
        <vers num="2.5_beta40" />
        <vers num="2.5_beta41" />
        <vers num="2.5_beta47" />
        <vers num="2.5_beta51" />
        <vers num="2.5_beta56" />
        <vers num="2.5_beta59" />
        <vers num="2.5_beta65" />
        <vers num="2.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0808" published="2005-05-02" name="CVE-2005-0808" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6A2LEF" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/JGEI-6A2LEF</ref>
      <ref url="http://www.kb.cert.org/vuls/id/204710" source="CERT-VN" adv="1">VU#204710</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19681" source="XF">tomcat-manager-ajp12-dos(19681)</ref>
      <ref url="http://www.securityfocus.com/bid/12795" source="BID">12795</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS05-006_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS05-006_e/index-e.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" edition="beta2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0809" published="2005-05-02" name="CVE-2005-0809" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/581068" source="CERT-VN" adv="1">VU#581068</ref>
      <ref url="http://www.securityfocus.com/bid/12843" source="BID">12843</ref>
      <ref url="http://secunia.com/advisories/14617" source="SECUNIA">14617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="notify_technology" name="notifylink">
        <vers num="enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0810" published="2005-05-02" name="CVE-2005-0810" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in NotifyLink before 3.0 allows remote attackers to execute arbitrary SQL commands via the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/264097" source="CERT-VN" adv="1">VU#264097</ref>
      <ref url="http://www.securityfocus.com/bid/12843" source="BID">12843</ref>
      <ref url="http://secunia.com/advisories/14617" source="SECUNIA">14617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="notify_technology" name="notifylink">
        <vers num="enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0811" published="2005-05-02" name="CVE-2005-0811" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a direct request to certain URLs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/131828" source="CERT-VN" adv="1">VU#131828</ref>
      <ref url="http://www.securityfocus.com/bid/12843" source="BID">12843</ref>
      <ref url="http://secunia.com/advisories/14617" source="SECUNIA">14617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="notify_technology" name="notifylink">
        <vers num="enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0812" published="2005-05-02" name="CVE-2005-0812" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web interface in NotifyLink 3.0 displays passwords in cleartext on the administrative page, which could allow remote attackers or local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/770532" source="CERT-VN" adv="1">VU#770532</ref>
      <ref url="http://www.securityfocus.com/bid/12843" source="BID">12843</ref>
      <ref url="http://secunia.com/advisories/14617" source="SECUNIA">14617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="notify_technology" name="notifylink">
        <vers num="enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0813" published="2005-05-02" name="CVE-2005-0813" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12827" source="BID" patch="1">12827</ref>
      <ref url="http://secunia.com/advisories/13674" source="SECUNIA" patch="1">13674</ref>
      <ref url="http://www.vanheusden.com/ir/" source="CONFIRM">http://www.vanheusden.com/ir/</ref>
      <ref url="http://www.osvdb.org/14832" source="OSVDB">14832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="initial_redirect" name="initial_redirect_squid_proxy_plug-in">
        <vers num="0.1" />
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0814" published="2005-05-02" name="CVE-2005-0814" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in lshd in Lysator LSH 1.x and 2.x before 2.0.1 allows remote attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-717" source="DEBIAN" patch="1">DSA-717</ref>
      <ref url="http://secunia.com/advisories/14609" source="SECUNIA" patch="1">14609</ref>
      <ref url="http://lists.lysator.liu.se/pipermail/lsh-bugs/2005q1/000328.html" source="MLIST" patch="1" adv="1">[lsh-bugs] 20050316 ANNOUNCE: LSH-2.0.1, fix for denial of service bug</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19724" source="XF">lsh-lshd-dos(19724)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lysator" name="lsh">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0815" published="2005-05-02" name="CVE-2005-0815" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19741" source="XF">kernel-iso9660-filesystem(19741)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.securityfocus.com/bid/12837" source="BID">12837</ref>
      <ref url="http://www.securityfocus.com/archive/1/393590" source="BUGTRAQ">20050317 Linux ISO9660 handling flaws</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9307" source="OVAL">oval:org.mitre.oval:def:9307</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.12-rc1" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.12-rc1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0191.html" source="REDHAT">RHSA-2006:0191</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0190.html" source="REDHAT">RHSA-2006:0190</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:072" source="MANDRIVA">MDKSA-2006:072</ref>
      <ref url="http://secunia.com/advisories/18684" source="SECUNIA">18684</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.24" />
        <vers num="2.0.25" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
        <vers num="2.0.29" />
        <vers num="2.0.3" />
        <vers num="2.0.30" />
        <vers num="2.0.31" />
        <vers num="2.0.32" />
        <vers num="2.0.33" />
        <vers num="2.0.34" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.0.9.9" />
        <vers num="2.1" />
        <vers num="2.1.89" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.27" edition="rc2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.99" edition="pre1" />
        <vers num="2.3.99" edition="pre2" />
        <vers num="2.3.99" edition="pre3" />
        <vers num="2.3.99" edition="pre4" />
        <vers num="2.3.99" edition="pre5" />
        <vers num="2.3.99" edition="pre6" />
        <vers num="2.3.99" edition="pre7" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" edition="pre3" />
        <vers num="2.4.30" edition="rc2" />
        <vers num="2.4.30" edition="rc3" />
        <vers num="2.4.31" edition="pre1" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0816" published="2005-05-02" name="CVE-2005-0816" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19729" source="XF">solaris-newgrp-bo(19729)</ref>
      <ref url="http://www.securityfocus.com/bid/12838" source="BID">12838</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57710-1" source="SUNALERT" adv="1">57710</ref>
      <ref url="http://securitytracker.com/id?1013462" source="SECTRACK">1013462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0817" published="2005-05-02" name="CVE-2005-0817" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/44530" source="XF">symantec-dnsdproxy-redirect(44530)</ref>
      <ref url="http://www.isc.sans.org/diary.php?date=2005-03-04" source="MISC">http://www.isc.sans.org/diary.php?date=2005-03-04</ref>
      <ref url="http://securitytracker.com/id?1013451" source="SECTRACK">1013451</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2005.03.15.html" source="CONFIRM" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2005.03.15.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0225.html" source="BUGTRAQ">20040615 Symantec Enterprise Firewall DNSD cache poisoning Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16423" source="XF">sef-dns-spoofing(16423)</ref>
      <ref url="http://secunia.com/advisories/14595" source="SECUNIA">14595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="enterprise_firewall">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="symantec" name="velociraptor">
        <vers num="model_1300" />
      </prod>
      <prod vendor="symantec" name="gateway_security_5300">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="gateway_security_5400">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0818" published="2005-05-02" name="CVE-2005-0818" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19725" source="XF">punbb-email-jabber-xss(19725)</ref>
      <ref url="http://securitytracker.com/id?1013446" source="SECTRACK">1013446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0819" published="2005-05-02" name="CVE-2005-0819" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12831" source="BID" patch="1">12831</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971038.htm" source="CONFIRM" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971038.htm</ref>
      <ref url="http://securitytracker.com/id?1013460" source="SECTRACK">1013460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="6.5" edition="sp2" />
        <vers num="6.5" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0820" published="2005-05-02" name="CVE-2005-0820" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/kb/867443" source="MSKB" adv="1">867443</ref>
      <ref url="http://www.securityfocus.com/bid/12824" source="BID">12824</ref>
      <ref url="http://www.osvdb.org/14882" source="OSVDB">14882</ref>
      <ref url="http://securitytracker.com/id?1013454" source="SECTRACK">1013454</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0821" published="2005-05-02" name="CVE-2005-0821" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12821" source="BID" patch="1">12821</ref>
      <ref url="http://support.citrix.com/kb/entry.jspa?externalID=CTX105574" source="CONFIRM" patch="1" adv="1">http://support.citrix.com/kb/entry.jspa?externalID=CTX105574</ref>
      <ref url="http://securitytracker.com/id?1013457" source="SECTRACK" patch="1">1013457</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19723" source="XF">metaframe-conferencing-gain-access(19723)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0822" published="2005-05-02" name="CVE-2005-0822" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.citrix.com/kb/entry.jspa?externalID=CTX105762" source="CONFIRM" patch="1" adv="1">http://support.citrix.com/kb/entry.jspa?externalID=CTX105762</ref>
      <ref url="http://support.citrix.com/kb/entry.jspa?entryID=5970&amp;categoryID=254" source="CONFIRM" adv="1">http://support.citrix.com/kb/entry.jspa?entryID=5970&amp;categoryID=254</ref>
      <ref url="http://www.securityfocus.com/bid/24041" source="BID">24041</ref>
      <ref url="http://support.citrix.com/article/CTX105800" source="CONFIRM">http://support.citrix.com/article/CTX105800</ref>
      <ref url="http://securitytracker.com/id?1018077" source="SECTRACK">1018077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe_password_manager">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0823" published="2005-05-02" name="CVE-2005-0823" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19718" source="XF">isnooker-mydetails-plaintext-password(19718)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19717" source="XF">ipool-mydetails-plaintext-password(19717)</ref>
      <ref url="http://www.securityfocus.com/bid/12830" source="BID">12830</ref>
      <ref url="http://securitytracker.com/id?1013459" source="SECTRACK">1013459</ref>
      <ref url="http://securitytracker.com/id?1013458" source="SECTRACK">1013458</ref>
      <ref url="http://secunia.com/advisories/14629" source="SECUNIA">14629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thepoolclub" name="ipool">
        <vers prev="1" num="1.6.81" />
      </prod>
      <prod vendor="thepoolclub" name="isnooker">
        <vers prev="1" num="1.6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0824" published="2005-05-02" name="CVE-2005-0824" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14524" source="SECUNIA" patch="1" adv="1">14524</ref>
      <ref url="http://www.mail-archive.com/mathopd%40mathopd.org/msg00272.html" source="CONFIRM">http://www.mail-archive.com/mathopd%40mathopd.org/msg00272.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mathopd" name="mathopd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0825" published="2005-05-02" name="CVE-2005-0825" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in LTris before 1.0.10 allows local users to execute arbitrary code via a crafted highscores file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-24.xml" source="GENTOO" patch="1">GLSA 200503-24</ref>
      <ref url="http://secunia.com/advisories/14635" source="SECUNIA" patch="1">14635</ref>
      <ref url="http://lgames.sourceforge.net/index.php?action=show_news&amp;news_action=show_item&amp;item_id=108" source="CONFIRM">http://lgames.sourceforge.net/index.php?action=show_news&amp;news_action=show_item&amp;item_id=108</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=85770" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=85770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lgames" name="ltris">
        <vers prev="1" num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0826" published="2005-05-02" name="CVE-2005-0826" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19750" source="XF">ollydbg-long-filename-do(19750)</ref>
      <ref url="http://www.securityfocus.com/bid/12850" source="BID">12850</ref>
      <ref url="http://securitytracker.com/id?1013478" source="SECTRACK">1013478</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111125734701262&amp;w=2" source="BUGTRAQ" adv="1">20050319 OllyDbg long process Module debug Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ollydbg" name="ollydbg">
        <vers num="1.06" />
        <vers num="1.08b" />
        <vers num="1.09" />
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0827" published="2005-05-02" name="CVE-2005-0827" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Viewcat.php in (1) RUNCMS 1.1A, (2) Ciamos 0.9.2 RC1, e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allow remote attackers to obtain sensitive information via an invalid parameter to the convertorderbytrans function, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14641" source="SECUNIA" patch="1">14641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19755" source="XF">ciamos-viewcat-path-disclosure(19755)</ref>
      <ref url="http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdf" source="MISC" adv="1">http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111125588920928&amp;w=2" source="BUGTRAQ">20050319 Ciamos Installation path(IHS)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117182417422&amp;w=2" source="BUGTRAQ">20050318 runcms installation path</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ciamos" name="ciamos">
        <vers num="0.9.2_rc1" />
      </prod>
      <prod vendor="e-xoops" name="e-xoops">
        <vers num="1.05_rev3" />
      </prod>
      <prod vendor="runcms" name="runcms">
        <vers num="1.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0828" published="2005-05-02" name="CVE-2005-0828" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14641" source="SECUNIA" patch="1" adv="1">14641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19754" source="XF">ciamos-file-information-disclosure(19754)</ref>
      <ref url="http://www.securityfocus.com/bid/12848" source="BID">12848</ref>
      <ref url="http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdf" source="MISC" adv="1">http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdf</ref>
      <ref url="http://www.ihsteam.com/download/advisory/Exoops%20highlight%20hole.txt" source="MISC">http://www.ihsteam.com/download/advisory/Exoops%20highlight%20hole.txt</ref>
      <ref url="http://secunia.com/advisories/14648" source="SECUNIA" adv="1">14648</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111125645312693&amp;w=2" source="BUGTRAQ">20050319 Ciamos Highlight.php Security Hole(IHS)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117241923006&amp;w=2" source="BUGTRAQ">20050318 runcms highlight.php hole</ref>
      <ref url="http://www.osvdb.org/14890" source="OSVDB">14890</ref>
      <ref url="http://securitytracker.com/id?1013485" source="SECTRACK">1013485</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ciamos" name="ciamos">
        <vers num="0.9.2_rc1" />
      </prod>
      <prod vendor="e-xoops" name="e-xoops">
        <vers num="1.05r3" />
      </prod>
      <prod vendor="runcms" name="runcms">
        <vers num="1.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0829" published="2005-05-02" name="CVE-2005-0829" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142918711745&amp;w=2" source="BUGTRAQ">20050319 Re: [PersianHacker.NET 200503-10]PHP-Fusion v5.01 Html Injection</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142752220155&amp;w=2" source="BUGTRAQ">20050319 Fw: [PersianHacker.NET 200503-10]PHP-Fusion v5.01 Html Injection    Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111125692513645&amp;w=2" source="BUGTRAQ">20050319 [PersianHacker.NET 200503-10]PHP-Fusion v5.01 Html Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0830" published="2005-05-02" name="CVE-2005-0830" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Xzabite DYNDNSUpdate 0.6.15 and earlier, including the ipcheck function in dyndnsupdate.c, allow remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-27.xml" source="GENTOO" adv="1">GLSA-200503-27</ref>
      <ref url="http://secunia.com/advisories/14663" source="SECUNIA" adv="1">14663</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=84659" source="MISC" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=84659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xzabite" name="dyndnsupdate">
        <vers num="0.6.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0831" published="2005-05-02" name="CVE-2005-0831" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12845" source="BID" patch="1">12845</ref>
      <ref url="http://www.securityfocus.com/archive/1/393695" source="BUGTRAQ">20050318 PHP-Post Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-post" name="php-post_web_forum">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.3" />
        <vers num="0.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0832" published="2005-05-02" name="CVE-2005-0832" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12845" source="BID">12845</ref>
      <ref url="http://www.php-post.co.uk/index.php?s=content&amp;p=download" source="CONFIRM">http://www.php-post.co.uk/index.php?s=content&amp;p=download</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-post" name="php-post_web_forum">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.3" />
        <vers num="0.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0833" published="2005-05-02" name="CVE-2005-0833" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12846" source="BID">12846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="belkin" name="belkin_54g_wireless_router">
        <vers num="f5d7130" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0834" published="2005-05-02" name="CVE-2005-0834" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Belkin 54G (F5D7130) wireless router enables SNMP by default in a manner that allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12846" source="BID">12846</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0835" published="2005-05-02" name="CVE-2005-0835" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12846" source="BID">12846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="belkin" name="54g_wireless_router">
        <vers num="f5d7130" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0836" published="2005-05-02" name="CVE-2005-0836" modified="2010-05-29" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12847" source="BID" patch="1">12847</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-28.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-28</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000200.1-1" source="SUNALERT">1000200</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200255-1" source="SUNALERT">200255</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57740-1" source="SUNALERT">57740</ref>
      <ref url="http://secunia.com/advisories/14640" source="SECUNIA" adv="1">14640</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111117284323657&amp;w=2" source="FULLDISC" adv="1">20050318 Java Web Start argument injection vulnerability</ref>
      <ref url="http://jouko.iki.fi/adv/ws.html" source="MISC">http://jouko.iki.fi/adv/ws.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_32_java2.html" source="SUSE">SUSE-SA:2005:032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="j2se">
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":sdk" />
        <vers num="1.4.2_01" edition="" />
        <vers num="1.4.2_01" edition=":sdk" />
        <vers num="1.4.2_02" edition="" />
        <vers num="1.4.2_02" edition=":sdk" />
        <vers num="1.4.2_03" edition="" />
        <vers num="1.4.2_03" edition=":sdk" />
        <vers num="1.4.2_04" edition="" />
        <vers num="1.4.2_04" edition=":sdk" />
        <vers num="1.4.2_05" edition="" />
        <vers num="1.4.2_05" edition=":sdk" />
        <vers num="1.4.2_06" edition="" />
        <vers num="1.4.2_06" edition=":sdk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0837" published="2005-05-02" name="CVE-2005-0837" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19760" source="XF">icecast-get-bypass-security(19760)</ref>
      <ref url="http://www.securityfocus.com/bid/12849" source="BID">12849</ref>
      <ref url="http://www.securityfocus.com/archive/1/393705" source="BUGTRAQ">20050318 IceCast up to v2.20 multiple vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1013475" source="SECTRACK">1013475</ref>
      <ref url="http://secunia.com/advisories/14644" source="SECUNIA" adv="1">14644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icecast" name="icecast">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0838" published="2005-05-02" name="CVE-2005-0838" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a long test value in an xsl:if tag, or (3) a long select value in an xsl:value-of tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19753" source="XF">icecast-xsl-gain-pivileges(19753)</ref>
      <ref url="http://www.securityfocus.com/bid/12849" source="BID">12849</ref>
      <ref url="http://www.securityfocus.com/archive/1/393705" source="BUGTRAQ">20050318 IceCast up to v2.20 multiple vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1013475" source="SECTRACK">1013475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icecast" name="icecast">
        <vers num="2.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0839" published="2005-05-02" name="CVE-2005-0839" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.mail-archive.com/linux-kernel@vger.kernel.org/msg64704.html" source="MLIST" adv="1">[linux-kernel] 20050301 Re: Breakage from patch: Only root should be able to set the N_MOUSE line discipline.</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9460" source="OVAL">oval:org.mitre.oval:def:9460</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41fa6464E1UuGu6zmketEYxm73KSyQ" source="MISC">http://linux.bkbits.net:8080/linux-2.6/cset@41fa6464E1UuGu6zmketEYxm73KSyQ</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0840" reject="1" published="2005-05-02" name="CVE-2005-0840" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0706.  Reason: This candidate is a duplicate of CVE-2005-0706.  Notes: All CVE users should reference CVE-2005-0706 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-0841" published="2005-05-02" name="CVE-2005-0841" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attackers to execute arbitrary SQL commands, as demonstrated via (1) the person parameter to people.php or (2) the Login field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14642" source="SECUNIA" patch="1" adv="1">14642</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19787" source="XF">phpmyfamily-multiple-scripts-sql-injection(19787)</ref>
      <ref url="http://www.securityfocus.com/bid/12860" source="BID">12860</ref>
      <ref url="http://securitytracker.com/id?1013493" source="SECTRACK">1013493</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111143649730845&amp;w=2" source="BUGTRAQ" adv="1">20050321 phpMyFamily 1.4.0 SQL vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyfamily" name="phpmyfamily">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0842" published="2005-05-02" name="CVE-2005-0842" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13563" source="SECUNIA">13563</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111151292704335&amp;w=2" source="BUGTRAQ">20050322 Kayako eSupport Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="esupport">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0843" published="2005-05-02" name="CVE-2005-0843" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14680" source="SECUNIA" patch="1" adv="1">14680</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111151651621097&amp;w=2" source="BUGTRAQ">20050322 [ Positive Technologies #SA] Phorum "location" HTTP Response</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="5.0.14a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0844" published="2005-05-02" name="CVE-2005-0844" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19791" source="XF">nortel-contivity-information-disclosure(19791)</ref>
      <ref url="http://www.nta-monitor.com/news/vpn-flaws/nortel/nortel-client/" source="MISC" adv="1">http://www.nta-monitor.com/news/vpn-flaws/nortel/nortel-client/</ref>
      <ref url="http://securitytracker.com/id?1013512" source="SECTRACK" adv="1">1013512</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111151589203707&amp;w=2" source="BUGTRAQ" adv="1">20050322 Nortel VPN Client Issue: Clear-text password stored in memory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="contivity">
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0845" published="2005-05-02" name="CVE-2005-0845" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14658" source="SECUNIA" patch="1" adv="1">14658</ref>
      <ref url="http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&amp;group=netwin.surgemail&amp;item=8814&amp;utag=" source="CONFIRM" patch="1">http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&amp;group=netwin.surgemail&amp;item=8814&amp;utag=</ref>
      <ref url="http://www.security.org.sg/vuln/surgemail22g3.html" source="MISC">http://www.security.org.sg/vuln/surgemail22g3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111159967417903&amp;w=2" source="BUGTRAQ" adv="1">20050323 [SIG^2 G-TEC] SurgeMail Webmail Attachment Upload and XSS</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0846" published="2005-05-02" name="CVE-2005-0846" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14658" source="SECUNIA" patch="1" adv="1">14658</ref>
      <ref url="http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&amp;group=netwin.surgemail&amp;item=8814&amp;utag=" source="CONFIRM" patch="1">http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&amp;group=netwin.surgemail&amp;item=8814&amp;utag=</ref>
      <ref url="http://www.security.org.sg/vuln/surgemail22g3.html" source="MISC">http://www.security.org.sg/vuln/surgemail22g3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111159967417903&amp;w=2" source="BUGTRAQ" adv="1">20050323 [SIG^2 G-TEC] SurgeMail Webmail Attachment Upload and XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="surgemail">
        <vers num="2.2g3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0847" published="2005-05-02" name="CVE-2005-0847" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19777" source="XF" patch="1">ocean-ftp-connection-dos(19777)</ref>
      <ref url="http://www.securityfocus.com/bid/12859" source="BID" patch="1">12859</ref>
      <ref url="http://secunia.com/advisories/14662" source="SECUNIA" patch="1" adv="1">14662</ref>
      <ref url="http://milw0rm.com/exploits/893" source="MILW0RM">893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="code_ocean" name="ocean_ftp_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0848" published="2005-05-02" name="CVE-2005-0848" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has arrived using the socket ioctl.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19762" source="XF">funlabs-games-upd-dos(19762)</ref>
      <ref url="http://securitytracker.com/id?1013492" source="SECTRACK" adv="1">1013492</ref>
      <ref url="http://secunia.com/advisories/14638" source="SECUNIA" adv="1">14638</ref>
      <ref url="http://aluigi.altervista.org/adv/funlabsboom-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/funlabsboom-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="funlabs" name="4x4_off-road_adventure_iii">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="cabelas_big_game_hunter_2004_season">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="cabelas_big_game_hunter_2005">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="cabelas_dangerous_hunts">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="cabelas_deer_hunt_2005_season">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="revolution">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="secret_service_in_harms_way">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="shadow_force_razor_unit">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="us_most_wanted_nowhere_to_hide">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0849" published="2005-05-02" name="CVE-2005-0849" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that cause the server to copy more memory than was actually provided in the packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013492" source="SECTRACK" adv="1">1013492</ref>
      <ref url="http://secunia.com/advisories/14638" source="SECUNIA" adv="1">14638</ref>
      <ref url="http://aluigi.altervista.org/adv/funlabsboom-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/funlabsboom-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="funlabs" name="4x4_off-road_adventure_iii">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="cabelas_big_game_hunter_2004_season">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="cabelas_big_game_hunter_2005">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="cabelas_dangerous_hunts">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="cabelas_deer_hunt_2005_season">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="revolution">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="secret_service_in_harms_way">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="shadow_force_razor_unit">
        <vers num="" />
      </prod>
      <prod vendor="funlabs" name="us_most_wanted_nowhere_to_hide">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0850" published="2005-05-02" name="CVE-2005-0850" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12865" source="BID" patch="1">12865</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=21558&amp;release_id=314473" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=21558&amp;release_id=314473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filezilla" name="filezilla_server">
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6a" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1b" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4d" />
        <vers num="0.9.4e" />
        <vers num="0.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0851" published="2005-05-02" name="CVE-2005-0851" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12865" source="BID" patch="1">12865</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=21558&amp;release_id=314473" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=21558&amp;release_id=314473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filezilla" name="filezilla_server">
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6a" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1b" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4d" />
        <vers num="0.9.4e" />
        <vers num="0.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0852" published="2005-05-02" name="CVE-2005-0852" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12870" source="BID">12870</ref>
      <ref url="http://www.securityfocus.com/archive/1/393956" source="BUGTRAQ">20050322 Possible windows+python bug</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0853" published="2005-05-02" name="CVE-2005-0853" modified="2009-02-06" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later.  NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19779" source="XF" patch="1">betaparticle-web-root-information-disclosure(19779)</ref>
      <ref url="http://secunia.com/advisories/14668" source="SECUNIA" patch="1" adv="1">14668</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47419" source="XF">bpblog-blog-info-disclosure(47419)</ref>
      <ref url="http://www.securityfocus.com/bid/12861" source="BID">12861</ref>
      <ref url="http://www.milw0rm.com/exploits/7499" source="MILW0RM">7499</ref>
      <ref url="http://secunia.com/advisories/33233" source="SECUNIA">33233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="betaparticle" name="betaparticle_blog">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0854" published="2005-05-02" name="CVE-2005-0854" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19781" source="XF" patch="1">betaparticle-blog-authentication-bypass(19781)</ref>
      <ref url="http://secunia.com/advisories/14668" source="SECUNIA" patch="1" adv="1">14668</ref>
      <ref url="http://www.securityfocus.com/bid/12861" source="BID">12861</ref>
      <ref url="http://blog.betaparticle.com/template_permalink.asp?id=68" source="CONFIRM">http://blog.betaparticle.com/template_permalink.asp?id=68</ref>
    </refs>
    <vuln_soft>
      <prod vendor="betaparticle" name="betaparticle_blog">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0855" published="2005-05-02" name="CVE-2005-0855" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full pathname in a PHP error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013474" source="SECTRACK" patch="1">1013474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolforum" name="coolforum">
        <vers prev="1" num="0.8.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0856" published="2005-05-02" name="CVE-2005-0856" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013474" source="SECTRACK" patch="1">1013474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolforum" name="coolforum">
        <vers prev="1" num="0.8.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0857" published="2005-05-02" name="CVE-2005-0857" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19758" source="XF" patch="1">coolforum-avatar-xss(19758)</ref>
      <ref url="http://securitytracker.com/id?1013474" source="SECTRACK" patch="1">1013474</ref>
      <ref url="http://www.securityfocus.com/bid/12852" source="BID">12852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolforum" name="coolforum">
        <vers prev="1" num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0858" published="2005-05-02" name="CVE-2005-0858" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19761" source="XF" patch="1">coolforum-register-sql-injection(19761)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19759" source="XF" patch="1">coolforum-adminentete-sql-injection(19759)</ref>
      <ref url="http://securitytracker.com/id?1013474" source="SECTRACK" patch="1">1013474</ref>
      <ref url="http://www.securityfocus.com/bid/12852" source="BID">12852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolforum" name="coolforum">
        <vers prev="1" num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0859" published="2005-05-02" name="CVE-2005-0859" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php.  NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report.  Also, the news.php version was later reported to be in 1.12 through 1.14.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14670" source="SECUNIA" patch="1" adv="1">14670</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19765" source="XF">czarnews-multiple-scripts-file-include(19765)</ref>
      <ref url="http://www.securityfocus.com/bid/18411" source="BID">18411</ref>
      <ref url="http://www.securityfocus.com/bid/12857" source="BID">12857</ref>
      <ref url="http://www.osvdb.org/14926" source="OSVDB">14926</ref>
      <ref url="http://www.osvdb.org/14925" source="OSVDB">14925</ref>
      <ref url="http://securitytracker.com/id?1013486" source="SECTRACK">1013486</ref>
      <ref url="http://milw0rm.com/exploits/2009" source="MILW0RM">2009</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27733" source="XF">czarnews-news-config-file-include(27733)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="czaries_network" name="czarnews">
        <vers num="1.13b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0860" published="2005-05-02" name="CVE-2005-0860" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12855" source="BID">12855</ref>
      <ref url="http://securitytracker.com/id?1013487" source="SECTRACK">1013487</ref>
      <ref url="http://secunia.com/advisories/14669" source="SECUNIA" adv="1">14669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_rusted_gate" name="trg_news">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0861" published="2005-05-02" name="CVE-2005-0861" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in DeleGate before 8.11.1 may allow attackers to cause a denial of service or execute arbitrary code, possibly due to "overflows on arrays."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19775" source="XF" patch="1">delegate-bo(19775)</ref>
      <ref url="http://www.delegate.org/mail-lists/delegate-en/2840" source="MISC" patch="1">http://www.delegate.org/mail-lists/delegate-en/2840</ref>
      <ref url="http://secunia.com/advisories/14649" source="SECUNIA" patch="1">14649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delegate" name="delegate">
        <vers prev="1" num="8.11.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0862" published="2005-05-02" name="CVE-2005-0862" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19721" source="XF">phpopenchat-file-include(19721)</ref>
      <ref url="http://www.zone-h.org/advisories/read/id=7310" source="MISC" adv="1">http://www.zone-h.org/advisories/read/id=7310</ref>
      <ref url="http://www.securityfocus.com/bid/12817" source="BID">12817</ref>
      <ref url="http://www.osvdb.org/14809" source="OSVDB">14809</ref>
      <ref url="http://www.osvdb.org/14808" source="OSVDB">14808</ref>
      <ref url="http://www.osvdb.org/14807" source="OSVDB">14807</ref>
      <ref url="http://securitytracker.com/id?1013434" source="SECTRACK">1013434</ref>
      <ref url="http://secunia.com/advisories/14600" source="SECUNIA" adv="1">14600</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465237/100/0/threaded" source="BUGTRAQ">20070410 PhpOpenChat &lt;= 3.0.1 (poc.php) Multiple Remote File Include Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpopenchat" name="phpopenchat">
        <vers num="2.3.4" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0863" published="2005-05-02" name="CVE-2005-0863" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19748" source="XF">phpopenchat-regulars-register-xss(19748)</ref>
      <ref url="http://www.securityfocus.com/bid/12841" source="BID">12841</ref>
      <ref url="http://secunia.com/advisories/14651" source="SECUNIA">14651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpopenchat" name="phpopenchat">
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0864" published="2005-05-02" name="CVE-2005-0864" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zone-h.org/en/advisories/read/id=7339/" source="MISC" adv="1">http://zone-h.org/en/advisories/read/id=7339/</ref>
      <ref url="http://www.securityfocus.com/bid/12864" source="BID">12864</ref>
      <ref url="http://exploitlabs.com/files/advisories/EXPL-A-2005-002-samsung-adsl.txt" source="MISC" adv="1">http://exploitlabs.com/files/advisories/EXPL-A-2005-002-samsung-adsl.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="securecomputing" name="samsung_adsl_modem">
        <vers num="smdk8947v1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0865" published="2005-05-02" name="CVE-2005-0865" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zone-h.org/en/advisories/read/id=7339/" source="MISC" adv="1">http://zone-h.org/en/advisories/read/id=7339/</ref>
      <ref url="http://www.securityfocus.com/bid/12864" source="BID">12864</ref>
      <ref url="http://securitytracker.com/id?1013615" source="SECTRACK">1013615</ref>
      <ref url="http://exploitlabs.com/files/advisories/EXPL-A-2005-002-samsung-adsl.txt" source="MISC" adv="1">http://exploitlabs.com/files/advisories/EXPL-A-2005-002-samsung-adsl.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="securecomputing" name="samsung_adsl_modem">
        <vers num="smdk8947v1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0866" published="2005-05-02" name="CVE-2005-0866" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-100-1" source="UBUNTU">USN-100-1</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=291376" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=291376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cdrtools" name="cdrecord">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0867" published="2005-05-02" name="CVE-2005-0867" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10867" source="OVAL">oval:org.mitre.oval:def:10867</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0868" published="2005-05-02" name="CVE-2005-0868" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venera.com/downloads/Attack_5250_terminal_emulations_from_iSeries_server.pdf" source="MISC">http://www.venera.com/downloads/Attack_5250_terminal_emulations_from_iSeries_server.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111160242803070&amp;w=2" source="BUGTRAQ">20050323 Backdoors in AS/400 emulations allow the server to attack connected PC workstations</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bosanova" name="launcher400">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="client_access">
        <vers num="" />
      </prod>
      <prod vendor="mochasoft" name="tn5250">
        <vers num="" />
      </prod>
      <prod vendor="powerterm" name="interconnect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0869" published="2005-05-02" name="CVE-2005-0869" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19808" source="XF">phpsysinfo-path-disclosure(19808)</ref>
      <ref url="http://secunia.com/advisories/14690/" source="SECUNIA" adv="1">14690</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111161017209422&amp;w=2" source="BUGTRAQ" adv="1">20050323 [SECURITYREASON.COM] phpSysInfo 2.3 Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsysinfo" name="phpsysinfo">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0870" published="2005-05-02" name="CVE-2005-0870" modified="2010-04-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19807" source="XF">phpsysinfo-sensor-program-xss(19807)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-724" source="DEBIAN">DSA-724</ref>
      <ref url="http://secunia.com/advisories/14690/" source="SECUNIA" adv="1">14690</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111161017209422&amp;w=2" source="BUGTRAQ" adv="1">20050323 [SECURITYREASON.COM] phpSysInfo 2.3 Multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/15414" source="BID">15414</ref>
      <ref url="http://www.securityfocus.com/bid/12887" source="BID">12887</ref>
      <ref url="http://www.securityfocus.com/archive/1/416543" source="BUGTRAQ">20051115 Advisory 22/2005: Multiple vulnerabilities in phpSysInfo</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:212" source="MANDRIVA">MDKSA-2005:212</ref>
      <ref url="http://www.debian.org/security/2005/dsa-899" source="DEBIAN">DSA-899</ref>
      <ref url="http://www.debian.org/security/2005/dsa-898" source="DEBIAN">DSA-898</ref>
      <ref url="http://www.debian.org/security/2005/dsa-897" source="DEBIAN">DSA-897</ref>
      <ref url="http://secunia.com/advisories/17643" source="SECUNIA">17643</ref>
      <ref url="http://secunia.com/advisories/17616" source="SECUNIA">17616</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=301118" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=301118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsysinfo" name="phpsysinfo">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0871" published="2005-05-02" name="CVE-2005-0871" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19824" source="XF">topic-calendar-path-disclosure(19824)</ref>
      <ref url="http://securitytracker.com/id?1013554" source="SECTRACK">1013554</ref>
      <ref url="http://secunia.com/advisories/14659" source="SECUNIA">14659</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168190630576&amp;w=2" source="BUGTRAQ">20050324 Multiple vulnerabilities in Topic Calendar 1.0.1 for phpBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0872" published="2005-05-02" name="CVE-2005-0872" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19821" source="XF">topic-calendar-start-xss(19821)</ref>
      <ref url="http://securitytracker.com/id?1013554" source="SECTRACK">1013554</ref>
      <ref url="http://secunia.com/advisories/14659" source="SECUNIA">14659</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168190630576&amp;w=2" source="BUGTRAQ">20050324 Multiple vulnerabilities in Topic Calendar 1.0.1 for phpBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0873" published="2005-05-02" name="CVE-2005-0873" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-292A.html" source="CERT">TA05-292A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/210524" source="CERT-VN">VU#210524</ref>
      <ref url="http://www.securityfocus.com/bid/12892" source="BID">12892</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168323804203&amp;w=2" source="BUGTRAQ">20050324 Oracle Reports Server 10g Vulnerable to  XSS</ref>
      <ref url="http://www.securityfocus.com/bid/15134" source="BID">15134</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuoct2005.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/pdf/cpuoct2005.html</ref>
      <ref url="http://secunia.com/advisories/17250" source="SECUNIA">17250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="10g_reports_server">
        <vers num="9.0.4.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0874" published="2005-05-02" name="CVE-2005-0874" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14689" source="SECUNIA" adv="1">14689</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111171416802350&amp;w=2" source="BUGTRAQ" adv="1">20050324 LogicLibrary BugScan VSR,Trillian 2.0, 3.0 and 3.1</ref>
      <ref url="http://www.osvdb.org/15004" source="OSVDB">15004</ref>
      <ref url="http://securitytracker.com/id?1013557" source="SECTRACK">1013557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_studios" name="trillian">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0875" published="2005-05-02" name="CVE-2005-0875" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14689" source="SECUNIA" adv="1">14689</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111171416802350&amp;w=2" source="BUGTRAQ" adv="1">20050324 LogicLibrary BugScan VSR,Trillian 2.0, 3.0 and 3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_studios" name="trillian">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0876" published="2005-05-02" name="CVE-2005-0876" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19825" source="XF" patch="1">dnsmasq-dhcp-offbyone-bo(19825)</ref>
      <ref url="http://www.securityfocus.com/bid/12897" source="BID" patch="1">12897</ref>
      <ref url="http://secunia.com/advisories/14691" source="SECUNIA" patch="1" adv="1">14691</ref>
      <ref url="http://www.thekelleys.org.uk/dnsmasq/CHANGELOG" source="CONFIRM">http://www.thekelleys.org.uk/dnsmasq/CHANGELOG</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnsmasq" name="dnsmasq">
        <vers num="2.14" />
        <vers num="2.15" />
        <vers num="2.16" />
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.19" />
        <vers num="2.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0877" published="2005-05-02" name="CVE-2005-0877" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19826" source="XF" patch="1">dnsmasq-dns-cache-poisoning(19826)</ref>
      <ref url="http://www.securityfocus.com/bid/12897" source="BID" patch="1">12897</ref>
      <ref url="http://secunia.com/advisories/14691" source="SECUNIA" patch="1" adv="1">14691</ref>
      <ref url="http://www.thekelleys.org.uk/dnsmasq/CHANGELOG" source="CONFIRM">http://www.thekelleys.org.uk/dnsmasq/CHANGELOG</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnsmasq" name="dnsmasq">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.10" />
        <vers num="2.11" />
        <vers num="2.12" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.15" />
        <vers num="2.16" />
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.19" />
        <vers num="2.2" />
        <vers num="2.20" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0878" published="2005-03-23" name="CVE-2005-0878" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19797" source="XF" patch="1" adv="1">mercuryboard-title-pm-xss(19797)</ref>
      <ref url="http://www.securityfocus.com/bid/12872" source="BID" patch="1" adv="1">12872</ref>
      <ref url="http://secunia.com/advisories/14679" source="SECUNIA" patch="1" adv="1">14679</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard_message_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0879" published="2005-05-02" name="CVE-2005-0879" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via a URL in the act parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19809" source="XF">vortexportal-act-file-include(19809)</ref>
      <ref url="http://www.securityfocus.com/bid/12878" source="BID">12878</ref>
      <ref url="http://www.osvdb.org/14959" source="OSVDB">14959</ref>
      <ref url="http://www.osvdb.org/14958" source="OSVDB">14958</ref>
      <ref url="http://securitytracker.com/id?1013545" source="SECTRACK">1013545</ref>
      <ref url="http://secunia.com/advisories/14707" source="SECUNIA" adv="1">14707</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0405.html" source="BUGTRAQ" adv="1">20050323 Vortex Portal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vortex_portal" name="vortex_portal">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0880" published="2005-05-02" name="CVE-2005-0880" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">content.php in Vortex Portal allows remote attackers to obtain sensitive information via an invalid act parameter, which leaks the full pathname in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19811" source="XF">vortex-portal-path-disclosure(19811)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0405.html" source="BUGTRAQ">20050323 Vortex Portal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vortex_portal" name="vortex_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0881" published="2005-03-23" name="CVE-2005-0881" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14708" source="SECUNIA" patch="1" adv="1">14708</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19817" source="XF" adv="1">articlelive-articleid-xss(19817)</ref>
      <ref url="http://www.securityfocus.com/bid/12879" source="BID" adv="1">12879</ref>
      <ref url="http://www.securityfocus.com/archive/1/394069" source="BUGTRAQ" adv="1">20050323 Interspire ArticleLive 2005 (php version) is vulnerable to XSS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112483966331737&amp;w=2" source="BUGTRAQ">20050823 Re: Interspire ArticleLive 2005 (php version) is vulnerable to XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interspire" name="articlelive">
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0882" published="2005-05-02" name="CVE-2005-0882" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admincore.php in BirdBlog before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) userpw parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19799" source="XF" patch="1">birdblog-admincore-sql-injection(19799)</ref>
      <ref url="http://www.securityfocus.com/bid/12880" source="BID" patch="1">12880</ref>
      <ref url="http://securitytracker.com/id?1013548" source="SECTRACK" patch="1">1013548</ref>
      <ref url="http://secunia.com/advisories/14676" source="SECUNIA" patch="1" adv="1">14676</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/birdblog/birdblog/admin/admincore.php?r1=1.4&amp;r2=1.5" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/birdblog/birdblog/admin/admincore.php?r1=1.4&amp;r2=1.5</ref>
      <ref url="http://birdblog.sourceforge.net/ChangeLog" source="CONFIRM">http://birdblog.sourceforge.net/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="birdblog" name="birdblog">
        <vers num="1.0.0" />
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0883" published="2005-03-23" name="CVE-2005-0883" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (2) the -afs-1- query string to the msg.php page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19803" source="XF" adv="1">digitalhive-basephp-xss(19803)</ref>
      <ref url="http://www.securityfocus.com/bid/12883" source="BID" adv="1">12883</ref>
      <ref url="http://securitytracker.com/id?1013516" source="SECTRACK" adv="1">1013516</ref>
      <ref url="http://secunia.com/advisories/14702" source="SECUNIA" adv="1">14702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digitalhive" name="digitalhive">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0884" published="2005-05-02" name="CVE-2005-0884" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DigitalHive 2.0 allows remote attackers to re-install the product by directly accessing the install script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19802" source="XF">digitalhive-reinstall(19802)</ref>
      <ref url="http://securitytracker.com/id?1013516" source="SECTRACK">1013516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digitalhive" name="digitalhive">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0885" published="2005-05-02" name="CVE-2005-0885" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12886" source="BID">12886</ref>
      <ref url="http://securitytracker.com/id?1013515" source="SECTRACK">1013515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0886" published="2005-05-02" name="CVE-2005-0886" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12888" source="BID">12888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1_final" />
        <vers num="1.3_final" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0_alpha_3" />
        <vers num="2.0_pdr3" />
        <vers num="2.0_pf1" />
        <vers num="2.0_pf2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0887" published="2005-03-24" name="CVE-2005-0887" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which causes code to be injected into an eval statement.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19806" source="XF" patch="1" adv="1">dcl-file-include(19806)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=315144" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=315144</ref>
      <ref url="http://securitytracker.com/id?1013559" source="SECTRACK" patch="1" adv="1">1013559</ref>
      <ref url="http://secunia.com/advisories/14688" source="SECUNIA" patch="1" adv="1">14688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_dean" name="double_choco_latte">
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.4.2" />
        <vers num="0.9.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0888" published="2005-05-02" name="CVE-2005-0888" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in functions.inc.php for Double Choco Latte 0.9.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) class or (2) method name.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19805" source="XF" patch="1">dcl-xss(19805)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=315160" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=315160</ref>
      <ref url="http://securitytracker.com/id?1013559" source="SECTRACK" patch="1">1013559</ref>
      <ref url="http://secunia.com/advisories/14688" source="SECUNIA" patch="1" adv="1">14688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_dean" name="double_choco_latte">
        <vers num="0.9.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0889" published="2005-03-24" name="CVE-2005-0889" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi CMS 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the area parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12895" source="BID" adv="1">12895</ref>
      <ref url="http://securitytracker.com/id?1013558" source="SECTRACK" adv="1">1013558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dream4" name="koobi_cms">
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0890" published="2005-05-02" name="CVE-2005-0890" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12896" source="BID">12896</ref>
      <ref url="http://securitytracker.com/id?1013558" source="SECTRACK">1013558</ref>
      <ref url="http://secunia.com/advisories/14696" source="SECUNIA" adv="1">14696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dream4" name="koobi_cms">
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0891" published="2005-05-02" name="CVE-2005-0891" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-344.html" source="REDHAT" patch="1" adv="1">RHSA-2005:344</ref>
      <ref url="http://www.securityfocus.com/bid/12950" source="BID">12950</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded" source="FEDORA">FLSA-2005:155510</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-343.html" source="REDHAT">RHSA-2005:343</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214" source="MANDRIVA">MDKSA-2005:214</ref>
      <ref url="http://secunia.com/advisories/17657" source="SECUNIA" adv="1">17657</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9710" source="OVAL">oval:org.mitre.oval:def:9710</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000958" source="CONECTIVA">CLSA-2005:958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtk" name="gtk+">
        <vers num="2.0.2" />
        <vers num="2.0.6" />
        <vers num="2.2.1" />
        <vers num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0892" published="2005-03-28" name="CVE-2005-0892" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in smail 3.2.0.120 allows remote attackers or local users to execute arbitrary code via a long string in the MAIL FROM command and possibly other SMTP commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-722" source="DEBIAN" patch="1" adv="1">DSA-722</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111177045217717&amp;w=2" source="BUGTRAQ" adv="1">20050325 smail remote and local root holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smail" name="smail">
        <vers num="3.2.0.120" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0893" published="2005-05-02" name="CVE-2005-0893" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">modes.c in smail 3.2.0.120 implements signal handlers with certain unsafe library calls, which may allow attackers to execute arbitrary code via signal handler race conditions, possibly using xmalloc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111177045217717&amp;w=2" source="BUGTRAQ" adv="1">20050325 smail remote and local root holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smail" name="smail">
        <vers num="3.2.0.120" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0894" published="2005-05-02" name="CVE-2005-0894" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">OpenmosixCollector and OpenMosixView in OpenMosixView 1.5 allow local users to overwrite or delete arbitrary files via a symlink attack on (1) temporary files in the openmosixcollector directory or (2) nodes.tmp.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12902" source="BID" patch="1">12902</ref>
      <ref url="http://secunia.com/advisories/14693" source="SECUNIA" adv="1">14693</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111176899423078&amp;w=2" source="BUGTRAQ" adv="1">20050325 RX250305 - OpenMosixView : Multiple Race conditions - advisory and exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmosixview" name="openmosixview">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0895" published="2005-05-02" name="CVE-2005-0895" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netcomm 1300NB DSL Modem allows remote attackers to cause a denial of service (device hang) via a large number of ping packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12901" source="BID">12901</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111177093020587&amp;w=2" source="BUGTRAQ" adv="1">20050325 Netcomm 1300NB DSL Modem Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netcomm" name="nb1300">
        <vers num="4.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0896" published="2005-05-02" name="CVE-2005-0896" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) page, or (3) subsubcat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12900" source="BID">12900</ref>
      <ref url="http://secunia.com/advisories/14692" source="SECUNIA" adv="1">14692</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111176904423360&amp;w=2" source="BUGTRAQ" adv="1">20050325 phpMyDirectory 10.1.3-rel Cross site scripting</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0897" published="2005-05-02" name="CVE-2005-0897" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12910" source="BID">12910</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186424600509&amp;w=2" source="BUGTRAQ">20050325 File inclusion and XSS vulnerability in E-Store Kit-2 PayPal Edition</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magicscripts" name="e-store_kit-2">
        <vers num="paypal" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0898" published="2005-03-26" name="CVE-2005-0898" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in downloadform.php in E-Store Kit-2 PayPal Edition allows remote attackers to inject arbitrary web script or HTML via the txn_id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12909" source="BID" adv="1">12909</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186424600509&amp;w=2" source="BUGTRAQ" adv="1">20050325 File inclusion and XSS vulnerability in E-Store Kit-2 PayPal Edition</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magicscripts" name="e-store_kit-2">
        <vers num="paypal" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0899" published="2005-05-02" name="CVE-2005-0899" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186209318029&amp;w=2" source="BUGTRAQ">20050325 AS/400 LDAP user accounts disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="os_400">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0900" published="2005-03-26" name="CVE-2005-0900" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186145609320&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050325 ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6</ref>
      <ref url="http://zone-h.org/advisories/read/id=7356" source="MISC" adv="1">http://zone-h.org/advisories/read/id=7356</ref>
      <ref url="http://nukebookmarks.sourceforge.net/" source="CONFIRM">http://nukebookmarks.sourceforge.net/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukebookmarks" name="nukebookmarks">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0901" published="2005-05-02" name="CVE-2005-0901" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zone-h.org/advisories/read/id=7356" source="MISC">http://zone-h.org/advisories/read/id=7356</ref>
      <ref url="http://nukebookmarks.sourceforge.net/" source="CONFIRM">http://nukebookmarks.sourceforge.net/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186145609320&amp;w=2" source="BUGTRAQ">20050325 ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukebookmarks" name="nukebookmarks">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0902" published="2005-05-02" name="CVE-2005-0902" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zone-h.org/advisories/read/id=7356" source="MISC" adv="1">http://zone-h.org/advisories/read/id=7356</ref>
      <ref url="http://nukebookmarks.sourceforge.net/" source="CONFIRM">http://nukebookmarks.sourceforge.net/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186145609320&amp;w=2" source="BUGTRAQ" adv="1">20050325 ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukebookmarks" name="nukebookmarks">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0903" published="2005-05-02" name="CVE-2005-0903" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12905" source="BID">12905</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186277521713&amp;w=2" source="BUGTRAQ">20050326 QuickTime malformed JPEG buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime_pictureviewer">
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0904" published="2005-05-02" name="CVE-2005-0904" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19819" source="XF">windows-desktop-tsshutdnexe-dos(19819)</ref>
      <ref url="http://support.microsoft.com/kb/889323" source="MSKB">889323</ref>
      <ref url="http://securitytracker.com/id?1013552" source="SECTRACK">1013552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="remote_desktop_protocol">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0905" published="2005-05-02" name="CVE-2005-0905" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12898" source="BID" patch="1">12898</ref>
      <ref url="http://secunia.com/advisories/14712" source="SECUNIA" patch="1" adv="1">14712</ref>
      <ref url="http://forum.maxthon.com/forum/index.php?showtopic=18207" source="MISC" patch="1">http://forum.maxthon.com/forum/index.php?showtopic=18207</ref>
      <ref url="http://www.raffon.net/advisories/maxthon/searchbarid.html" source="MISC" adv="1">http://www.raffon.net/advisories/maxthon/searchbarid.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111175236620942&amp;w=2" source="FULLDISC" adv="1">20050325 Maxthon browser search bar information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxthon" name="maxthon">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0906" published="2005-05-02" name="CVE-2005-0906" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Heritage of Kings, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12912" source="BID">12912</ref>
      <ref url="http://www.securityfocus.com/archive/1/394404" source="BUGTRAQ">20050328 Buffer-overflow in Tincat 2 minor than 2.0.28 (Sacred, Settlers 5 and others)</ref>
      <ref url="http://secunia.com/advisories/14767" source="SECUNIA">14767</ref>
      <ref url="http://secunia.com/advisories/14762" source="SECUNIA">14762</ref>
      <ref url="http://aluigi.altervista.org/adv/tincat2bof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/tincat2bof-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="instance_four" name="tincat">
        <vers num="release_2" />
      </prod>
      <prod vendor="sacred" name="sacred">
        <vers num="1.8.2.6" />
      </prod>
      <prod vendor="ubi_soft" name="the_settlersheritage_of_kings">
        <vers num="1.0_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0907" published="2005-05-02" name="CVE-2005-0907" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.php, (3) the lang parameter to index.php, (4) the searchQuery parameter to search_result.php, (5) or the searchTopCategoryID parameter to search_result.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013565" source="SECTRACK" patch="1">1013565</ref>
      <ref url="http://www.securityfocus.com/archive/1/394406/2005-03-26/2005-04-01/2" source="BUGTRAQ" adv="1">20050327 Multiple sql injection, and xss vulnerabilities in Vladersoft Shopping Cart v.3.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valdersoft" name="shopping_cart">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0908" published="2005-03-28" name="CVE-2005-0908" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the searchTopCategoryID parameter to search_result.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013565" source="SECTRACK" patch="1" adv="1">1013565</ref>
      <ref url="http://www.securityfocus.com/archive/1/394406/2005-03-26/2005-04-01/2" source="BUGTRAQ" adv="1">20050327 Multiple sql injection, and xss vulnerabilities in Vladersoft Shopping Cart v.3.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valdersoft" name="valdersoft_shopping_cart">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0909" published="2005-05-02" name="CVE-2005-0909" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in shoutact.php for TKai's Shoutbox allows remote attackers to execute arbitrary PHP code via the query parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12914" source="BID">12914</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111202260908735&amp;w=2" source="FULLDISC" adv="1">20050328 THai's Shoutbox correction name</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tkais_shoutbox" name="tkais_shoutbox">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0910" published="2005-05-02" name="CVE-2005-0910" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) the viewcat parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013566" source="SECTRACK">1013566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-xoops" name="e-xoops">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0911" published="2005-03-28" name="CVE-2005-0911" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter in the viewarticle action for index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013566" source="SECTRACK" adv="1">1013566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-xoops" name="e-xoops">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0912" published="2005-03-24" name="CVE-2005-0912" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerabilities in deplate before 0.7.2 have unknown impact, possibly involving elements.rb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=315034" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=315034</ref>
      <ref url="http://securitytracker.com/id?1013555" source="SECTRACK" patch="1" adv="1">1013555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deplate" name="deplate">
        <vers prev="1" num="0.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0913" published="2005-05-02" name="CVE-2005-0913" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19880" source="XF" patch="1">smarty-regexreplace-security-bpass(19880)</ref>
      <ref url="http://securitytracker.com/id?1013556" source="SECTRACK" patch="1">1013556</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-35.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-35</ref>
      <ref url="http://secunia.com/advisories/14729/" source="SECUNIA" patch="1" adv="1">14729</ref>
      <ref url="http://news.php.net/php.smarty.dev/2673" source="CONFIRM" patch="1">http://news.php.net/php.smarty.dev/2673</ref>
      <ref url="http://www.securityfocus.com/bid/12941" source="BID">12941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smarty" name="smarty">
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0914" published="2005-03-26" name="CVE-2005-0914" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CPG Dragonfly 9.0.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the profile parameter to index.php or (2) the cat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013573" source="SECTRACK" adv="1">1013573</ref>
      <ref url="http://security.talte.net/content/view/252/46/" source="MISC" adv="1">http://security.talte.net/content/view/252/46/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpg-nuke" name="cpg_dragonfly_cms">
        <vers num="9.0.2_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0915" published="2005-05-02" name="CVE-2005-0915" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013570" source="SECTRACK" patch="1">1013570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmasters-debutants" name="wd_guestbook">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0916" published="2005-05-02" name="CVE-2005-0916" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_queue_init function but exits without running io_queue_release, which causes exit_aio and is_hugepage_only_range to fail.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset%404248c8c0es30_4YVdwa6vteKi7h_nw" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset%404248c8c0es30_4YVdwa6vteKi7h_nw</ref>
      <ref url="http://groups-beta.google.com/group/linux.kernel/browse_thread/thread/13b43bd5783842f6/7ce3c5a514a497ab?q=io_queue_init&amp;rnum=3#7ce3c5a514a497ab" source="MISC">http://groups-beta.google.com/group/linux.kernel/browse_thread/thread/13b43bd5783842f6/7ce3c5a514a497ab?q=io_queue_init&amp;rnum=3#7ce3c5a514a497ab</ref>
      <ref url="http://www.securityfocus.com/bid/12987" source="BID">12987</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html" source="SUSE">SUSE-SA:2005:050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0917" published="2005-05-02" name="CVE-2005-0917" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index_header.php for EncapsBB 0.3.2_fixed, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the root parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15078" source="OSVDB">15078</ref>
      <ref url="http://securitytracker.com/id?1013569" source="SECTRACK">1013569</ref>
      <ref url="http://secunia.com/advisories/14761" source="SECUNIA">14761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerdev" name="encapsbb">
        <vers num="0.3.2_fixed" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0918" published="2005-05-05" name="CVE-2005-0918" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hyperdose.com/advisories/H2005-07.txt" source="MISC" patch="1">http://www.hyperdose.com/advisories/H2005-07.txt</ref>
      <ref url="http://www.adobe.com/support/techdocs/323585.html" source="CONFIRM" patch="1">http://www.adobe.com/support/techdocs/323585.html</ref>
      <ref url="http://securitytracker.com/id?1013890" source="SECTRACK">1013890</ref>
      <ref url="http://secunia.com/advisories/15255" source="SECUNIA" adv="1">15255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="svg_viewer">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.01" />
        <vers num="3.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0919" published="2005-03-29" name="CVE-2005-0919" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12927" source="BID" adv="1">12927</ref>
      <ref url="http://securitytracker.com/id?1013588" source="SECTRACK" adv="1">1013588</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111211930330410&amp;w=2" source="FULLDISC" adv="1">20050329 Adventia Chat</ref>
      <ref url="http://exploitlabs.com/files/advisories/EXPL-A-2005-003-adventiachat.txt" source="MISC" adv="1">http://exploitlabs.com/files/advisories/EXPL-A-2005-003-adventiachat.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21317" source="XF">adventia-chat-field-xss(21317)</ref>
      <ref url="http://www.securityfocus.com/bid/12940" source="BID">12940</ref>
      <ref url="http://www.osvdb.org/15156" source="OSVDB">15156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adventia" name="adventia_chat">
        <vers num="3.1" />
      </prod>
      <prod vendor="adventia" name="adventia_server_pro">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0920" published="2005-05-02" name="CVE-2005-0920" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12925" source="BID" patch="1">12925</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=315830" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=315830</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0921" published="2005-05-02" name="CVE-2005-0921" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/kb/896093" source="MSKB" patch="1" adv="1">896093</ref>
      <ref url="http://www.securityfocus.com/bid/12913" source="BID">12913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_connector">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":ibm_lotus_domino" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0922" published="2005-05-02" name="CVE-2005-0922" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file type.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/146020" source="CERT-VN" adv="1">VU#146020</ref>
      <ref url="http://www.securityfocus.com/bid/12923" source="BID">12923</ref>
      <ref url="http://securitytracker.com/id?1013587" source="SECTRACK">1013587</ref>
      <ref url="http://securitytracker.com/id?1013586" source="SECTRACK">1013586</ref>
      <ref url="http://securitytracker.com/id?1013585" source="SECTRACK">1013585</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html" source="CONFIRM" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html</ref>
      <ref url="http://secunia.com/advisories/14741" source="SECUNIA" adv="1">14741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ms_exchange" />
        <vers num="2005" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":professional" />
        <vers num="2005" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2004_professional" />
        <vers num="2005_premier" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0923" published="2005-05-02" name="CVE-2005-0923" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network share.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/713620" source="CERT-VN" adv="1">VU#713620</ref>
      <ref url="http://www.securityfocus.com/bid/12924" source="BID">12924</ref>
      <ref url="http://securitytracker.com/id?1013587" source="SECTRACK">1013587</ref>
      <ref url="http://securitytracker.com/id?1013586" source="SECTRACK">1013586</ref>
      <ref url="http://securitytracker.com/id?1013585" source="SECTRACK">1013585</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html" source="CONFIRM" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html</ref>
      <ref url="http://secunia.com/advisories/14741" source="SECUNIA">14741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ms_exchange" />
        <vers num="2005" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":professional" />
        <vers num="2005" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2004_professional" />
        <vers num="2005_premier" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0924" published="2005-03-29" name="CVE-2005-0924" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Adventia E-Data 2.0 allows remote attackers to inject arbitrary web script or HTML via a query keyword.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013589" source="SECTRACK" adv="1">1013589</ref>
      <ref url="http://secunia.com/advisories/14739" source="SECUNIA" adv="1">14739</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111211945505635&amp;w=2" source="FULLDISC" adv="1">20050329 E-Data</ref>
      <ref url="http://exploitlabs.com/files/advisories/EXPL-A-2005-004-edata.txt" source="MISC" adv="1">http://exploitlabs.com/files/advisories/EXPL-A-2005-004-edata.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19889" source="XF">edata-new-user-xss(19889)</ref>
      <ref url="http://www.securityfocus.com/bid/12927" source="BID">12927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adventia" name="e-data">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0925" published="2005-05-02" name="CVE-2005-0925" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013603" source="SECTRACK" patch="1" adv="1">1013603</ref>
      <ref url="http://www.securityfocus.com/bid/12931" source="BID">12931</ref>
      <ref url="http://www.persianhacker.net/news/news-2945.html" source="MISC">http://www.persianhacker.net/news/news-2945.html</ref>
      <ref url="http://www.osvdb.org/15121" source="OSVDB">15121</ref>
      <ref url="http://secunia.com/advisories/14725" source="SECUNIA" adv="1">14725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214393101387&amp;w=2" source="BUGTRAQ" adv="1">20050329 [PersianHacker.NET 200503-11]Ublog reload 1.0.4 and prior</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0926" published="2005-05-02" name="CVE-2005-0926" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attachments with MIME-encoded file names.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sylpheed.good-day.net/changelog.html.en" source="CONFIRM">http://sylpheed.good-day.net/changelog.html.en</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sylpheed" name="sylpheed">
        <vers num="0.8.11" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0927" published="2005-05-02" name="CVE-2005-0927" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=195" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=195</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=316038" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=316038</ref>
      <ref url="http://secunia.com/advisories/14716" source="SECUNIA" adv="1">14716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0928" published="2005-05-02" name="CVE-2005-0928" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15098" source="OSVDB">15098</ref>
      <ref url="http://www.osvdb.org/15097" source="OSVDB">15097</ref>
      <ref url="http://www.osvdb.org/15096" source="OSVDB">15096</ref>
      <ref url="http://securitytracker.com/id?1013581" source="SECTRACK">1013581</ref>
      <ref url="http://secunia.com/advisories/14742" source="SECUNIA" adv="1">14742</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205342909640&amp;w=2" source="BUGTRAQ" adv="1">20050328 Multiple Sql injection, and multiple XSS vulnerabilities in Photopost PHP Pro Photo Gallery Software.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="5.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0929" published="2005-05-02" name="CVE-2005-0929" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15100" source="OSVDB">15100</ref>
      <ref url="http://www.osvdb.org/15099" source="OSVDB">15099</ref>
      <ref url="http://securitytracker.com/id?1013581" source="SECTRACK">1013581</ref>
      <ref url="http://secunia.com/advisories/14742" source="SECUNIA">14742</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111213719017716&amp;w=2" source="BUGTRAQ">20050328 Re: Multiple Sql injection, and multiple XSS vulnerabilities in Photopost PHP Pro Photo Gallery Software.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205342909640&amp;w=2" source="BUGTRAQ">20050328 Multiple Sql injection, and multiple XSS vulnerabilities in Photopost PHP Pro Photo Gallery Software.</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0930" published="2005-05-02" name="CVE-2005-0930" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message parameter to message.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12929" source="BID">12929</ref>
      <ref url="http://www.securityfocus.com/archive/1/394526" source="BUGTRAQ">20050329 [PersianHacker.NET 200503-12]Chatness 2.5.1 and prior XSS Vulnerabilities</ref>
      <ref url="http://www.persianhacker.net/news/news-2946.html" source="MISC">http://www.persianhacker.net/news/news-2946.html</ref>
      <ref url="http://securitytracker.com/id?1013604" source="SECTRACK">1013604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chatness" name="chatness">
        <vers prev="1" num="2.5" />
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0931" published="2005-03-29" name="CVE-2005-0931" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12926" source="BID" adv="1">12926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jimmy" name="the_includer">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0932" published="2005-05-02" name="CVE-2005-0932" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpCOIN 1.2.1b and earlier allow remote attackers to execute arbitrary SQL commands (1) via the search engine, (2) the username or email fields in the "forgotten password" feature, or (3) the domain name in a package order.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12917" source="BID">12917</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coinsoft_technologies" name="phpcoin">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0933" published="2005-05-02" name="CVE-2005-0933" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in auxpage.php for phpCOIN 1.2.1b and earlier allows remote attackers to read arbitrary files via the page parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12917" source="BID">12917</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coinsoft_technologies" name="phpcoin">
        <vers prev="1" num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0934" published="2005-05-02" name="CVE-2005-0934" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://wackowiki.com/WackoDownload/InEnglish#h4828-4" source="CONFIRM" patch="1">http://wackowiki.com/WackoDownload/InEnglish#h4828-4</ref>
      <ref url="http://secunia.com/advisories/14720" source="SECUNIA" patch="1" adv="1">14720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wackowiki" name="wackowiki">
        <vers num="r4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0935" published="2005-05-02" name="CVE-2005-0935" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12903" source="BID">12903</ref>
      <ref url="http://www.hackerscenter.com/Archive/view.asp?id=1774" source="MISC">http://www.hackerscenter.com/Archive/view.asp?id=1774</ref>
      <ref url="http://securitytracker.com/id?1013563" source="SECTRACK">1013563</ref>
      <ref url="http://secunia.com/advisories/14711" source="SECUNIA" adv="1">14711</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111221890614271&amp;w=2" source="BUGTRAQ" adv="1">20050330 Multiple sql injection, and xss vulnerabilities in Pay pal Storefront</ref>
      <ref url="http://www.osvdb.org/15058" source="OSVDB">15058</ref>
      <ref url="http://www.osvdb.org/15057" source="OSVDB">15057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esmi" name="paypal_storefront">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0936" published="2005-05-02" name="CVE-2005-0936" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12904" source="BID">12904</ref>
      <ref url="http://www.osvdb.org/15059" source="OSVDB">15059</ref>
      <ref url="http://www.hackerscenter.com/Archive/view.asp?id=1774" source="MISC">http://www.hackerscenter.com/Archive/view.asp?id=1774</ref>
      <ref url="http://securitytracker.com/id?1013563" source="SECTRACK">1013563</ref>
      <ref url="http://secunia.com/advisories/14711" source="SECUNIA">14711</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111221890614271&amp;w=2" source="BUGTRAQ">20050330 Multiple sql injection, and xss vulnerabilities in Pay pal Storefront</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esmi" name="paypal_storefront">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0937" published="2005-02-22" name="CVE-2005-0937" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lkml.org/lkml/2005/2/22/123" source="MISC" patch="1" adv="1">http://lkml.org/lkml/2005/2/22/123</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10037" source="OVAL">oval:org.mitre.oval:def:10037</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@421cfc11zFsK9gxvSJ2t__FCmuUd3Q" source="CONFIRM" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@421cfc11zFsK9gxvSJ2t__FCmuUd3Q</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-420.html" source="REDHAT">RHSA-2005:420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0938" published="2005-05-02" name="CVE-2005-0938" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013603" source="SECTRACK">1013603</ref>
      <ref url="http://secunia.com/advisories/14725" source="SECUNIA">14725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214393101387&amp;w=2" source="BUGTRAQ">20050329 [PersianHacker.NET 200503-11]Ublog reload 1.0.4 and prior</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uapplication" name="ublog_reload">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0940" reject="1" published="2005-05-02" name="CVE-2005-0940" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0490.  Reason: This candidate was inadvertently referenced in a vendor advisory due to a typo.  Notes: All CVE users should reference CVE-2005-0490 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0941" published="2005-05-02" name="CVE-2005-0941" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13092" source="BID">13092</ref>
      <ref url="http://www.securityfocus.com/archive/1/395516" source="BUGTRAQ">20050412 OpenOffice DOC document Heap Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-375.html" source="REDHAT">RHSA-2005:375</ref>
      <ref url="http://www.openoffice.org/issues/show_bug.cgi?id=46388" source="CONFIRM">http://www.openoffice.org/issues/show_bug.cgi?id=46388</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-13.xml" source="GENTOO">GLSA-200504-13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9106" source="OVAL">oval:org.mitre.oval:def:9106</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_21_sr.html" source="SUSE">SUSE-SR:2005:021</ref>
      <ref url="http://secunia.com/advisories/17027" source="SECUNIA">17027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0942" published="2005-05-02" name="CVE-2005-0942" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19354" source="XF" patch="1">sybase-adaptive-server(19354)</ref>
      <ref url="http://www.sybase.com/detail?id=1034520" source="CONFIRM" patch="1" adv="1">http://www.sybase.com/detail?id=1034520</ref>
      <ref url="http://www.securityfocus.com/bid/12080" source="BID" patch="1">12080</ref>
      <ref url="http://www.ngssoftware.com/advisories/sybase-ase.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/sybase-ase.txt</ref>
      <ref url="http://secunia.com/advisories/13632" source="SECUNIA" patch="1" adv="1">13632</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272918117194&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050405 Sybase ASE Multiple Security Issues (#NISR05042005)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0315.html" source="BUGTRAQ" patch="1">20041222 Sybase ASE 12.5.2 vulnerabilities</ref>
      <ref url="http://www.sybase.com/detail?id=1034752" source="CONFIRM" adv="1">http://www.sybase.com/detail?id=1034752</ref>
      <ref url="http://www.securityfocus.com/archive/1/393851" source="BUGTRAQ" adv="1">20050321 Details of Sybase ASE bugs withheld</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="adaptive_server_enterprise">
        <vers num="11.03.3" edition="" />
        <vers num="11.03.3" edition=":linux" />
        <vers num="11.5" edition="" />
        <vers num="11.5" edition=":hp" />
        <vers num="11.5" edition=":win" />
        <vers num="11.5" edition=":sun" />
        <vers num="11.5" edition=":digital_unix" />
        <vers num="11.5.1" edition="" />
        <vers num="11.5.1" edition=":sun" />
        <vers num="11.5.1" edition=":win" />
        <vers num="11.5.1" edition=":digital_unix" />
        <vers num="11.5.1" edition=":hp" />
        <vers num="11.9.2" edition="" />
        <vers num="11.9.2" edition=":win" />
        <vers num="11.9.2" edition=":sun" />
        <vers num="11.9.2" edition=":digital_unix" />
        <vers num="11.9.2" edition=":hp" />
        <vers num="12.0" edition="" />
        <vers num="12.0" edition=":hp" />
        <vers num="12.0" edition=":win" />
        <vers num="12.0" edition=":sun" />
        <vers num="12.0" edition=":digital_unix" />
        <vers num="12.0.1" edition="" />
        <vers num="12.0.1" edition=":hp" />
        <vers num="12.0.1" edition=":sun" />
        <vers num="12.0.1" edition=":win" />
        <vers num="12.0.1" edition=":digital_unix" />
        <vers num="12.5" edition="" />
        <vers num="12.5" edition=":hp" />
        <vers num="12.5" edition=":sgi" />
        <vers num="12.5" edition=":sun" />
        <vers num="12.5" edition=":linux" />
        <vers num="12.5" edition=":digital_unix" />
        <vers num="12.5" edition=":win" />
        <vers num="12.5.2" />
        <vers num="12.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0943" published="2005-03-30" name="CVE-2005-0943" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19903" source="XF" patch="1" adv="1">cisco-vpn-3000-dos(19903)</ref>
      <ref url="http://www.securityfocus.com/bid/12948" source="BID" patch="1" adv="1">12948</ref>
      <ref url="http://secunia.com/advisories/14784" source="SECUNIA" patch="1" adv="1">14784</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050330-vpn3k.shtml" source="CISCO" adv="1">20050330 Cisco VPN 3000 Concentrator Vulnerable to Crafted SSL Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3002_hardware_client">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3020_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="2.0" />
        <vers num="2.5.2.a" />
        <vers num="2.5.2.b" />
        <vers num="2.5.2.c" />
        <vers num="2.5.2.d" />
        <vers num="2.5.2.f" />
        <vers num="3.0" />
        <vers num="3.0.3.a" />
        <vers num="3.0.3.b" />
        <vers num="3.0.4" />
        <vers num="3.1" />
        <vers num="3.1(rel)" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.4" />
        <vers num="3.5(rel)" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.7" />
        <vers num="3.6.7d" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.5.b" />
        <vers num="4.1" />
        <vers num="4.1.5.b" />
        <vers num="4.1.7.a" />
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="3.6.3" />
        <vers num="3.6.5" />
        <vers num="3.6.7" />
        <vers num="3.6.7.a" />
        <vers num="3.6.7.b" />
        <vers num="3.6.7.c" />
        <vers num="3.6.7.d" />
        <vers num="3.6.7.f" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0944" published="2005-05-02" name="CVE-2005-0944" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/176380" source="CERT-VN">VU#176380</ref>
      <ref url="http://www.hexview.com/docs/20050331-1.txt" source="MISC" adv="1">http://www.hexview.com/docs/20050331-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111231465920199&amp;w=2" source="BUGTRAQ" adv="1">20050331 [HV-HIGH] Microsoft Jet DB engine vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/442610/100/100/threaded" source="BUGTRAQ">20060808 Re: Will Microsoft patch remarkable old Msjet40.dll issue?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/442446/100/100/threaded" source="BUGTRAQ">20060804 Will Microsoft patch remarkable old Msjet40.dll issue?</ref>
      <ref url="http://blogs.securiteam.com/?p=535" source="MISC">http://blogs.securiteam.com/?p=535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="jet">
        <vers prev="1" num="4.0.8618.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0945" published="2005-05-02" name="CVE-2005-0945" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19864" source="XF" patch="1">acsblog-tags-xss(19864)</ref>
      <ref url="http://securitytracker.com/id?1013584" source="SECTRACK" adv="1">1013584</ref>
      <ref url="http://secunia.com/advisories/14744/" source="SECUNIA" adv="1">14744</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214069029812&amp;w=2" source="BUGTRAQ" adv="1">20050328 Multiple XSS vulnerabilities in ACS Blog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp_press" name="acs_blog">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0946" published="2005-03-29" name="CVE-2005-0946" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the ordering new package page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12917" source="BID" patch="1">12917</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214190111520&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050329 Multiple phpCoin Vulnerabilities</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coinsoft_technologies" name="phpcoin">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0947" published="2005-05-02" name="CVE-2005-0947" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19896" source="XF" patch="1">phpcoin-auxpage-file-include(19896)</ref>
      <ref url="http://www.securityfocus.com/bid/12917" source="BID">12917</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214190111520&amp;w=2" source="BUGTRAQ" adv="1">20050329 Multiple phpCoin Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coinsoft_technologies" name="phpcoin">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0948" published="2005-05-02" name="CVE-2005-0948" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19892" source="XF">portalapp-adclick-sql-injection(19892)</ref>
      <ref url="http://www.securityfocus.com/bid/12936" source="BID">12936</ref>
      <ref url="http://securitytracker.com/id?1013591" source="SECTRACK">1013591</ref>
      <ref url="http://secunia.com/advisories/14749" source="SECUNIA">14749</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111213291118273&amp;w=2" source="BUGTRAQ">20050329 Multiple sql injection, and xss vulnerabilities in PortalApp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iatek" name="portalapp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0949" published="2005-05-02" name="CVE-2005-0949" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19891" source="XF">portalapp-contentasp-xss(19891)</ref>
      <ref url="http://www.securityfocus.com/bid/12936" source="BID">12936</ref>
      <ref url="http://securitytracker.com/id?1013591" source="SECTRACK">1013591</ref>
      <ref url="http://secunia.com/advisories/14749" source="SECUNIA">14749</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111213291118273&amp;w=2" source="BUGTRAQ">20050329 Multiple sql injection, and xss vulnerabilities in PortalApp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iatek" name="portalapp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0950" published="2005-03-29" name="CVE-2005-0950" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19900" source="XF" patch="1" adv="1">faststone-dotdot-directory-traversal(19900)</ref>
      <ref url="http://www.securityfocus.com/bid/12937" source="BID" patch="1" adv="1">12937</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/FastStone4in1Browser1.2-adv.txt" source="MISC" patch="1" adv="1">http://www.autistici.org/fdonato/advisory/FastStone4in1Browser1.2-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1013596" source="SECTRACK" patch="1" adv="1">1013596</ref>
      <ref url="http://secunia.com/advisories/14743" source="SECUNIA" patch="1" adv="1">14743</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111213034206802&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050329 directory traversal in FastStone 4in1 Browser 1.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faststone" name="4in1_browser">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0951" reject="1" published="2005-05-02" name="CVE-2005-0951" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **   DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: this candidate was created as a result of an analysis error for a researcher advisory for an issue that already existed.  It stated an incorrect parameter, which was not part of the vulnerability at all. Notes: CVE users should not reference this candidate at all.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0952" published="2005-05-02" name="CVE-2005-0952" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111221940107161&amp;w=2" source="BUGTRAQ">20050330 PaFileDB Version 3.1 and below are exploitable via a XSS and a SQL injection vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29394" source="XF">pafiledb-action-xss(29394)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/448017/100/100/threaded" source="BUGTRAQ">20061008 XSS IN paFileDB 3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0953" published="2005-05-02" name="CVE-2005-0953" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html" source="CERT">TA07-319A</ref>
      <ref url="http://www.debian.org/security/2005/dsa-730" source="DEBIAN" patch="1" adv="1">DSA-730</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19926" source="XF">bzip2-toctou-symlink(19926)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3868" source="VUPEN">ADV-2007-3868</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3525" source="VUPEN">ADV-2007-3525</ref>
      <ref url="http://www.securityfocus.com/bid/12954" source="BID">12954</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456430/30/8730/threaded" source="BUGTRAQ">20070109 rPSA-2007-0004-1 bzip2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10902" source="OVAL">oval:org.mitre.oval:def:10902</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111229375217633&amp;w=2" source="BUGTRAQ">20050330 bzip2 TOCTOU file-permissions vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/26444" source="BID">26444</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-474.html" source="REDHAT">RHSA-2005:474</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.html" source="OPENPKG">OpenPKG-SA-2007.002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:026" source="MANDRIVA">MDKSA-2006:026</ref>
      <ref url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html" source="FEDORA">FLSA:158801</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200191-1" source="SUNALERT">200191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103118-1" source="SUNALERT">103118</ref>
      <ref url="http://secunia.com/advisories/29940" source="SECUNIA">29940</ref>
      <ref url="http://secunia.com/advisories/27643" source="SECUNIA">27643</ref>
      <ref url="http://secunia.com/advisories/27274" source="SECUNIA">27274</ref>
      <ref url="http://secunia.com/advisories/19183" source="SECUNIA">19183</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html" source="APPLE">APPLE-SA-2007-11-14</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307041" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307041</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc" source="SGI">20060301-01-U</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-004.txt.asc" source="NETBSD">NetBSD-SA2008-004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1154" source="OVAL" sig="1">oval:org.mitre.oval:def:1154</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bzip" name="bzip2">
        <vers num="0.9" />
        <vers num="0.9.5_a" />
        <vers num="0.9.5_b" />
        <vers num="0.9.5_c" />
        <vers num="0.9.5_d" />
        <vers num="0.9_a" />
        <vers num="0.9_b" />
        <vers num="0.9_c" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0954" published="2005-05-02" name="CVE-2005-0954" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15507" source="XF">winxp-explorer-wmf-dos(15507)</ref>
      <ref url="http://www.securityfocus.com/bid/9892" source="BID">9892</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5CP081FFFY.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5CP081FFFY.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111231106513788&amp;w=2" source="BUGTRAQ" adv="1">20050331 WindowsXP malformed .wmf files DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
      <prod vendor="microsoft" name="windows_explorer">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0955" published="2005-05-02" name="CVE-2005-0955" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in InterAKT MX Shop 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id_ctg parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14793" source="SECUNIA" adv="1">14793</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111230101127767&amp;w=2" source="BUGTRAQ" adv="1">20050331 MX Shop 1.1.1 and MX Kart 1.1.2 are vulnerable to multiple SQL injection vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/12957" source="BID">12957</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interakt" name="mx_shop">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0956" published="2005-05-02" name="CVE-2005-0956" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in InterAKT MX Kart 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_man parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14793" source="SECUNIA">14793</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111230101127767&amp;w=2" source="BUGTRAQ">20050331 MX Shop 1.1.1 and MX Kart 1.1.2 are vulnerable to multiple SQL injection vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interakt" name="mx_kart">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0957" published="2005-03-31" name="CVE-2005-0957" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bay Technical Associates RPC-3 Telnet Host 3.05 allows remote attackers to bypass authentication by pressing the escape and enter keys at the username prompt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19921" source="XF" adv="1">rpc3-logon-bypass-authentication(19921)</ref>
      <ref url="http://www.securityfocus.com/bid/12955" source="BID" adv="1">12955</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111230568025271&amp;w=2" source="BUGTRAQ" adv="1">20050331 Bay Technical Associates telnet server logon bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bay_technical_associates" name="rpc3_telnet">
        <vers num="f_3.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0958" published="2005-05-02" name="CVE-2005-0958" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tripbit.org/advisories/TA-040305.txt" source="MISC">http://www.tripbit.org/advisories/TA-040305.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12947" source="BID">12947</ref>
      <ref url="http://www.securiteam.com/exploits/5KP0W0AF5K.html" source="MISC">http://www.securiteam.com/exploits/5KP0W0AF5K.html</ref>
      <ref url="http://unl0ck.org/files/papers/mtftpd.txt" source="MISC">http://unl0ck.org/files/papers/mtftpd.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yepyep" name="mtftpd">
        <vers num="0.1a" />
        <vers num="0.2" />
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0959" published="2005-05-02" name="CVE-2005-0959" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12947" source="BID">12947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yepyep" name="mtftpd">
        <vers num="0.1a" />
        <vers num="0.2" />
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0960" published="2005-05-02" name="CVE-2005-0960" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the SACK functionality in (1) tcp_input.c and (2) tcp_usrreq.c OpenBSD 3.5 and 3.6 allow remote attackers to cause a denial of service (memory exhaustion or system crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12951" source="BID" patch="1">12951</ref>
      <ref url="http://www.openbsd.org/errata35.html#sack" source="OPENBSD" patch="1">20050330 [3.5] 030: RELIABILITY FIX: March 30, 2005</ref>
      <ref url="http://www.openbsd.org/errata.html#sack" source="OPENBSD" patch="1">20050330 [3.6] 013: RELIABILITY FIX: March 30, 2005</ref>
      <ref url="http://securitytracker.com/id?1013611" source="SECTRACK" patch="1">1013611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0961" published="2005-05-02" name="CVE-2005-0961" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14730" source="SECUNIA" patch="1" adv="1">14730</ref>
      <ref url="http://lists.horde.org/archives/announce/2005/000176.html" source="CONFIRM" patch="1">http://lists.horde.org/archives/announce/2005/000176.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_sr.html" source="SUSE">SUSE-SR:2005:016</ref>
      <ref url="http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.49&amp;r2=1.515.2.93&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.49&amp;r2=1.515.2.93&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="application_framework">
        <vers num="3.0.4_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0962" published="2005-05-02" name="CVE-2005-0962" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19904" source="XF">squirrelcart-index-sql-injection(19904)</ref>
      <ref url="http://www.securityfocus.com/bid/12944" source="BID">12944</ref>
      <ref url="http://secunia.com/advisories/14770" source="SECUNIA" adv="1">14770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lighthouse_development" name="squirrelcart">
        <vers num="1.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0963" published="2005-05-02" name="CVE-2005-0963" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed.  NOTE: it has been debated as to whether or not this issue poses a security vulnerability, since administrative privileges would be required, and other DoS attacks are possible with such privileges.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19895" source="XF">toshiba-acpi-bios-dos(19895)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111229803502643&amp;w=2" source="BUGTRAQ">20050331 RE: Portcullis Security Advisory 05-011 ACPI 1.6 BIOS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111229708208629&amp;w=2" source="BUGTRAQ">20050331 Re: Portcullis Security Advisory 05-011 ACPI 1.6 BIOS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214319914810&amp;w=2" source="BUGTRAQ" adv="1">20050329 Portcullis Security Advisory 05-011 ACPI 1.6 BIOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toshiba" name="acpi_flash_bios">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0964" published="2005-05-02" name="CVE-2005-0964" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19893" source="XF" patch="1">kerio-firewall-rule-security-bypass(19893)</ref>
      <ref url="http://www.securityfocus.com/bid/12946" source="BID" patch="1">12946</ref>
      <ref url="http://www.kerio.com/security_advisory.html#0503" source="CONFIRM" adv="1">http://www.kerio.com/security_advisory.html#0503</ref>
      <ref url="http://securitytracker.com/id?1013607" source="SECTRACK">1013607</ref>
      <ref url="http://secunia.com/advisories/14717" source="SECUNIA" adv="1">14717</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="personal_firewall">
        <vers num="4.0.10" />
        <vers num="4.0.16" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0965" published="2005-05-02" name="CVE-2005-0965" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14815" source="SECUNIA" patch="1" adv="1">14815</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11292" source="OVAL">oval:org.mitre.oval:def:11292</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238715307356&amp;w=2" source="BUGTRAQ" adv="1">20050401 multiple remote denial of service vulnerabilities in Gaim</ref>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=13" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/index.php?id=13</ref>
      <ref url="http://www.securityfocus.com/bid/12999" source="BID">12999</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-365.html" source="REDHAT">RHSA-2005:365</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:071" source="MANDRAKE">MDKSA-2005:071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0966" published="2005-05-02" name="CVE-2005-0966" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=235&amp;release_id=317750" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=235&amp;release_id=317750</ref>
      <ref url="http://secunia.com/advisories/14815" source="SECUNIA" patch="1" adv="1">14815</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19939" source="XF">gaim-ircmsginvite-dos(19939)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19937" source="XF">gaim-irc-plugin-bo(19937)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9185" source="OVAL">oval:org.mitre.oval:def:9185</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238715307356&amp;w=2" source="BUGTRAQ" adv="1">20050401 multiple remote denial of service vulnerabilities in Gaim</ref>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=14" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/index.php?id=14</ref>
      <ref url="http://www.securityfocus.com/bid/13003" source="BID">13003</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-365.html" source="REDHAT">RHSA-2005:365</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:071" source="MANDRAKE">MDKSA-2005:071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0967" published="2005-05-02" name="CVE-2005-0967" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013645" source="SECTRACK" patch="1">1013645</ref>
      <ref url="http://secunia.com/advisories/14815" source="SECUNIA" patch="1" adv="1">14815</ref>
      <ref url="http://sourceforge.net/tracker/?func=detail&amp;aid=1172115&amp;group_id=235&amp;atid=100235" source="CONFIRM">http://sourceforge.net/tracker/?func=detail&amp;aid=1172115&amp;group_id=235&amp;atid=100235</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9657" source="OVAL">oval:org.mitre.oval:def:9657</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=15" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/?id=15</ref>
      <ref url="http://www.securityfocus.com/bid/13004" source="BID">13004</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-365.html" source="REDHAT">RHSA-2005:365</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:071" source="MANDRAKE">MDKSA-2005:071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0968" published="2005-05-02" name="CVE-2005-0968" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Computer Associates (CA) eTrust Intrusion Detection 3.0 allows remote attackers to cause a denial of service via large size values that are not properly validated before calling the CPImportKey function in the Crypto API.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=223&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050405 Computer Associates eTrust Intrusion Detection System CPImportKey DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0969" published="2005-05-12" name="CVE-2005-0969" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html" source="APPLE">APPLE-SA-2005-04-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0970" published="2005-05-02" name="CVE-2005-0970" modified="2009-10-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow attackers to conduct unauthorized activities with escalated privileges via vulnerable scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html" source="APPLE">APPLE-SA-2005-04-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0971" published="2005-05-12" name="CVE-2005-0971" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/212190" source="CERT-VN">VU#212190</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-04-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0972" published="2005-05-12" name="CVE-2005-0972" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/185702" source="CERT-VN">VU#185702</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html" source="APPLE">APPLE-SA-2005-04-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0973" published="2005-05-12" name="CVE-2005-0973" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-04-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0974" published="2005-05-12" name="CVE-2005-0974" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/713614" source="CERT-VN">VU#713614</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00004.html" source="APPLE">APPLE-SA-2005-05-19</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-04-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0975" published="2005-05-02" name="CVE-2005-0975" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to cause a denial of service (CPU consumption) via a crafted mach-o header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013735" source="SECTRACK" patch="1">1013735</ref>
      <ref url="http://secunia.com/advisories/13902" source="SECUNIA" patch="1" adv="1">13902</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18979" source="XF">macos-machloader-dos(18979)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0041" source="VUPEN">ADV-2005-0041</ref>
      <ref url="http://www.securityfocus.com/bid/12314" source="BID">12314</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-185.shtml" source="CIAC" adv="1">P-185</ref>
      <ref url="http://securitytracker.com/id?1012941" source="SECTRACK">1012941</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616533903671&amp;w=2" source="BUGTRAQ" adv="1">20050119 Darwin Kernel Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-04-15</ref>
      <ref url="http://felinemenace.org/advisories/macosx.txt" source="MISC" adv="1">http://felinemenace.org/advisories/macosx.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
      </prod>
      <prod vendor="opendarwin" name="darwin_kernel">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0976" published="2005-05-02" name="CVE-2005-0976" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://remahl.se/david/vuln/001/" source="MISC">http://remahl.se/david/vuln/001/</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html" source="APPLE">APPLE-SA-2005-04-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.2" />
      </prod>
      <prod vendor="hmdt" name="shiira">
        <vers num="0.93" />
      </prod>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0977" published="2005-05-02" name="CVE-2005-0977" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-103-1" source="UBUNTU" adv="1">USN-103-1</ref>
      <ref url="http://www.securityfocus.com/bid/12970" source="BID">12970</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10400" source="OVAL">oval:org.mitre.oval:def:10400</ref>
      <ref url="http://lkml.org/lkml/2005/2/5/111" source="CONFIRM">http://lkml.org/lkml/2005/2/5/111</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@420551fbRlv9-QG6Gw9Lw_bKVfPSsg" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@420551fbRlv9-QG6Gw9Lw_bKVfPSsg</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0978" published="2005-05-02" name="CVE-2005-0978" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a .. (dot dot) in a PUSH command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19930" source="XF">bluesoleil-object-push-directory-traversal(19930)</ref>
      <ref url="http://www.securityfocus.com/bid/12961" source="BID">12961</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0401a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2005-0401a%5D.txt</ref>
      <ref url="http://secunia.com/advisories/14790/" source="SECUNIA">14790</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238511206503&amp;w=2" source="BUGTRAQ">20050401 DMA[2005-0401a] - 'IVT BlueSoleil Directory Transversal'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ivt" name="bluesoleil">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0979" published="2005-05-02" name="CVE-2005-0979" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted values in a profile file, as demonstrated using a long SysName field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19934" source="XF">rumba-profile-values-bo(19934)</ref>
      <ref url="http://www.securityfocus.com/bid/12965" source="BID">12965</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238364916500&amp;w=2" source="BUGTRAQ" adv="1">20050401 Buffer Overflow within the RUMBA product</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netmanage" name="rumba">
        <vers num="7.3" />
        <vers num="7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0980" published="2005-05-02" name="CVE-2005-0980" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modifying the view parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12973" source="BID">12973</ref>
      <ref url="http://secunia.com/advisories/14802" source="SECUNIA" adv="1">14802</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111247198021626&amp;w=2" source="BUGTRAQ" adv="1">20050402 AlstraSoft EPay Pro v2.0 has file include and multiple xss</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alstrasoft" name="epay">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0981" published="2005-05-02" name="CVE-2005-0981" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) payment or (2) send parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12974" source="BID">12974</ref>
      <ref url="http://secunia.com/advisories/14802" source="SECUNIA" adv="1">14802</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111247198021626&amp;w=2" source="BUGTRAQ" adv="1">20050402 AlstraSoft EPay Pro v2.0 has file include and multiple xss</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alstrasoft" name="epay">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0982" published="2005-05-02" name="CVE-2005-0982" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Yet Another Forum.net 0.9.9 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, or (3) Subject field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013632" source="SECTRACK">1013632</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111247338301262&amp;w=2" source="BUGTRAQ">20050402 Yet Another Forum.net XSS vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yet_another_forum.net" name="yet_another_forum.net">
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0983" published="2005-05-02" name="CVE-2005-0983" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12976" source="BID">12976</ref>
      <ref url="http://secunia.com/advisories/14811" source="SECUNIA">14811</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111246796918067&amp;w=2" source="BUGTRAQ">20050402 In-game players kicking in the Quake 3 engine</ref>
      <ref url="http://bani.anime.net/banimod/forums/viewtopic.php?p=27322" source="MISC">http://bani.anime.net/banimod/forums/viewtopic.php?p=27322</ref>
      <ref url="http://aluigi.altervista.org/adv/q3msgboom-adv.txt" source="MISC">http://aluigi.altervista.org/adv/q3msgboom-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activision" name="call_of_duty">
        <vers num="1.4" />
        <vers num="1.5b" />
      </prod>
      <prod vendor="activision" name="call_of_duty_united_offensive">
        <vers num="1.41" />
        <vers num="1.51b" />
      </prod>
      <prod vendor="activision" name="return_to_castle_wolfenstein">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="id_software" name="quake_3_arena">
        <vers num="1.1.7" />
        <vers num="1.16" />
        <vers num="1.31" />
      </prod>
      <prod vendor="id_software" name="quake_3_arena_server">
        <vers num="1.29f" />
        <vers num="1.29g" />
      </prod>
      <prod vendor="id_software" name="quake_3_engine">
        <vers num="" />
      </prod>
      <prod vendor="id_software" name="wolfenstein_enemy_territory">
        <vers num="1.0.2" />
        <vers num="2.56" />
      </prod>
      <prod vendor="lucasarts" name="star_wars_jedi_knight_ii_jedi_outcast">
        <vers num="1.0.4" />
      </prod>
      <prod vendor="lucasarts" name="star_wars_jedi_knight_jedi_academy">
        <vers num="1.0.11" />
      </prod>
      <prod vendor="raven_software" name="soldier_of_fortune_2">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0984" published="2005-05-02" name="CVE-2005-0984" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12977" source="BID">12977</ref>
      <ref url="http://secunia.com/advisories/14809" source="SECUNIA" adv="1">14809</ref>
      <ref url="http://aluigi.altervista.org/adv/jamsgbof-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/jamsgbof-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111246855213653&amp;w=2" source="BUGTRAQ">20050402 In-game server buffer-overflow in Jedi Academy 1.011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucasarts" name="star_wars_jedi_knight_jedi_academy">
        <vers num="1.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0985" published="2005-12-31" name="CVE-2005-0985" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan control unit (FCU) driver.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=301324" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=301324</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0986" published="2005-05-02" name="CVE-2005-0986" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted.  NOTE: IBM has reported that it is unable to replicate this issue.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0322" source="VUPEN">ADV-2005-0322</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=224&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050406 IBM Lotus Domino Server Web Service DoS Vulnerability</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21202446" source="MISC" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg21202446</ref>
      <ref url="http://secunia.com/advisories/14858" source="SECUNIA" adv="1">14858</ref>
      <ref url="http://news.zdnet.co.uk/software/applications/0,39020384,39194293,00.htm" source="MISC">http://news.zdnet.co.uk/software/applications/0,39020384,39194293,00.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_server">
        <vers num="6.0.3" />
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0987" published="2005-05-02" name="CVE-2005-0987" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013622" source="SECTRACK" patch="1">1013622</ref>
      <ref url="http://www.ircservices.esper.net/Changes.txt" source="CONFIRM">http://www.ircservices.esper.net/Changes.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irc_services" name="nickserv_listlinks">
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.2" />
        <vers num="5.0.20" />
        <vers num="5.0.21" />
        <vers num="5.0.22" />
        <vers num="5.0.23" />
        <vers num="5.0.24" />
        <vers num="5.0.25" />
        <vers num="5.0.26" />
        <vers num="5.0.27" />
        <vers num="5.0.28" />
        <vers num="5.0.29" />
        <vers num="5.0.3" />
        <vers num="5.0.30" />
        <vers num="5.0.31" />
        <vers num="5.0.32" />
        <vers num="5.0.33" />
        <vers num="5.0.34" />
        <vers num="5.0.35" />
        <vers num="5.0.36" />
        <vers num="5.0.37" />
        <vers num="5.0.38" />
        <vers num="5.0.39" />
        <vers num="5.0.4" />
        <vers num="5.0.40" />
        <vers num="5.0.41" />
        <vers num="5.0.42" />
        <vers num="5.0.43" />
        <vers num="5.0.44" />
        <vers num="5.0.45" />
        <vers num="5.0.46" />
        <vers num="5.0.47" />
        <vers num="5.0.48" />
        <vers num="5.0.49" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0988" published="2005-05-02" name="CVE-2005-0988" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://www.securityfocus.com/bid/12996" source="BID" patch="1">12996</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.securityfocus.com/archive/1/394965" source="BUGTRAQ" adv="1">20050404 gzip TOCTOU file-permissions vulnerability</ref>
      <ref url="http://www.osvdb.org/15487" source="OSVDB">15487</ref>
      <ref url="http://www.debian.org/security/2005/dsa-752" source="DEBIAN">DSA-752</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1" source="SUNALERT">101816</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.555852" source="SLACKWARE">SSA:2006-262</ref>
      <ref url="http://secunia.com/advisories/22033" source="SECUNIA">22033</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://secunia.com/advisories/18100" source="SECUNIA">18100</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-357.html" source="REDHAT">RHSA-2005:357</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10242" source="OVAL">oval:org.mitre.oval:def:10242</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt" source="SCO">SCOSA-2005.58</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:765" source="OVAL" sig="1">oval:org.mitre.oval:def:765</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1169" source="OVAL" sig="1">oval:org.mitre.oval:def:1169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gzip">
        <vers num="1.2.4" />
        <vers num="1.2.4a" />
        <vers num="1.3.3" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="release_p8" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="release_p3" />
        <vers num="4.11" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
        <vers num="5.4" edition="releng" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_appliance_server">
        <vers num="1.0_hosting" />
        <vers num="1.0_workgroup" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_desktop">
        <vers num="10.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_home">
        <vers num="" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="10.0" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
        <vers num="5.04" edition="" />
        <vers num="5.04" edition=":i386" />
        <vers num="5.04" edition=":powerpc" />
        <vers num="5.04" edition=":amd64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0989" published="2005-05-02" name="CVE-2005-0989" modified="2011-07-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-386.html" source="REDHAT" patch="1" adv="1">RHSA-2005:386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-18</ref>
      <ref url="http://secunia.com/advisories/14821" source="SECUNIA" patch="1" adv="1">14821</ref>
      <ref url="http://secunia.com/advisories/14820" source="SECUNIA" patch="1" adv="1">14820</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=288688" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=288688</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.securityfocus.com/bid/12988" source="BID">12988</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-33.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-33.html</ref>
      <ref url="http://securitytracker.com/id?1013643" source="SECTRACK">1013643</ref>
      <ref url="http://securitytracker.com/id?1013635" source="SECTRACK">1013635</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA" adv="1">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11706" source="OVAL">oval:org.mitre.oval:def:11706</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100025" source="OVAL" sig="1">oval:org.mitre.oval:def:100025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7.6" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0990" published="2005-05-02" name="CVE-2005-0990" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19957" source="XF" patch="1">sharutils-temp-file-symlink(19957)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-377.html" source="REDHAT" patch="1" adv="1">RHSA-2005:377</ref>
      <ref url="https://bugzilla.ubuntu.com/show_bug.cgi?id=8459" source="MISC" adv="1">https://bugzilla.ubuntu.com/show_bug.cgi?id=8459</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-104-1" source="UBUNTU" adv="1">USN-104-1</ref>
      <ref url="http://www.securityfocus.com/bid/12981" source="BID">12981</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9613" source="OVAL">oval:org.mitre.oval:def:9613</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=302412" source="MISC" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=302412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="sharutils">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0991" published="2005-05-02" name="CVE-2005-0991" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12992" source="BID">12992</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY59207&amp;apar=only" source="AIXAPAR">IY59207</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY59206&amp;apar=only" source="AIXAPAR">IY59206</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY59205&amp;apar=only" source="AIXAPAR">IY59205</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0992" published="2005-05-02" name="CVE-2005-0992" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19940" source="XF" patch="1">phpmyadmin-convcharset-xss(19940)</ref>
      <ref url="http://www.securityfocus.com/bid/12982" source="BID" patch="1">12982</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-08</ref>
      <ref url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-3" source="CONFIRM" adv="1">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-3</ref>
      <ref url="http://www.arrelnet.com/advisories/adv20050403.html" source="MISC" adv="1">http://www.arrelnet.com/advisories/adv20050403.html</ref>
      <ref url="http://secunia.com/advisories/14799" source="SECUNIA" adv="1">14799</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264361622660&amp;w=2" source="BUGTRAQ" adv="1">20050404 phpMyAdmin Cross-site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2_pre1" />
        <vers num="2.2_pre2" />
        <vers num="2.2_rc1" />
        <vers num="2.2_rc2" />
        <vers num="2.2_rc3" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.5_pl1" />
        <vers num="2.5.5_rc1" />
        <vers num="2.5.5_rc2" />
        <vers num="2.5.6_rc1" />
        <vers num="2.5.7" />
        <vers num="2.5.7_pl1" />
        <vers num="2.6.0_pl1" />
        <vers num="2.6.0_pl2" />
        <vers num="2.6.0_pl3" />
        <vers num="2.6.1" />
        <vers num="2.6.1_pl1" />
        <vers num="2.6.1_pl3" />
        <vers num="2.6.1_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0993" published="2005-05-02" name="CVE-2005-0993" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12986" source="BID" patch="1">12986</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263251718491&amp;w=2" source="BUGTRAQ" adv="1">20050404 possible privilege escalation on Sco OpenServer 5.0.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0994" published="2005-05-02" name="CVE-2005-0994" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt parameters to advSearch_h.asp, and possibly (2) the offset parameter to tarinasworld_butterflyjournal.asp.  NOTE: it is possible that item (2) is the result of a typo or editing error from the original research report.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12990" source="BID">12990</ref>
      <ref url="http://www.osvdb.org/15265" source="OSVDB">15265</ref>
      <ref url="http://www.osvdb.org/15263" source="OSVDB">15263</ref>
      <ref url="http://secunia.com/advisories/14833" source="SECUNIA" adv="1">14833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0995" published="2005-05-02" name="CVE-2005-0995" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp. NOTE: it has been reported that storelocator_submit.asp does not exist in ProductCart.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12990" source="BID">12990</ref>
      <ref url="http://www.osvdb.org/15268" source="OSVDB">15268</ref>
      <ref url="http://www.osvdb.org/15266" source="OSVDB">15266</ref>
      <ref url="http://www.osvdb.org/15264" source="OSVDB">15264</ref>
      <ref url="http://secunia.com/advisories/14833" source="SECUNIA" adv="1">14833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0996" published="2005-05-02" name="CVE-2005-0996" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the email or url parameters in the Add function, (2) the min parameter in the viewsdownload function, or (3) the min parameter in the search function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111289685724764&amp;w=2" source="BUGTRAQ" adv="1">20050403 [SECURITYREASON.COM] phpnuke 7.6 Multiple vulnerabilities in Downloads Module cXIb8O3.13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0997" published="2005-05-02" name="CVE-2005-0997" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the email or url parameters in the Add function, (2) the url parameter in the modifylinkrequestS function, (3) the orderby or min parameters in the viewlink function, (4) the orderby, min, or show parameters in the search function, or (5) the ratenum parameter in the MostPopular function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111289685724764&amp;w=2" source="BUGTRAQ" adv="1">20050403 [SECURITYREASON.COM] phpnuke 7.6 Multiple vulnerabilities in Web_Links Module cXIb8O3.14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0998" published="2005-05-02" name="CVE-2005-0998" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web_Links module for PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via an invalid show parameter, which triggers a division by zero PHP error that leaks the full pathname of the server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111289685724764&amp;w=2" source="BUGTRAQ" adv="1">20050403 [SECURITYREASON.COM] phpnuke 7.6 Multiple vulnerabilities in Web_Links Module cXIb8O3.14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0999" published="2005-05-02" name="CVE-2005-0999" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/advisory-41.html" source="MISC" adv="1">http://www.waraxe.us/advisory-41.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111281649616901&amp;w=2" source="BUGTRAQ" adv="1">20050406 [waraxe-2005-SA#041] - Critical Sql Injection in PhpNuke 6.x-7.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1000" published="2005-05-02" name="CVE-2005-1000" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19952" source="XF" patch="1">phpnuke-modulesphp-xss(19952)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263454308478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050403 Full path disclosure and XSS in PHPNuke</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.html" source="BUGTRAQ" adv="1">20050404 [SECURITYREASON.COM] PhpNuke 7.6=>x Multiple vulnerabilities cXIb8O3.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1001" published="2005-05-02" name="CVE-2005-1001" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the full pathname of the web server in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19953" source="XF" patch="1">phpnuke-modulesphp-path-disclosure(19953)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.html" source="BUGTRAQ" patch="1" adv="1">20050404 [SECURITYREASON.COM] PhpNuke 7.6=>x Multiple vulnerabilities cXIb8O3.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1002" published="2005-05-02" name="CVE-2005-1002" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">logwebftbs2000.exe in Logics Software File Transfer (LOG-FT) allows remote attackers to read arbitrary files via modified (1) VAR_FT_LANG and (2) VAR_FT_TMPL parameters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12998" source="BID">12998</ref>
      <ref url="http://secunia.com/advisories/14851" source="SECUNIA">14851</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111271950916436&amp;w=2" source="BUGTRAQ">20050405 Logics Software BS2000 Host to Web Client ALL PLATFORMS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logics_software" name="log-ft">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1003" published="2005-05-02" name="CVE-2005-1003" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php for ProfitCode PayProCart 3.0 allows remote attackers to include arbitrary PHP files via .. (dot dot) sequences in the modID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19954" source="XF">payprocart-dotdot-directory-traversal(19954)</ref>
      <ref url="http://securitytracker.com/id?1013640" source="SECTRACK">1013640</ref>
      <ref url="http://secunia.com/advisories/14832" source="SECUNIA">14832</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264602406090&amp;w=2" source="BUGTRAQ">20050404 Authenticaion bypass, Directory transversal and XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="profitcode" name="payprocart">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1004" published="2005-05-02" name="CVE-2005-1004" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML via the sgnuptype parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19955" source="XF">Payprocart-usrdetails-xss(19955)</ref>
      <ref url="http://securitytracker.com/id?1013640" source="SECTRACK">1013640</ref>
      <ref url="http://secunia.com/advisories/14832" source="SECUNIA">14832</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264602406090&amp;w=2" source="BUGTRAQ">20050404 Authenticaion bypass, Directory transversal and XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="profitcode" name="payprocart">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1005" published="2005-05-02" name="CVE-2005-1005" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstrated via a direct request to adminshop/index.php with hex-encoded .. sequences in the ftoedit parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19956" source="XF">payprocart-index-bypass-authentication(19956)</ref>
      <ref url="http://securitytracker.com/id?1013640" source="SECTRACK">1013640</ref>
      <ref url="http://secunia.com/advisories/14832" source="SECUNIA">14832</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264602406090&amp;w=2" source="BUGTRAQ">20050404 Authenticaion bypass, Directory transversal and XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="profitcode" name="payprocart">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1006" published="2005-05-02" name="CVE-2005-1006" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) the user login name, which is not filtered when the administrator views the log file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19960" source="XF">sonicwall-username-code-execution(19960)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19958" source="XF">sonicwall-http-get-requests-xss(19958)</ref>
      <ref url="http://www.securityfocus.com/bid/12984" source="BID">12984</ref>
      <ref url="http://www.oliverkarow.de/research/SonicWall.txt" source="MISC">http://www.oliverkarow.de/research/SonicWall.txt</ref>
      <ref url="http://securitytracker.com/id?1013638" source="SECTRACK">1013638</ref>
      <ref url="http://secunia.com/advisories/14823" source="SECUNIA">14823</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0041.html" source="BUGTRAQ">20050404 SonicWALL SOHO/10 - XSS vulnerability</ref>
      <ref url="http://www.osvdb.org/15262" source="OSVDB">15262</ref>
      <ref url="http://www.osvdb.org/15261" source="OSVDB">15261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicwall" name="soho">
        <vers num="5.1.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1007" published="2005-05-02" name="CVE-2005-1007" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19961" source="XF">communigatepro-list-dos(19961)</ref>
      <ref url="http://www.stalker.com/CommuniGatePro/History.html" source="CONFIRM">http://www.stalker.com/CommuniGatePro/History.html</ref>
      <ref url="http://www.osvdb.org/15257" source="OSVDB">15257</ref>
      <ref url="http://secunia.com/advisories/14604" source="SECUNIA" adv="1">14604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalker" name="communigate_pro">
        <vers num="4.3c1" />
        <vers num="4.3c2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1008" published="2005-05-02" name="CVE-2005-1008" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via a "javascript:" URL in an IMG tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12958" source="BID">12958</ref>
      <ref url="http://securitytracker.com/id?1013614" source="SECTRACK">1013614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-dev" name="xm_forum">
        <vers num="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1009" published="2005-05-02" name="CVE-2005-1009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name entry in the configure.cfg file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19932" source="XF">netvault-configurecfg-bo(19932)</ref>
      <ref url="http://www.securityfocus.com/bid/12967" source="BID">12967</ref>
      <ref url="http://www.securityfocus.com/archive/1/394801" source="BUGTRAQ" adv="1">20050401 [Hat-Squad Advisory] Bakbone NetVault Heap overflow Vulnerabilities</ref>
      <ref url="http://www.hat-squad.com/en/000165.html" source="MISC" adv="1">http://www.hat-squad.com/en/000165.html</ref>
      <ref url="http://www.hat-squad.com/en/000164.html" source="MISC" adv="1">http://www.hat-squad.com/en/000164.html</ref>
      <ref url="http://www.class101.org/netv-remhbof.pdf" source="MISC" adv="1">http://www.class101.org/netv-remhbof.pdf</ref>
      <ref url="http://www.class101.org/netv-locsbof.pdf" source="MISC" adv="1">http://www.class101.org/netv-locsbof.pdf</ref>
      <ref url="http://securitytracker.com/id?1013625" source="SECTRACK">1013625</ref>
      <ref url="http://secunia.com/advisories/14814" source="SECUNIA" adv="1">14814</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bakbone" name="netvault">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1010" published="2005-05-02" name="CVE-2005-1010" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Comersus Cart 6 allows remote attackers to inject arbitrary web script or HTML via the account username.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19962" source="XF">comersus-username-xss(19962)</ref>
      <ref url="http://www.securityfocus.com/bid/13000" source="BID">13000</ref>
      <ref url="http://securitytracker.com/id?1013634" source="SECTRACK">1013634</ref>
      <ref url="http://secunia.com/advisories/14825" source="SECUNIA">14825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_cart">
        <vers num="6.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1011" published="2005-05-02" name="CVE-2005-1011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zone-h.com/en/advisories/read/id=7367/" source="MISC">http://www.zone-h.com/en/advisories/read/id=7367/</ref>
      <ref url="http://www.securityfocus.com/bid/12985" source="BID">12985</ref>
      <ref url="http://securitytracker.com/id?1013631" source="SECTRACK">1013631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iatek" name="siteenable">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1012" published="2005-05-02" name="CVE-2005-1012" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the contenttype parameter to content.asp, (2) the title, or (3) the description.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19891" source="XF">portalapp-contentasp-xss(19891)</ref>
      <ref url="http://www.zone-h.com/en/advisories/read/id=7367/" source="MISC" adv="1">http://www.zone-h.com/en/advisories/read/id=7367/</ref>
      <ref url="http://securitytracker.com/id?1013631" source="SECTRACK">1013631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iatek" name="siteenable">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1013" published="2005-05-02" name="CVE-2005-1013" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to cause a denial of service (server crash) via an EHLO command with a Unicode string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19973" source="XF" patch="1">mailenable-ehlo-dos(19973)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19948" source="XF" patch="1">mailenable-smtp-dos(19948)</ref>
      <ref url="http://www.securityfocus.com/bid/12994" source="BID" patch="1">12994</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5HP031PFFG.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/windowsntfocus/5HP031PFFG.html</ref>
      <ref url="http://www.mailenable.com/hotfix/" source="CONFIRM" patch="1">http://www.mailenable.com/hotfix/</ref>
      <ref url="http://securitytracker.com/id?1013637" source="SECTRACK" patch="1">1013637</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111273637518494&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050405 MailEnable Smtpd remote Dos [x0n3-h4ck]</ref>
      <ref url="http://www.osvdb.org/15232" source="OSVDB">15232</ref>
      <ref url="http://secunia.com/advisories/14812" source="SECUNIA">14812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_enterprise">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
      </prod>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1014" published="2005-05-02" name="CVE-2005-1014" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP service for MailEnable Enterprise 1.04 and earlier and Professional 1.54 allows remote attackers to execute arbitrary code via a long AUTHENTICATE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19947" source="XF" patch="1">mailenable-imap-dos(19947)</ref>
      <ref url="http://www.securityfocus.com/bid/12995" source="BID" patch="1">12995</ref>
      <ref url="http://www.mailenable.com/hotfix/" source="CONFIRM" patch="1">http://www.mailenable.com/hotfix/</ref>
      <ref url="http://securitytracker.com/id?1013637" source="SECTRACK" patch="1">1013637</ref>
      <ref url="http://secunia.com/advisories/14812" source="SECUNIA" patch="1" adv="1">14812</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-April/033123.html" source="FULLDISC" adv="1">20050405 MailEnable Imapd remote BoF + Exploit [x0n3-h4ck]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_enterprise">
        <vers num="1.0" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
      </prod>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1015" published="2005-05-02" name="CVE-2005-1015" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-April/033144.html" source="FULLDISC" adv="1">20050406 Re: MailEnable Imapd remote BoF + Exploit [x0n3-h4ck]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="imapd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1016" published="2005-05-02" name="CVE-2005-1016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in links_add_form.asp for MaxWebPortal 1.33 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URL in a banner URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14752" source="SECUNIA" patch="1" adv="1">14752</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19929" source="XF">maxwebportal-linksaddform-xss(19929)</ref>
      <ref url="http://www.securityfocus.com/bid/12968" source="BID">12968</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=1807" source="MISC">http://www.hackerscenter.com/archive/view.asp?id=1807</ref>
      <ref url="http://securitytracker.com/id?1013617" source="SECTRACK">1013617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers prev="1" num="1.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1017" published="2005-05-02" name="CVE-2005-1017" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the EVENT_ID parameter, as demonstrated using events.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013617" source="SECTRACK" patch="1">1013617</ref>
      <ref url="http://secunia.com/advisories/14752" source="SECUNIA" patch="1" adv="1">14752</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19928" source="XF">maxwebportal-eventsfunctions-sql-injection(19928)</ref>
      <ref url="http://www.securityfocus.com/bid/12968" source="BID">12968</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=1807" source="MISC">http://www.hackerscenter.com/archive/view.asp?id=1807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers prev="1" num="1.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1018" published="2005-05-02" name="CVE-2005-1018" modified="2009-07-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111351851802682&amp;w=2" source="BUGTRAQ" patch="1">20050414 Computer Associates BrightStor ARCserve Backup and BrightStor Enterprise Backup UniversalAgent buffer overflow vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/13102" source="BID">13102</ref>
      <ref url="http://www.securityfocus.com/archive/1/390760" source="BUGTRAQ">20050217 RE: BrightStor ARCserve Backup buffer overflow PoC (fixes available)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=232&amp;type=vulnerabilities" source="IDEFENSE">20050411 Computer Associates BrightStor ARCserve Backup UniversalAgent Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" edition="" />
        <vers num="11.1" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1019" published="2005-05-02" name="CVE-2005-1019" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19951" source="XF">aeon-getconfig-bo(19951)</ref>
      <ref url="http://security-tmp.h14.ru/exploits/23laeon.c.txt" source="MISC">http://security-tmp.h14.ru/exploits/23laeon.c.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111262942708249&amp;w=2" source="BUGTRAQ" adv="1">20050404 Local buffer overflow  on Aeon&lt;=0.2a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aeon" name="aeon">
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.2" />
        <vers num="0.2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1020" published="2005-05-02" name="CVE-2005-1020" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14854" source="SECUNIA" patch="1" adv="1">14854</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19990" source="XF">cisco-ios-ssh-message-log-dos(19990)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19989" source="XF">cisco-ios-authentication-send-dos(19989)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19987" source="XF">cisco-ios-sshv2-tacacs-authentication-dos(19987)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Apr/1013655.html" source="SECTRACK" adv="1">1013655</ref>
      <ref url="http://www.securityfocus.com/bid/13043" source="BID">13043</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050406-ssh.shtml" source="CISCO" adv="1">20050406 Vulnerabilities in Cisco IOS Secure Shell Server</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5455" source="OVAL">oval:org.mitre.oval:def:5455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0" />
        <vers num="12.0(23)s4" />
        <vers num="12.0(23)s5" />
        <vers num="12.0(24)s1" />
        <vers num="12.0(24)s4" />
        <vers num="12.0(24)s5" />
        <vers num="12.0(24.2)s" />
        <vers num="12.0(26)s1" />
        <vers num="12.0(27)s" />
        <vers num="12.0(27)sv" />
        <vers num="12.0(27)sv1" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sv" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0t" />
        <vers num="12.0w5" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0wx" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xp" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xt" />
        <vers num="12.0xu" />
        <vers num="12.0xv" />
        <vers num="12.0xw" />
        <vers num="12.1" />
        <vers num="12.1(11)e" />
        <vers num="12.1(11b)e" />
        <vers num="12.1(11b)e12" />
        <vers num="12.1(11b)e14" />
        <vers num="12.1(13)e9" />
        <vers num="12.1(19)e1" />
        <vers num="12.1(20)e" />
        <vers num="12.1(20)e1" />
        <vers num="12.1(20)e2" />
        <vers num="12.1(20)ea1" />
        <vers num="12.1(20)ec" />
        <vers num="12.1(20)ec1" />
        <vers num="12.1(20)eo" />
        <vers num="12.1(20)ew" />
        <vers num="12.1(20)ew1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1az" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1eu" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1m" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xk" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2(1)xa" />
        <vers num="12.2(1)xd" />
        <vers num="12.2(1)xd1" />
        <vers num="12.2(1)xd3" />
        <vers num="12.2(1)xd4" />
        <vers num="12.2(1)xe" />
        <vers num="12.2(1)xe2" />
        <vers num="12.2(1)xe3" />
        <vers num="12.2(1)xh" />
        <vers num="12.2(1)xq" />
        <vers num="12.2(1)xs" />
        <vers num="12.2(1)xs1" />
        <vers num="12.2(11)ja" />
        <vers num="12.2(11)ja1" />
        <vers num="12.2(11)t" />
        <vers num="12.2(12g)" />
        <vers num="12.2(12h)" />
        <vers num="12.2(14)sy" />
        <vers num="12.2(14)sy1" />
        <vers num="12.2(14)sz" />
        <vers num="12.2(14)za" />
        <vers num="12.2(14)za2" />
        <vers num="12.2(14.5)" />
        <vers num="12.2(14.5)t" />
        <vers num="12.2(15)zn" />
        <vers num="12.2(15.1)s" />
        <vers num="12.2(16)b" />
        <vers num="12.2(16.1)b" />
        <vers num="12.2(17a)sxa" />
        <vers num="12.2(18)ew" />
        <vers num="12.2(18)ewa" />
        <vers num="12.2(18)s" />
        <vers num="12.2(18)se" />
        <vers num="12.2(18)sv" />
        <vers num="12.2(18)sw" />
        <vers num="12.2(2)t4" />
        <vers num="12.2(2)xa" />
        <vers num="12.2(2)xa1" />
        <vers num="12.2(2)xa5" />
        <vers num="12.2(2)xb" />
        <vers num="12.2(2)xb3" />
        <vers num="12.2(2)xb4" />
        <vers num="12.2(2)xf" />
        <vers num="12.2(2)xg" />
        <vers num="12.2(2)xh" />
        <vers num="12.2(2)xh2" />
        <vers num="12.2(2)xh3" />
        <vers num="12.2(2)xi" />
        <vers num="12.2(2)xi1" />
        <vers num="12.2(2)xi2" />
        <vers num="12.2(2)xj" />
        <vers num="12.2(2)xj1" />
        <vers num="12.2(2)xk" />
        <vers num="12.2(2)xk2" />
        <vers num="12.2(2)xn" />
        <vers num="12.2(2)xt" />
        <vers num="12.2(2)xt3" />
        <vers num="12.2(2)xu" />
        <vers num="12.2(2)xu2" />
        <vers num="12.2(20)ew" />
        <vers num="12.2(20)s" />
        <vers num="12.2(20)s1" />
        <vers num="12.2(21)" />
        <vers num="12.2(21a)" />
        <vers num="12.2(23)" />
        <vers num="12.2(4)ja" />
        <vers num="12.2(4)ja1" />
        <vers num="12.2(8)ja" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2mx" />
        <vers num="12.2s" />
        <vers num="12.2se" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2x" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xw" />
        <vers num="12.2xz" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zi" />
        <vers num="12.2zj" />
        <vers num="12.2zk" />
        <vers num="12.2zl" />
        <vers num="12.2zm" />
        <vers num="12.2zn" />
        <vers num="12.2zo" />
        <vers num="12.2zp" />
        <vers num="12.2zq" />
        <vers num="12.3" />
        <vers num="12.3(2)t3" />
        <vers num="12.3(2)xc1" />
        <vers num="12.3(2)xc2" />
        <vers num="12.3(4)t" />
        <vers num="12.3(4)t1" />
        <vers num="12.3(4)t2" />
        <vers num="12.3(4)t3" />
        <vers num="12.3(4)xd" />
        <vers num="12.3(4)xd1" />
        <vers num="12.3(5)" />
        <vers num="12.3(5a)" />
        <vers num="12.3(5a)b" />
        <vers num="12.3(5b)" />
        <vers num="12.3(6)" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3j" />
        <vers num="12.3ja" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xm" />
        <vers num="12.3xn" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xt" />
        <vers num="12.3xu" />
        <vers num="12.3xv" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3ya" />
        <vers num="12.3yc" />
        <vers num="12.3yd" />
        <vers num="12.3ye" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yj" />
        <vers num="12.3yl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1021" published="2005-05-02" name="CVE-2005-1021" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 through 12.3, when authenticating against a TACACS+ server, allows remote attackers to cause a denial of service (memory consumption) via an incorrect username or password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19991" source="XF" patch="1">cisco-ios-memory-leak-dos(19991)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Apr/1013655.html" source="SECTRACK" patch="1">1013655</ref>
      <ref url="http://secunia.com/advisories/14854" source="SECUNIA" patch="1" adv="1">14854</ref>
      <ref url="http://www.securityfocus.com/bid/13042" source="BID">13042</ref>
      <ref url="http://www.osvdb.org/15303" source="OSVDB">15303</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050406-ssh.shtml" source="CISCO" adv="1">20050406 Vulnerabilities in Cisco IOS Secure Shell Server</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5687" source="OVAL">oval:org.mitre.oval:def:5687</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0s" />
        <vers num="12.0sx" />
        <vers num="12.1ax" />
        <vers num="12.1az" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eu" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1t" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2eu" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2s" />
        <vers num="12.2se" />
        <vers num="12.2sea" />
        <vers num="12.2seb" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2xa" />
        <vers num="12.2xc" />
        <vers num="12.2xf" />
        <vers num="12.2xn" />
        <vers num="12.2xs" />
        <vers num="12.2ye" />
        <vers num="12.2yk" />
        <vers num="12.2yo" />
        <vers num="12.2yx" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.3t" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xm" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1022" published="2005-05-02" name="CVE-2005-1022" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb05-02.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb05-02.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111290407411801&amp;w=2" source="BUGTRAQ" adv="1">20050407 Macromedia Security Bulletin - ColdFusion MX 6.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1023" published="2005-05-02" name="CVE-2005-1023" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module.  NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19952" source="XF" patch="1">phpnuke-modulesphp-xss(19952)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263454308478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050403 Full path disclosure and XSS in PHPNuke</ref>
      <ref url="http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt" source="MISC">http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1024" published="2005-05-02" name="CVE-2005-1024" modified="2008-10-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19953" source="XF" patch="1">phpnuke-modulesphp-path-disclosure(19953)</ref>
      <ref url="http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt" source="MISC" patch="1" adv="1">http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263454308478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050403 Full path disclosure and XSS in PHPNuke</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/44980" source="XF">phpnuke-myheadlines-path-disclosure(44980)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1025" published="2005-05-02" name="CVE-2005-1025" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venera.com/downloads/AS400_user_accounts_ftp_disclosure.pdf" source="MISC">http://www.venera.com/downloads/AS400_user_accounts_ftp_disclosure.pdf</ref>
      <ref url="http://www.osvdb.org/15300" source="OSVDB">15300</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264136829017&amp;w=2" source="BUGTRAQ">20050404 Disclosure of AS/400 user accounts via the FTP server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="iseries_as_400">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1026" published="2005-05-02" name="CVE-2005-1026" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to dlman.php in DLMan Pro or (2) id parameter to links.php in Linkz Pro (aka LinksLinks Pro).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.snailsource.com/forum/dlman.php?func=file_info&amp;file_id=77" source="CONFIRM">http://www.snailsource.com/forum/dlman.php?func=file_info&amp;file_id=77</ref>
      <ref url="http://www.securityfocus.com/bid/13030" source="BID">13030</ref>
      <ref url="http://www.securityfocus.com/bid/13028" source="BID">13028</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272430128195&amp;w=2" source="BUGTRAQ">20050404 SQL INJECTION in DLMan Pro.  PHPBB Mod.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111271895819594&amp;w=2" source="BUGTRAQ">20050404 SQL INJECTION in LinksLinks Pro.  PHPBB Mod.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dlman_pro" name="dlman_pro">
        <vers num="0.9.8" />
      </prod>
      <prod vendor="linkz_pro" name="linkz_pro">
        <vers num="1.0.3_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1027" published="2005-05-02" name="CVE-2005-1027" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272010303144&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050404 [SECURITYREASON.COM] Full path disclosure and XSS in PHPNuke part 3</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11994" source="XF">phpnuke-modules-xss(11994)</ref>
      <ref url="http://www.securityfocus.com/bid/7570" source="BID">7570</ref>
      <ref url="http://www.securityfocus.com/archive/1/321324" source="BUGTRAQ">20030511 PHPNuke "Your Account" XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1028" published="2005-05-02" name="CVE-2005-1028" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter set, (2) the Surveys module, or (3) the Your_Account module, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272010303144&amp;w=2" source="BUGTRAQ" adv="1">20050404 [SECURITYREASON.COM] Full path disclosure and XSS in PHPNuke part 3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1029" published="2005-04-06" name="CVE-2005-1029" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19977" source="XF" adv="1">aah-multiple-scripts-sql-injection(19977)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Apr/1013649.html" source="SECTRACK" adv="1">1013649</ref>
      <ref url="http://www.securityfocus.com/bid/13035" source="BID" adv="1">13035</ref>
      <ref url="http://www.securityfocus.com/bid/13034" source="BID" adv="1">13034</ref>
      <ref url="http://www.securityfocus.com/bid/13032" source="BID" adv="1">13032</ref>
      <ref url="http://secunia.com/advisories/14839" source="SECUNIA" adv="1">14839</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111280834000432&amp;w=2" source="BUGTRAQ" adv="1">20050406 Active Auction House has multiple Sql injection, error and XSS</ref>
      <ref url="http://www.osvdb.org/15283" source="OSVDB">15283</ref>
      <ref url="http://www.osvdb.org/15282" source="OSVDB">15282</ref>
      <ref url="http://www.osvdb.org/15281" source="OSVDB">15281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_web_softwares" name="active_auction_house">
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1030" published="2005-05-02" name="CVE-2005-1030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to watchthisitem.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19975" source="XF">aah-multiple-scripts-xss(19975)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Apr/1013649.html" source="SECTRACK">1013649</ref>
      <ref url="http://www.securityfocus.com/bid/13039" source="BID">13039</ref>
      <ref url="http://www.securityfocus.com/bid/13038" source="BID">13038</ref>
      <ref url="http://www.securityfocus.com/bid/13036" source="BID">13036</ref>
      <ref url="http://secunia.com/advisories/14839" source="SECUNIA" adv="1">14839</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111280834000432&amp;w=2" source="BUGTRAQ" adv="1">20050406 Active Auction House has multiple Sql injection, error and XSS</ref>
      <ref url="http://www.osvdb.org/15287" source="OSVDB">15287</ref>
      <ref url="http://www.osvdb.org/15286" source="OSVDB">15286</ref>
      <ref url="http://www.osvdb.org/15285" source="OSVDB">15285</ref>
      <ref url="http://www.osvdb.org/15284" source="OSVDB">15284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_web_softwares" name="active_auction_house">
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1031" published="2005-05-02" name="CVE-2005-1031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20001" source="XF" patch="1">exoops-runcms-upload-files(20001)</ref>
      <ref url="http://www.securityfocus.com/bid/13027" source="BID" patch="1">13027</ref>
      <ref url="http://secunia.com/advisories/14869" source="SECUNIA" patch="1" adv="1">14869</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111280711228450&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050406 runcms/e-xoops 1.1A and below file upload vulnerability</ref>
      <ref url="http://www.runcms.org/public/modules/news/" source="CONFIRM">http://www.runcms.org/public/modules/news/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-xoops" name="e-xoops">
        <vers num="1.05r3" />
      </prod>
      <prod vendor="runcms" name="runcms">
        <vers num="1.1" />
        <vers num="1.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1032" reject="1" published="2005-04-06" name="CVE-2005-1032" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters.  NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type and severity.  The vendor has disputed this issue, saying "These reports are credited to malicious person we refused to hire. We have not taken legal action against him only because he is located in India.  The vulnerabilites reported can not be reproduced, hence information you provide is contrary to fact." Further investigation by CVE personnel shows that an invalid SQL syntax error could be generated, but it only reveals portions of underlying database structure, which is already available in documentation from the vendor, and it does not appear to lead to path disclosure.  Therefore, this issue is not a vulnerability or an exposure, and it probably should be REJECTED.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1033" published="2005-05-02" name="CVE-2005-1033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013660" source="SECTRACK">1013660</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111281457918479&amp;w=2" source="BUGTRAQ">20050406 [NOBYTES.COM: #6] CubeCart 2.0.6 - Information Disclosure</ref>
      <ref url="http://www.osvdb.org/14064" source="OSVDB">14064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1034" published="2005-05-02" name="CVE-2005-1034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20011" source="XF" patch="1">surgeftp-leak-ftp-dos(20011)</ref>
      <ref url="http://secunia.com/advisories/14888" source="SECUNIA" patch="1" adv="1">14888</ref>
      <ref url="http://www.securityfocus.com/bid/13054" source="BID">13054</ref>
      <ref url="http://www.security.org.sg/vuln/surgeftp22m1.html" source="MISC" adv="1">http://www.security.org.sg/vuln/surgeftp22m1.html</ref>
      <ref url="http://securitytracker.com/id?1013664" source="SECTRACK">1013664</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111289226204780&amp;w=2" source="BUGTRAQ" adv="1">20050407 [SIG^2 G-TEC] SurgeFTP LEAK Command Denial-Of-Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="surgeftp">
        <vers num="2.2k3" />
        <vers num="2.2m1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1035" published="2005-04-05" name="CVE-2005-1035" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Pavuk before 0.9.32 have unknown attack vectors and impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=313436" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=313436</ref>
      <ref url="http://secunia.com/advisories/14571" source="SECUNIA" patch="1" adv="1">14571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pavuk" name="pavuk">
        <vers num="0.9.31" />
        <vers num="0.928r1" />
        <vers num="0.928r2" />
        <vers num="0.9_pl28" />
        <vers num="0.9_pl30b" />
        <vers num="0.9pl28i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1036" published="2005-05-02" name="CVE-2005-1036" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:03.amd64.asc" source="FREEBSD">FreeBSD-SA-05:03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1037" published="2005-05-02" name="CVE-2005-1037" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/br-20050405-00278.html?lang=en" source="MISC" patch="1" adv="1">http://www.niscc.gov.uk/niscc/docs/br-20050405-00278.html?lang=en</ref>
      <ref url="http://secunia.com/advisories/14856" source="SECUNIA" patch="1">14856</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY68825&amp;apar=only" source="AIXAPAR">IY68825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1038" published="2005-05-02" name="CVE-2005-1038" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink.  NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13024" source="BID" patch="1">13024</ref>
      <ref url="http://www.securityfocus.com/archive/1/395093" source="BUGTRAQ" adv="1">20050406 crontab from vixie-cron allows read other users crontabs</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11104" source="OVAL">oval:org.mitre.oval:def:11104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0117.html" source="REDHAT">RHSA-2006:0117</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-361.html" source="REDHAT">RHSA-2005:361</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-118.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-118.htm</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA">24995</ref>
      <ref url="http://secunia.com/advisories/20666" source="SECUNIA">20666</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA">19532</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers num="4.1" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1039" published="2005-05-02" name="CVE-2005-1039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13053" source="BID">13053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="coreutils">
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1040" published="2005-05-02" name="CVE-2005-1040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2005-Apr/0002.html" source="SUSE" adv="1">SUSE-SR:2005:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="linux_desktop">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1041" published="2005-05-02" name="CVE-2005-1041" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bk-commits-head&amp;m=111186506706769&amp;w=2" source="MLIST" patch="1">[bk-commits-head] 20050319 [PATCH] Fix crash while reading /proc/net/route</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9487" source="OVAL">oval:org.mitre.oval:def:9487</ref>
      <ref url="http://www.securityfocus.com/bid/13267" source="BID">13267</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded" source="SUSE">SUSE-SA:2005:068</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://secunia.com/advisories/17918" source="SECUNIA">17918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1042" published="2005-05-02" name="CVE-2005-1042" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml" source="GENTOO" patch="1">GLSA-200504-15</ref>
      <ref url="http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.33&amp;r2=1.118.2.34&amp;ty=u" source="CONFIRM" patch="1">http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.33&amp;r2=1.118.2.34&amp;ty=u</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154021" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154021</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-112-1" source="UBUNTU" adv="1">USN-112-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-406.html" source="REDHAT">RHSA-2005:406</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-405.html" source="REDHAT">RHSA-2005:405</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10822" source="OVAL">oval:org.mitre.oval:def:10822</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1043" published="2005-04-14" name="CVE-2005-1043" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-112-1" source="UBUNTU" patch="1" adv="1">USN-112-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-406.html" source="REDHAT" patch="1" adv="1">RHSA-2005:406</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-15</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154025" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154025</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10307" source="OVAL">oval:org.mitre.oval:def:10307</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
      <ref url="http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.29&amp;r2=1.118.2.30&amp;ty=u" source="CONFIRM" adv="1">http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.29&amp;r2=1.118.2.30&amp;ty=u</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="peachtree" name="peachtree_linux">
        <vers num="release_1" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":i386" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":sparc" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.0" edition=":ppc" />
        <vers num="7.0" edition="alpha" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":spa" />
        <vers num="7.1" edition=":sparc" />
        <vers num="7.1" edition=":x86" />
        <vers num="7.1" edition="alpha" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":i386" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":ppc" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":sparc" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1044" reject="1" published="2005-05-02" name="CVE-2005-1044" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0941.  Reason: This candidate is a duplicate of CVE-2005-0941.  Notes: All CVE users should reference CVE-2005-0941 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-1045" published="2005-05-02" name="CVE-2005-1045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20032" source="XF">firstclass-bookmark-command-execution(20032)</ref>
      <ref url="http://www.securityfocus.com/bid/13079" source="BID">13079</ref>
      <ref url="http://www.osvdb.org/15356" source="OSVDB">15356</ref>
      <ref url="http://securitytracker.com/id?1013665" source="SECTRACK">1013665</ref>
      <ref url="http://secunia.com/advisories/14898/" source="SECUNIA" adv="1">14898</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111323587931293&amp;w=2" source="BUGTRAQ" adv="1">20050408 OpenText FirstClass 8.0 Client Arbitrary File Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centrinity" name="centrinity_firstclass_desktop_client">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1046" published="2005-05-02" name="CVE-2005-1046" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_22_kdelibs3.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:022</ref>
      <ref url="http://www.debian.org/security/2005/dsa-714" source="DEBIAN" patch="1" adv="1">DSA-714</ref>
      <ref url="http://secunia.com/advisories/14908" source="SECUNIA" patch="1" adv="1">14908</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4241" source="VUPEN">ADV-2007-4241</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0331" source="VUPEN">ADV-2005-0331</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5802" source="OVAL">oval:org.mitre.oval:def:5802</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11081" source="OVAL">oval:org.mitre.oval:def:11081</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=102328" source="MISC" adv="1">http://bugs.kde.org/show_bug.cgi?id=102328</ref>
      <ref url="http://www.securityfocus.com/bid/13096" source="BID">13096</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" source="FEDORA">FLSA:178606</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-393.html" source="REDHAT">RHSA-2005:393</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050421-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20050421-1.txt</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201320-1" source="SUNALERT">201320</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103170-1" source="SUNALERT">103170</ref>
      <ref url="http://secunia.com/advisories/28114" source="SECUNIA">28114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1047" published="2005-04-07" name="CVE-2005-1047" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote authenticated users to execute arbitrary commands by uploading PHP files, then directly requesting them from the uploads directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013671" source="SECTRACK" adv="1">1013671</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111299353030534&amp;w=2" source="BUGTRAQ" adv="1">20050408 phpBB Upload Script "up.php" Arbitrary File Upload</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1048" published="2005-05-02" name="CVE-2005-1048" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter.  NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14868/" source="SECUNIA" patch="1">14868</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20019" source="XF">postnuke-sid-sql-injection(20019)</ref>
      <ref url="http://www.osvdb.org/15371" source="OSVDB">15371</ref>
      <ref url="http://securitytracker.com/id?1013670" source="SECTRACK">1013670</ref>
      <ref url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2679" source="MISC">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2679</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111298226029957&amp;w=2" source="BUGTRAQ">20050408 Sql injection, xss and path disclosure vulnerabilities in PostNuke 0.760-RC3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1049" published="2005-05-02" name="CVE-2005-1049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for 760 RC3, or for .750.  However, the op/user.php issue exists when the pnAntiCracker setting is disabled.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13076" source="BID" patch="1">13076</ref>
      <ref url="http://secunia.com/advisories/14868/" source="SECUNIA" patch="1" adv="1">14868</ref>
      <ref url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2679" source="MISC" patch="1" adv="1">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2679</ref>
      <ref url="http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/user.php.diff?r1=1.18&amp;r2=1.19" source="MISC" patch="1">http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/user.php.diff?r1=1.18&amp;r2=1.19</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20018" source="XF">postnuke-adminphp-userphp-xss(20018)</ref>
      <ref url="http://www.securityfocus.com/bid/13075" source="BID">13075</ref>
      <ref url="http://www.osvdb.org/15370" source="OSVDB">15370</ref>
      <ref url="http://securitytracker.com/id?1013670" source="SECTRACK">1013670</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111298226029957&amp;w=2" source="BUGTRAQ" adv="1">20050408 Sql injection, xss and path disclosure vulnerabilities in PostNuke 0.760-RC3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1050" published="2005-05-02" name="CVE-2005-1050" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote attackers to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20020" source="XF">postnuke-modules-full-path-disclosure(20020)</ref>
      <ref url="http://securitytracker.com/id?1013670" source="SECTRACK">1013670</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111298226029957&amp;w=2" source="BUGTRAQ" adv="1">20050408 Sql injection, xss and path disclosure vulnerabilities in PostNuke 0.760-RC3</ref>
      <ref url="http://digitalparadox.org/advisories/postnuke.txt" source="MISC">http://digitalparadox.org/advisories/postnuke.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1051" published="2005-05-02" name="CVE-2005-1051" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13071" source="BID" patch="1">13071</ref>
      <ref url="http://secunia.com/advisories/14882" source="SECUNIA" patch="1" adv="1">14882</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111306207306155&amp;w=2" source="BUGTRAQ">20050408 PunBB &lt;= 1.2.4 - change email to become admin exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0_alpha" />
        <vers num="1.0_beta1" />
        <vers num="1.0_beta2" />
        <vers num="1.0_beta3" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1052" published="2005-05-02" name="CVE-2005-1052" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20026" source="XF">owa-email-spoofing(20026)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=227&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050408 Microsoft Multiple E-Mail Client Address Spoofing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="outlook_web_access">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1053" published="2005-05-02" name="CVE-2005-1053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013672" source="SECTRACK" patch="1">1013672</ref>
      <ref url="http://secunia.com/advisories/14890" source="SECUNIA" patch="1">14890</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111323741032183&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050410 Multiple ModernBill 4.3.0 And Earlier Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20035" source="XF">modernbill-orderwiz-xss(20035)</ref>
      <ref url="http://www.osvdb.org/15426" source="OSVDB">15426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moderngigabyte" name="modernbill">
        <vers prev="1" num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1054" published="2005-05-02" name="CVE-2005-1054" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013672" source="SECTRACK" patch="1">1013672</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111323741032183&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050410 Multiple ModernBill 4.3.0 And Earlier Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20036" source="XF">modernbill-news-file-include(20036)</ref>
      <ref url="http://www.osvdb.org/15427" source="OSVDB">15427</ref>
      <ref url="http://secunia.com/advisories/14890" source="SECUNIA" adv="1">14890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moderngigabyte" name="modernbill">
        <vers prev="1" num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1055" published="2005-04-10" name="CVE-2005-1055" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013675" source="SECTRACK" patch="1" adv="1">1013675</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20039" source="XF" adv="1">towerblog-datlogin-information-disclosure(20039)</ref>
      <ref url="http://secunia.com/advisories/14884" source="SECUNIA" adv="1">14884</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111323802003019&amp;w=2" source="BUGTRAQ" adv="1">20050410 TowerBlog &lt;= 0.6 Admin Account View [x0n3-h4ck]</ref>
      <ref url="http://www.osvdb.org/15425" source="OSVDB">15425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="towerblog" name="towerblog">
        <vers num="0.2" />
        <vers num="0.4_r1" />
        <vers num="0.6" />
        <vers num="0.6_r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1056" published="2005-05-02" name="CVE-2005-1056" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19993" source="XF">openview-network-node-manager-dos(19993)</ref>
      <ref url="http://www.securityfocus.com/bid/13029" source="BID">13029</ref>
      <ref url="http://www.securityfocus.com/advisories/8372" source="HP" adv="1">HPSBMA01125</ref>
      <ref url="http://www.osvdb.org/15321" source="OSVDB">15321</ref>
      <ref url="http://securitytracker.com/id?1013651" source="SECTRACK">1013651</ref>
      <ref url="http://secunia.com/advisories/14865" source="SECUNIA" adv="1">14865</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.2" />
        <vers num="6.31" />
        <vers num="6.4" />
        <vers num="7.01" />
        <vers num="7.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1057" published="2005-05-02" name="CVE-2005-1057" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050406-xauth.shtml" source="CISCO" adv="1">20050406 Vulnerabilities in the Internet Key Exchange Xauth Implementation</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5852" source="OVAL">oval:org.mitre.oval:def:5852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2t" />
        <vers num="12.3" />
        <vers num="12.3t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1058" published="2005-05-02" name="CVE-2005-1058" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050406-xauth.shtml" source="CISCO" adv="1">20050406 Vulnerabilities in the Internet Key Exchange Xauth Implementation</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5738" source="OVAL">oval:org.mitre.oval:def:5738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2t" />
        <vers num="12.3" />
        <vers num="12.3t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1059" published="2005-05-02" name="CVE-2005-1059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-04/0148.html" source="FULLDISC" patch="1" adv="1">20050407 Cisco Linksys WET11 Password Resetting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20008" source="XF">linksys-wet11-security-bypass(20008)</ref>
      <ref url="http://www.securityfocus.com/bid/13051" source="BID">13051</ref>
      <ref url="http://secunia.com/advisories/14871" source="SECUNIA" adv="1">14871</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="wet11">
        <vers num="1.4.3" />
        <vers num="1.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1060" published="2005-05-02" name="CVE-2005-1060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13067" source="BID" patch="1">13067</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20024" source="XF">novell-netware-tcpipnlm-dos(20024)</ref>
      <ref url="http://secunia.com/advisories/14874" source="SECUNIA">14874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.5" edition="sp1" />
        <vers num="6.5" edition="sp1.1a" />
        <vers num="6.5" edition="sp1.1b" />
        <vers num="6.5" edition="sp2" />
        <vers num="6.5" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1061" published="2005-05-02" name="CVE-2005-1061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla-old/show_bug.cgi?id=137502" source="CONFIRM">https://bugzilla.redhat.com/bugzilla-old/show_bug.cgi?id=137502</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-364.html" source="REDHAT" adv="1">RHSA-2005:364</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logwatch" name="logwatch">
        <vers num="2.6.2" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1062" published="2005-05-02" name="CVE-2005-1062" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/397221" source="BUGTRAQ">20050429 [CAN-2005-1062] Administration protocol abuse allows local/remote password cracking</ref>
      <ref url="http://www.kerio.com/security_advisory.html" source="CONFIRM" adv="1">http://www.kerio.com/security_advisory.html</ref>
      <ref url="http://research.tic.udc.es/scg/advisories/20050429-1.txt" source="MISC">http://research.tic.udc.es/scg/advisories/20050429-1.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
      </prod>
      <prod vendor="kerio" name="personal_firewall">
        <vers num="4.0.10" />
        <vers num="4.0.11" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.16" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
      <prod vendor="kerio" name="winroute_firewall">
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1063" published="2005-04-29" name="CVE-2005-1063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to "compute unexpected conditions" and "perform cryptographic operations."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/397220" source="BUGTRAQ" patch="1" adv="1">20050429 [CAN-2005-1063] Administration protocol abuse leads to Service and System Denial of Service</ref>
      <ref url="http://www.kerio.com/security_advisory.html" source="CONFIRM" patch="1" adv="1">http://www.kerio.com/security_advisory.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
      </prod>
      <prod vendor="kerio" name="personal_firewall">
        <vers num="4.0.10" />
        <vers num="4.0.16" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
      <prod vendor="kerio" name="winroute_firewall">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1064" published="2005-04-10" name="CVE-2005-1064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.rsnapshot.org/security/2005/001.html" source="CONFIRM" patch="1" adv="1">http://www.rsnapshot.org/security/2005/001.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-12</ref>
      <ref url="http://securitytracker.com/id?1013674" source="SECTRACK" patch="1" adv="1">1013674</ref>
      <ref url="http://secunia.com/advisories/14878" source="SECUNIA" patch="1" adv="1">14878</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111317179531000&amp;w=2" source="FULLDISC" adv="1">20050410 rsnapshot Security Advisory 001</ref>
      <ref url="http://www.osvdb.org/15420" source="OSVDB">15420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsnapshot" name="filesystem_snapshot_utility">
        <vers num="1.0.10" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1065" published="2005-05-02" name="CVE-2005-1065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13072" source="BID" patch="1">13072</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2005-Apr/0002.html" source="SUSE" adv="1">SUSE-SR:2005:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="linux_desktop">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1066" published="2005-05-02" name="CVE-2005-1066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14899" source="SECUNIA" adv="1">14899</ref>
      <ref url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0504/126.html" source="BUGTRAQ" adv="1">20050411 rpdump TOCTOU file-permissions vulnerability</ref>
      <ref url="http://www.osvdb.org/15456" source="OSVDB">15456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.62" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1067" published="2005-04-08" name="CVE-2005-1067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in Access_user Class before 1.75 allows local users to gain access as other users via the password "new".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14897" source="SECUNIA" patch="1" adv="1">14897</ref>
      <ref url="http://freshmeat.net/projects/access_user/?branch_id=53852&amp;release_id=192770" source="CONFIRM" patch="1" adv="1">http://freshmeat.net/projects/access_user/?branch_id=53852&amp;release_id=192770</ref>
      <ref url="http://www.osvdb.org/15348" source="OSVDB">15348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="access_user_class" name="access_user_class">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1068" published="2005-05-02" name="CVE-2005-1068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20021" source="XF" patch="1">scssboard-url-tag-xss(20021)</ref>
      <ref url="http://www.securityfocus.com/bid/13041" source="BID" patch="1">13041</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=318346" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=318346</ref>
      <ref url="http://securitytracker.com/id?1013659" source="SECTRACK" patch="1">1013659</ref>
      <ref url="http://secunia.com/advisories/14694" source="SECUNIA" patch="1" adv="1">14694</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1069" published="2005-05-02" name="CVE-2005-1069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20022" source="XF" patch="1">scssboard-profile-unknown(20022)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=318346" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=318346</ref>
      <ref url="http://securitytracker.com/id?1013659" source="SECTRACK" patch="1">1013659</ref>
      <ref url="http://secunia.com/advisories/14694" source="SECUNIA" patch="1" adv="1">14694</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1070" published="2005-04-11" name="CVE-2005-1070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20059" source="XF" adv="1">invision-memberlist-sql-injection(20059)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Apr/1013676.html" source="SECTRACK" adv="1">1013676</ref>
      <ref url="http://www.securityfocus.com/bid/13097" source="BID" adv="1">13097</ref>
      <ref url="http://www.securityfocus.com/archive/1/395515" source="BUGTRAQ" adv="1">20050411 Invision board 1.3.1 and below are vulnerable to a sql injection vulnerability [PATCH INCLUDED]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1_final" />
        <vers num="1.3_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1071" published="2005-04-12" name="CVE-2005-1071" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15476" source="OSVDB">15476</ref>
      <ref url="http://secunia.com/advisories/14919" source="SECUNIA" adv="1">14919</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111331738223323&amp;w=2" source="BUGTRAQ" adv="1">20050412 Sql injection in jPortal version 2.3.1 (module banner)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1072" published="2005-04-08" name="CVE-2005-1072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PunBB before 1.2.5 allows remote attackers to inject arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.punbb.org/" source="CONFIRM" patch="1" adv="1">http://www.punbb.org/</ref>
      <ref url="http://secunia.com/advisories/14882" source="SECUNIA" patch="1" adv="1">14882</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0_alpha" />
        <vers num="1.0_beta1" />
        <vers num="1.0_beta2" />
        <vers num="1.0_beta3" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1073" published="2005-05-02" name="CVE-2005-1073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20038" source="XF">radbids-gold-php-xss(20038)</ref>
      <ref url="http://www.securityfocus.com/bid/13080" source="BID">13080</ref>
      <ref url="http://www.securityfocus.com/archive/1/395527" source="BUGTRAQ" adv="1">20050409 Directory transversal, sql injection and xss vulnerabilities in RadBids Gold v2</ref>
      <ref url="http://www.osvdb.org/15428" source="OSVDB">15428</ref>
      <ref url="http://secunia.com/advisories/14906" source="SECUNIA" adv="1">14906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscripts" name="radbids">
        <vers num="2" edition="" />
        <vers num="2" edition=":gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1074" published="2005-05-02" name="CVE-2005-1074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20040" source="XF">radbids-gold-index-sql-injection(20040)</ref>
      <ref url="http://www.securityfocus.com/bid/13080" source="BID">13080</ref>
      <ref url="http://www.securityfocus.com/archive/1/395527" source="BUGTRAQ" adv="1">20050409 Directory transversal, sql injection and xss vulnerabilities in RadBids Gold v2</ref>
      <ref url="http://www.osvdb.org/15429" source="OSVDB">15429</ref>
      <ref url="http://secunia.com/advisories/14906" source="SECUNIA" adv="1">14906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscripts" name="radbids">
        <vers num="2" edition="" />
        <vers num="2" edition=":gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1075" published="2005-05-02" name="CVE-2005-1075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20038" source="XF">radbids-gold-php-xss(20038)</ref>
      <ref url="http://www.securityfocus.com/bid/13080" source="BID">13080</ref>
      <ref url="http://www.securityfocus.com/archive/1/395527" source="BUGTRAQ" adv="1">20050409 Directory transversal, sql injection and xss vulnerabilities in RadBids Gold v2</ref>
      <ref url="http://www.osvdb.org/15431" source="OSVDB">15431</ref>
      <ref url="http://www.osvdb.org/15430" source="OSVDB">15430</ref>
      <ref url="http://secunia.com/advisories/14906" source="SECUNIA" adv="1">14906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscripts" name="radbids">
        <vers num="2" edition="" />
        <vers num="2" edition=":gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1076" published="2005-05-02" name="CVE-2005-1076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13101" source="BID">13101</ref>
      <ref url="http://www.securityfocus.com/archive/1/395544" source="BUGTRAQ" adv="1">20050411 WebCT 4.1 vulnerable to XSS attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webct" name="webct">
        <vers num="campus_4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1077" published="2005-04-12" name="CVE-2005-1077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13128" source="BID" adv="1">13128</ref>
      <ref url="http://www.securityfocus.com/bid/13127" source="BID" adv="1">13127</ref>
      <ref url="http://www.securityfocus.com/bid/13126" source="BID" adv="1">13126</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111330048629182&amp;w=2" source="FULLDISC" adv="1">20050412 XAMPP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xampp" name="apache_distribution">
        <vers num="0.1" edition="" />
        <vers num="0.1" edition=":solaris" />
        <vers num="0.2" edition="" />
        <vers num="0.2" edition=":solaris" />
        <vers num="0.3" edition="" />
        <vers num="0.3" edition=":solaris" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.10a" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1078" published="2005-04-12" name="CVE-2005-1078" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13131" source="BID" adv="1">13131</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111330048629182&amp;w=2" source="FULLDISC" adv="1">20050412 XAMPP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xampp" name="apache_distribution">
        <vers num="0.1" edition="" />
        <vers num="0.1" edition=":solaris" />
        <vers num="0.2" edition="" />
        <vers num="0.2" edition=":solaris" />
        <vers num="0.3" edition="" />
        <vers num="0.3" edition=":solaris" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.10a" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1079" published="2005-05-02" name="CVE-2005-1079" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/5LP0G0AFFY.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/5LP0G0AFFY.html</ref>
      <ref url="http://secunia.com/advisories/14929" source="SECUNIA" adv="1">14929</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111340031132596&amp;w=2" source="BUGTRAQ" adv="1">20050413 zOOM Media Gallery - Simple SQL Injection discovery</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1080" published="2005-05-02" name="CVE-2005-1080" modified="2010-06-22" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=601823" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=601823</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=594497" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=594497</ref>
      <ref url="http://www.securiteam.com/securitynews/5IP0C0AFGW.html" source="MISC" adv="1">http://www.securiteam.com/securitynews/5IP0C0AFGW.html</ref>
      <ref url="http://secunia.com/advisories/14902" source="SECUNIA" adv="1">14902</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111331593310508&amp;w=2" source="BUGTRAQ" adv="1">20050412 7a69Adv#23 - Jar tool directory transversal vulnerability</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127603032617644&amp;w=2" source="MLIST">[oss-security] 20100608 Re: jar, fastjar directory traversal vulnerabilities</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127602564508766&amp;w=2" source="MLIST">[oss-security] 20100608 jar, fastjar directory traversal vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1081" published="2005-05-02" name="CVE-2005-1081" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20052" source="XF">azdgdating-platinum-viewphp-xss(20052)</ref>
      <ref url="http://www.securityfocus.com/bid/13082" source="BID">13082</ref>
      <ref url="http://www.securityfocus.com/archive/1/395530" source="BUGTRAQ" adv="1">20050409 AzDGDatingPlatinum multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="azerbaijan_development_group" name="azdgdating">
        <vers num="1.1.0" edition="" />
        <vers num="1.1.0" edition=":platinum" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1082" published="2005-04-09" name="CVE-2005-1082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20051" source="XF" adv="1">azdgdating-platinum-sql-injection(20051)</ref>
      <ref url="http://www.securityfocus.com/bid/13082" source="BID" adv="1">13082</ref>
      <ref url="http://www.securityfocus.com/archive/1/395530" source="BUGTRAQ" adv="1">20050409 AzDGDatingPlatinum multiple vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27436" source="XF">azdgdatingplatinum-view-sql-injection(27436)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438607/100/100/threaded" source="BUGTRAQ">20060628 AzDGDatingPlatinum&lt;&lt;--v1.1.0 "view.php" SQL Injection</ref>
      <ref url="http://www.osvdb.org/15525" source="OSVDB">15525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="azerbaijan_development_group" name="azdgdating">
        <vers num="1.1.0" edition="" />
        <vers num="1.1.0" edition=":platinum" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1083" published="2005-05-02" name="CVE-2005-1083" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14913" source="SECUNIA" adv="1">14913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aewebworks" name="aedating">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1084" published="2005-05-02" name="CVE-2005-1084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14913" source="SECUNIA" adv="1">14913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aewebworks" name="aedating">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1085" published="2005-05-02" name="CVE-2005-1085" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14913" source="SECUNIA" adv="1">14913</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1086" published="2005-05-02" name="CVE-2005-1086" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20029" source="XF">an-httpd-cmdisdll-bo(20029)</ref>
      <ref url="http://www.securityfocus.com/bid/13066" source="BID">13066</ref>
      <ref url="http://www.security.org.sg/vuln/anhttpd142n.html" source="MISC" adv="1">http://www.security.org.sg/vuln/anhttpd142n.html</ref>
      <ref url="http://www.osvdb.org/15361" source="OSVDB">15361</ref>
      <ref url="http://securitytracker.com/id?1013666" source="SECTRACK">1013666</ref>
      <ref url="http://secunia.com/advisories/14861" source="SECUNIA" adv="1">14861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="an" name="an-httpd">
        <vers num="1.42n" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1087" published="2005-04-07" name="CVE-2005-1087" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20031" source="XF" adv="1">an-httpd-logfile-character-injection(20031)</ref>
      <ref url="http://www.security.org.sg/vuln/anhttpd142n.html" source="MISC" adv="1">http://www.security.org.sg/vuln/anhttpd142n.html</ref>
      <ref url="http://www.osvdb.org/15362" source="OSVDB" adv="1">15362</ref>
      <ref url="http://securitytracker.com/id?1013666" source="SECTRACK" adv="1">1013666</ref>
      <ref url="http://secunia.com/advisories/14861" source="SECUNIA" adv="1">14861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="an" name="an-httpd">
        <vers num="1.42n" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1088" published="2005-05-02" name="CVE-2005-1088" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19997" source="XF" patch="1">dameware-elevated-privileges(19997)</ref>
      <ref url="http://www.securityfocus.com/bid/13023" source="BID" patch="1">13023</ref>
      <ref url="http://securitytracker.com/id?1013653" source="SECTRACK" patch="1">1013653</ref>
      <ref url="http://secunia.com/advisories/14829" source="SECUNIA" patch="1" adv="1">14829</ref>
      <ref url="http://www.dameware.com/support/security/bulletin.asp?ID=SB5" source="CONFIRM" adv="1">http://www.dameware.com/support/security/bulletin.asp?ID=SB5</ref>
      <ref url="http://www.osvdb.org/18732" source="OSVDB">18732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dameware_development" name="mini_remote_control">
        <vers num="3.70" />
        <vers num="3.71" />
        <vers num="3.72" />
        <vers num="3.73" />
        <vers num="3.74" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" />
      </prod>
      <prod vendor="dameware_development" name="nt_utilities">
        <vers num="3.0.0.0" />
        <vers num="3.1.0.0" />
        <vers num="3.2.0.0" />
        <vers num="3.21.0.0" />
        <vers num="3.41.0.0" />
        <vers num="3.42.0.0" />
        <vers num="3.43.0.0" />
        <vers num="3.44.0.0" />
        <vers num="3.45.0.0" />
        <vers num="3.46.0.0" />
        <vers num="3.48.0.0" />
        <vers num="3.49" />
        <vers num="3.50" />
        <vers num="3.51" />
        <vers num="3.60.0.0" />
        <vers num="3.61.0.0" />
        <vers num="3.62.0.0" />
        <vers num="3.63.0.0" />
        <vers num="3.64.0.0" />
        <vers num="3.65.0.0" />
        <vers num="3.66.0.0" />
        <vers num="3.67" />
        <vers num="3.68.0.0" />
        <vers num="3.69" />
        <vers num="3.70" />
        <vers num="3.71.0.0" />
        <vers num="3.72.0.0" />
        <vers num="3.73.0.0" />
        <vers num="3.74.0.0" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1089" published="2005-04-11" name="CVE-2005-1089" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14880" source="SECUNIA" patch="1" adv="1">14880</ref>
      <ref url="http://dcplusplus.sourceforge.net/index.php?t=8&amp;s=1" source="CONFIRM" patch="1" adv="1">http://dcplusplus.sourceforge.net/index.php?t=8&amp;s=1</ref>
      <ref url="http://www.osvdb.org/15433" source="OSVDB">15433</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dc++" name="dc++">
        <vers prev="1" num="0.673" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1090" published="2005-05-02" name="CVE-2005-1090" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14918" source="SECUNIA" patch="1" adv="1">14918</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20033" source="XF">maxthon-directory-traversal(20033)</ref>
      <ref url="http://www.securityfocus.com/bid/13074" source="BID">13074</ref>
      <ref url="http://www.raffon.net/advisories/maxthon/multvulns.html" source="MISC" adv="1">http://www.raffon.net/advisories/maxthon/multvulns.html</ref>
      <ref url="http://www.osvdb.org/15423" source="OSVDB">15423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxthon" name="maxthon">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1091" published="2005-05-02" name="CVE-2005-1091" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.raffon.net/advisories/maxthon/multvulns.html" source="MISC" patch="1" adv="1">http://www.raffon.net/advisories/maxthon/multvulns.html</ref>
      <ref url="http://secunia.com/advisories/14918" source="SECUNIA" patch="1" adv="1">14918</ref>
      <ref url="http://www.securityfocus.com/bid/13073" source="BID">13073</ref>
      <ref url="http://www.osvdb.org/15424" source="OSVDB">15424</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1092" published="2005-05-02" name="CVE-2005-1092" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13105" source="BID">13105</ref>
      <ref url="http://www.osvdb.org/15421" source="OSVDB">15421</ref>
      <ref url="http://secunia.com/advisories/14923" source="SECUNIA" adv="1">14923</ref>
      <ref url="http://lostmon.blogspot.com/2005/04/deluxeftp-plain-text-passwords.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/04/deluxeftp-plain-text-passwords.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="light_speed_technology" name="deluxeftp">
        <vers num="6.0.1" />
        <vers num="7.0.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1093" published="2005-05-02" name="CVE-2005-1093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13048" source="BID" patch="1">13048</ref>
      <ref url="http://forums.miranda-im.org/showthread.php?p=9624" source="CONFIRM" patch="1">http://forums.miranda-im.org/showthread.php?p=9624</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20013" source="XF">popupplus-message-bo(20013)</ref>
      <ref url="http://www.osvdb.org/15482" source="OSVDB">15482</ref>
      <ref url="http://www.miranda-im.org/" source="CONFIRM">http://www.miranda-im.org/</ref>
      <ref url="http://securitytracker.com/id?1013661" source="SECTRACK">1013661</ref>
      <ref url="http://sec.org.il/coverages.php?c=89" source="MISC" adv="1">http://sec.org.il/coverages.php?c=89</ref>
      <ref url="http://forums.miranda-im.org/showthread.php?t=1070" source="MISC" adv="1">http://forums.miranda-im.org/showthread.php?t=1070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="popup_plus_plugin" name="popup_plus_plugin_for_miranda_im">
        <vers num="2.0.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1094" published="2005-04-08" name="CVE-2005-1094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">FTP Now 2.6.14 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20025" source="XF" adv="1">ftpnow-sites-information-disclosure(20025)</ref>
      <ref url="http://securitytracker.com/id?1013657" source="SECTRACK" adv="1">1013657</ref>
      <ref url="http://secunia.com/advisories/14889" source="SECUNIA" adv="1">14889</ref>
      <ref url="http://www.osvdb.org/15296" source="OSVDB">15296</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1095" published="2005-05-02" name="CVE-2005-1095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20014" source="XF">ocean12-membershipmgr-mainasp-xss(20014)</ref>
      <ref url="http://www.securityfocus.com/bid/13046" source="BID">13046</ref>
      <ref url="http://www.osvdb.org/15306" source="OSVDB">15306</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=1865" source="MISC">http://www.hackerscenter.com/archive/view.asp?id=1865</ref>
      <ref url="http://securitytracker.com/id?1013667" source="SECTRACK">1013667</ref>
      <ref url="http://secunia.com/advisories/14864" source="SECUNIA" adv="1">14864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocean12_technologies" name="membership_manager_pro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1096" published="2005-04-06" name="CVE-2005-1096" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to execute arbitrary SQL commands via the UserID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20015" source="XF" adv="1">ocean12-membershipmgr-mainasp-sql-injection(20015)</ref>
      <ref url="http://www.securityfocus.com/bid/13049" source="BID" adv="1">13049</ref>
      <ref url="http://www.osvdb.org/15307" source="OSVDB" adv="1">15307</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=1865" source="MISC" adv="1">http://www.hackerscenter.com/archive/view.asp?id=1865</ref>
      <ref url="http://securitytracker.com/id?1013667" source="SECTRACK" adv="1">1013667</ref>
      <ref url="http://secunia.com/advisories/14864" source="SECUNIA" adv="1">14864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocean12_technologies" name="membership_manager_pro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1097" published="2005-05-02" name="CVE-2005-1097" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013673" source="SECTRACK">1013673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rebrand" name="p2p_share_spy">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1098" published="2005-05-02" name="CVE-2005-1098" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19967" source="XF">getdataback-ntfs-information-disclosure(19967)</ref>
      <ref url="http://www.osvdb.org/15210" source="OSVDB">15210</ref>
      <ref url="http://securitytracker.com/id?1013644" source="SECTRACK">1013644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="runtime_software" name="getdataback_for_ntfs">
        <vers num="2.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1099" published="2005-04-12" name="CVE-2005-1099" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the HandleChild function in server.c in Greylisting daemon (GLD) 1.3 and 1.4, when GLD is listening on a network interface, allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15492" source="OSVDB" patch="1" adv="1">15492</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-10</ref>
      <ref url="http://secunia.com/advisories/14941" source="SECUNIA" patch="1" adv="1">14941</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20066" source="XF" adv="1">gld-serverc-bo(20066)</ref>
      <ref url="http://www.gasmi.net/down/gld-history" source="CONFIRM" adv="1">http://www.gasmi.net/down/gld-history</ref>
      <ref url="http://securitytracker.com/alerts/2005/Apr/1013678.html" source="SECTRACK" adv="1">1013678</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111342432325670&amp;w=2" source="BUGTRAQ" adv="1">20050413 Gld 1.5 released (security fix)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111339935903880&amp;w=2" source="BUGTRAQ" adv="1">20050412 GLD (Greylisting daemon for Postfix) multiple vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="salim_gasmi" name="gld">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1100" published="2005-05-02" name="CVE-2005-1100" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-10.xml" source="GENTOO" patch="1">GLSA-200504-10</ref>
      <ref url="http://secunia.com/advisories/14941" source="SECUNIA" patch="1">14941</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20067" source="XF">gld-cnfc-format-string(20067)</ref>
      <ref url="http://www.osvdb.org/15493" source="OSVDB">15493</ref>
      <ref url="http://securitytracker.com/alerts/2005/Apr/1013678.html" source="SECTRACK">1013678</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111339935903880&amp;w=2" source="BUGTRAQ">20050412 GLD (Greylisting daemon for Postfix) multiple vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="salim_gasmi" name="gld">
        <vers num="1.3" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1101" published="2005-05-02" name="CVE-2005-1101" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20042" source="XF" patch="1">lotus-timedate-bo(20042)</ref>
      <ref url="http://www.ngssoftware.com/advisories/lotus-01.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/lotus-01.txt</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202431" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202431</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335285121320&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050412 Remote Buffer Overflow in Lotus Domino</ref>
      <ref url="http://www.osvdb.org/15364" source="OSVDB">15364</ref>
      <ref url="http://secunia.com/advisories/14879/" source="SECUNIA" adv="1">14879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_server">
        <vers num="6.0.5" />
        <vers num="6.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1102" published="2005-05-02" name="CVE-2005-1102" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://wordpress.org/support/topic.php?id=30721" source="MISC" patch="1" adv="1">http://wordpress.org/support/topic.php?id=30721</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-04</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111336102101571&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050412 WordPress XSS and HTML injection</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=88926" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=88926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1103" published="2005-04-12" name="CVE-2005-1103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by exporting the policy file, changing it, and importing it back into SSA.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335219201828&amp;w=2" source="BUGTRAQ" adv="1">20050412 IRM 011: Sygate,Security Agent (Sygate Secure Enterprise) Fail Open</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sygate_technologies" name="security_agent">
        <vers num="3.5_build_2576" />
        <vers num="3.5_build_2577" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1104" published="2005-05-02" name="CVE-2005-1104" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14930" source="SECUNIA" adv="1">14930</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335198125566&amp;w=2" source="BUGTRAQ" adv="1">20050412 Centra 7 XSS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centra" name="centra">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1105" published="2005-05-02" name="CVE-2005-1105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335615600839&amp;w=2" source="BUGTRAQ">20050412 JavaMail allows directory traversal in attachments</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="javamail">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1106" published="2005-05-02" name="CVE-2005-1106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335498626164&amp;w=2" source="BUGTRAQ" adv="1">20050413 QuickTime for Windows malformed GIF DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime_pictureviewer">
        <vers num="6.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1107" published="2005-04-18" name="CVE-2005-1107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection by modifying certain files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=233&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050418 McAfee Internet Security Suite 2005 Insecure File Permission Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="internet_security_suite">
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1108" published="2005-05-02" name="CVE-2005-1108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ij_untrusted_url function in JunkBuster 2.0.2-r2, with single-threaded mode enabled, allows remote attackers to overwrite the referrer field via a crafted HTTP request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20093" source="XF" patch="1">junkbuster-ijuntrustedurl-gain-access(20093)</ref>
      <ref url="http://www.securityfocus.com/bid/13147" source="BID" patch="1">13147</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-11.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-11</ref>
      <ref url="http://www.debian.org/security/2005/dsa-713" source="DEBIAN" patch="1" adv="1">DSA-713</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=88537" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=88537</ref>
      <ref url="http://www.osvdb.org/15502" source="OSVDB">15502</ref>
      <ref url="http://secunia.com/advisories/14932/" source="SECUNIA" adv="1">14932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="junkbuster" name="internet_junkbuster">
        <vers num="2.0.2_r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1109" published="2005-05-02" name="CVE-2005-1109" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The filtering of URLs in JunkBuster before 2.0.2-r3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via heap corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20094" source="XF" patch="1">junkbuster-heap-corruption(20094)</ref>
      <ref url="http://www.securityfocus.com/bid/13146" source="BID" patch="1">13146</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-11.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-11</ref>
      <ref url="http://www.debian.org/security/2005/dsa-713" source="DEBIAN" patch="1" adv="1">DSA-713</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=88537" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=88537</ref>
      <ref url="http://www.osvdb.org/15503" source="OSVDB">15503</ref>
      <ref url="http://secunia.com/advisories/14932/" source="SECUNIA" adv="1">14932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="junkbuster" name="internet_junkbuster">
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.2_r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1110" published="2005-05-02" name="CVE-2005-1110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the RespondeHTTPPendiente function in the HTTP server for SUMUS 0.2.2 allows remote attackers to execute arbitrary code via a large packet sent to TCP port 81.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20110" source="XF">sumus-respondehttppendiente-bo(20110)</ref>
      <ref url="http://securitytracker.com/id?1013717" source="SECTRACK">1013717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111350491800089&amp;w=2" source="BUGTRAQ">20050414 sumus[v0.2.2]: (httpd) remote buffer overflow exploit.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sumus" name="sumus">
        <vers num="0.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1111" published="2005-05-02" name="CVE-2005-1111" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13159" source="BID">13159</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9783" source="OVAL">oval:org.mitre.oval:def:9783</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111342664116120&amp;w=2" source="BUGTRAQ" adv="1">20050413 cpio TOCTOU file-permissions vulnerability</ref>
      <ref url="http://www.ubuntu.com/usn/usn-189-1" source="UBUNTU">USN-189-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-806.html" source="REDHAT">RHSA-2005:806</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-378.html" source="REDHAT">RHSA-2005:378</ref>
      <ref url="http://www.osvdb.org/15725" source="OSVDB">15725</ref>
      <ref url="http://www.debian.org/security/2005/dsa-846" source="DEBIAN">DSA-846</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/18395" source="SECUNIA">18395</ref>
      <ref url="http://secunia.com/advisories/18290" source="SECUNIA">18290</ref>
      <ref url="http://secunia.com/advisories/17532" source="SECUNIA">17532</ref>
      <ref url="http://secunia.com/advisories/17123" source="SECUNIA">17123</ref>
      <ref url="http://secunia.com/advisories/16998" source="SECUNIA">16998</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txt" source="SCO">SCOSA-2005.32</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txt" source="SCO">SCOSA-2006.2</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.asc" source="FREEBSD">FreeBSD-SA-06:03</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:358" source="OVAL" sig="1">oval:org.mitre.oval:def:358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="cpio">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="2.4-2" />
        <vers num="2.5" />
        <vers num="2.5.90" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1112" published="2005-05-02" name="CVE-2005-1112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20099" source="XF">ibm-websphere-information-disclosure(20099)</ref>
      <ref url="http://securitytracker.com/id?1013697" source="SECTRACK" adv="1">1013697</ref>
      <ref url="http://secunia.com/advisories/14962" source="SECUNIA" adv="1">14962</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111342594129109&amp;w=2" source="BUGTRAQ" adv="1">20050413 IBM WebSphere Widespread configuration JSP disclosure</ref>
      <ref url="http://www.securityfocus.com/bid/13160" source="BID">13160</ref>
      <ref url="http://www.osvdb.org/15501" source="OSVDB">15501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.2.1" />
        <vers num="5.0.2.3" />
        <vers num="5.0.2.4" />
        <vers num="5.0.2.5" />
        <vers num="5.0.2.6" />
        <vers num="5.0.2.7" />
        <vers num="5.0.2.8" />
        <vers num="5.0.2.9" />
        <vers num="5.1.0" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="5.1.1" />
        <vers num="5.1.1.1" />
        <vers num="5.1.1.2" />
        <vers num="5.1.1.3" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1113" published="2005-05-02" name="CVE-2005-1113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52 and earlier allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3) portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c parameter to index.php, or (7) the article parameter to portal.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20085" source="XF">phpbb-multiple-modules-xss(20085)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343406309969&amp;w=2" source="BUGTRAQ">20050413 Multiple Sql injection and XSS vulnerabilities in phpBB Plus and below and some of its modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb_plus">
        <vers num="1.3" />
        <vers num="1.51" />
        <vers prev="1" num="1.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1114" published="2005-05-02" name="CVE-2005-1114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20086" source="XF">phpbb-multiple-modules-sql-injection(20086)</ref>
      <ref url="http://www.securityfocus.com/bid/13155" source="BID">13155</ref>
      <ref url="http://www.digitalparadox.org/advisories/phpbbp.txt" source="MISC">http://www.digitalparadox.org/advisories/phpbbp.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343406309969&amp;w=2" source="BUGTRAQ" adv="1">20050413 Multiple Sql injection and XSS vulnerabilities in phpBB Plus and below and some of its modules</ref>
      <ref url="http://www.osvdb.org/15931" source="OSVDB">15931</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
      </prod>
      <prod vendor="smartor" name="photo_album">
        <vers num="2.0.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1115" published="2005-05-02" name="CVE-2005-1115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13158" source="BID">13158</ref>
      <ref url="http://www.securityfocus.com/bid/13157" source="BID">13157</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343406309969&amp;w=2" source="BUGTRAQ" adv="1">20050413 Multiple Sql injection and XSS vulnerabilities in phpBB Plus and below and some of its modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
      </prod>
      <prod vendor="smartor" name="photo_album">
        <vers num="2.0.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1116" published="2005-05-02" name="CVE-2005-1116" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343406309969&amp;w=2" source="BUGTRAQ">20050413 Multiple Sql injection and XSS vulnerabilities in phpBB Plus and below and some of its modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1117" published="2005-05-02" name="CVE-2005-1117" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifying the site parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13169" source="BID">13169</ref>
      <ref url="http://secunia.com/advisories/14972" source="SECUNIA" adv="1">14972</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111350434925520&amp;w=2" source="BUGTRAQ" adv="1">20050414 All4WWW-Homepagecreator Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="all4www" name="all4www-homepagecreator">
        <vers num="1.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1118" published="2005-04-14" name="CVE-2005-1118" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the postdata parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/366372" source="CERT-VN">VU#366372</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20098" source="XF" patch="1" adv="1">rsa-auth-postdata-xss(20098)</ref>
      <ref url="http://www.oliverkarow.de/research/rsaxss.txt" source="MISC" patch="1" adv="1">http://www.oliverkarow.de/research/rsaxss.txt</ref>
      <ref url="http://securitytracker.com/id?1013724" source="SECTRACK" patch="1" adv="1">1013724</ref>
      <ref url="http://secunia.com/advisories/14954" source="SECUNIA" patch="1" adv="1">14954</ref>
      <ref url="http://www.securityfocus.com/bid/13168" source="BID" adv="1">13168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="authentication_agent_for_web">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1119" published="2005-05-02" name="CVE-2005-1119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13171" source="BID">13171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.3_p1" />
        <vers num="1.6.3_p2" />
        <vers num="1.6.3_p3" />
        <vers num="1.6.3_p4" />
        <vers num="1.6.3_p5" />
        <vers num="1.6.3_p6" />
        <vers num="1.6.3_p7" />
        <vers num="1.6.4" />
        <vers num="1.6.4_p1" />
        <vers num="1.6.4_p2" />
        <vers num="1.6.5" />
        <vers num="1.6.5_p1" />
        <vers num="1.6.5_p2" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.7_p5" />
        <vers num="1.6.8" />
        <vers num="1.6.8_p1" />
        <vers num="1.6.8_p8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1120" published="2005-05-02" name="CVE-2005-1120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in IlohaMail 0.8.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the e-mail (1) body, (2) filename, or (3) MIME type.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20095" source="XF">ilohamail-mail-attached-file-xss(20095)</ref>
      <ref url="http://www.securityfocus.com/bid/13175" source="BID">13175</ref>
      <ref url="http://secunia.com/advisories/14957" source="SECUNIA" adv="1">14957</ref>
      <ref url="http://www.osvdb.org/15506" source="OSVDB">15506</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1010" source="DEBIAN">DSA-1010</ref>
      <ref url="http://securitytracker.com/id?1013701" source="SECTRACK">1013701</ref>
      <ref url="http://secunia.com/advisories/19266" source="SECUNIA">19266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ilohamail" name="ilohamail">
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.4.2" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
        <vers num="0.8.10" />
        <vers num="0.8.11" />
        <vers num="0.8.12" />
        <vers num="0.8.13" />
        <vers num="0.8.14_rc1" />
        <vers num="0.8.14_rc2" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1121" published="2005-05-02" name="CVE-2005-1121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13172" source="BID" patch="1">13172</ref>
      <ref url="http://www.debian.org/security/2005/dsa-726" source="DEBIAN" patch="1" adv="1">DSA-726</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200505-02.xml" source="GENTOO" patch="1" adv="1">GLSA-200505-02</ref>
      <ref url="http://rst.void.ru/papers/advisory24.txt" source="MISC" patch="1" adv="1">http://rst.void.ru/papers/advisory24.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20191" source="XF">oops-format-string(20191)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igor_khasilev" name="oops_proxy_server">
        <vers num="1.4.22" />
        <vers num="1.5.19" />
        <vers num="1.5.53" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1122" published="2005-04-14" name="CVE-2005-1122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded format string specifiers (aka "double expansion error").</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-14.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-14</ref>
      <ref url="http://secunia.com/advisories/14953" source="SECUNIA" patch="1" adv="1">14953</ref>
      <ref url="http://www.osvdb.org/15511" source="OSVDB" adv="1">15511</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=87916" source="MISC" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=87916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monkey" name="monkey_http_daemon">
        <vers num="0.1.4" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1123" published="2005-05-02" name="CVE-2005-1123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-14.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-14</ref>
      <ref url="http://www.osvdb.org/15512" source="OSVDB">15512</ref>
      <ref url="http://secunia.com/advisories/14953" source="SECUNIA" adv="1">14953</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=87916" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=87916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monkey" name="monkey_http_daemon">
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.1.1" />
        <vers num="0.4.2" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.4.2" />
        <vers num="0.8.4_rc1" />
        <vers num="0.8.4_rc2" />
        <vers num="0.8.5" />
        <vers num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1124" published="2005-05-02" name="CVE-2005-1124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57734-1" source="SUNALERT" patch="1" adv="1">57734</ref>
      <ref url="http://secunia.com/advisories/14971" source="SECUNIA" patch="1">14971</ref>
      <ref url="http://www.osvdb.org/15516" source="OSVDB">15516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1125" published="2005-05-02" name="CVE-2005-1125" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit other vulnerabilities before the _libsafe_die function call is completed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13190" source="BID">13190</ref>
      <ref url="http://www.securityfocus.com/archive/1/395999" source="BUGTRAQ" adv="1">20050415 [Overflow.pl] Libsafe - Safety Check Bypass Vulnerability</ref>
      <ref url="http://www.overflow.pl/adv/libsafebypass.txt" source="MISC" adv="1">http://www.overflow.pl/adv/libsafebypass.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="libsafe">
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1126" published="2005-04-15" name="CVE-2005-1126" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20114" source="XF" patch="1" adv="1">freebsd-ifconf-information-disclosure(20114)</ref>
      <ref url="http://www.osvdb.org/15514" source="OSVDB" patch="1" adv="1">15514</ref>
      <ref url="http://secunia.com/advisories/14959" source="SECUNIA" patch="1" adv="1">14959</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:04.ifconf.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-05:04</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2256" source="VUPEN">ADV-2005-2256</ref>
      <ref url="http://www.securityfocus.com/bid/15252" source="BID">15252</ref>
      <ref url="http://secunia.com/advisories/17368" source="SECUNIA">17368</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Oct/msg00000.html" source="APPLE">APPLE-SA-2005-10-31</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1127" published="2005-05-02" name="CVE-2005-1127" modified="2010-04-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14958" source="SECUNIA" patch="1">14958</ref>
      <ref url="http://lists.ee.ethz.ch/postgrey/msg00647.html" source="MLIST" patch="1">[postgrey] 20050414 ANNOUNCE: Postgrey 1.21 (SECURITY)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20108" source="XF">postgrey-logging-dos(20108)</ref>
      <ref url="http://www.osvdb.org/15517" source="OSVDB">15517</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111354538331167&amp;w=2" source="FULLDISC">20050415 Use of function "log" in Perl module Net::Server</ref>
      <ref url="http://lists.ee.ethz.ch/postgrey/msg00630.html" source="MLIST">[postgrey] 20050414 Re: Problem with crashing postgrey</ref>
      <ref url="http://lists.ee.ethz.ch/postgrey/msg00627.html" source="MLIST">[postgrey] 20050414 Problem with crashing postgrey</ref>
      <ref url="http://www.securityfocus.com/bid/13193" source="BID">13193</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:131" source="MANDRIVA">MDKSA-2006:131</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200608-18.xml" source="GENTOO">GLSA-200608-18</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1122" source="DEBIAN">DSA-1122</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1121" source="DEBIAN">DSA-1121</ref>
      <ref url="http://secunia.com/advisories/21452" source="SECUNIA">21452</ref>
      <ref url="http://secunia.com/advisories/21164" source="SECUNIA">21164</ref>
      <ref url="http://secunia.com/advisories/21152" source="SECUNIA">21152</ref>
      <ref url="http://secunia.com/advisories/21149" source="SECUNIA">21149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgrey" name="postgrey">
        <vers prev="1" num="1.16" />
        <vers num="1.17" />
        <vers num="1.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1128" published="2005-05-02" name="CVE-2005-1128" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15541" source="OSVDB">15541</ref>
      <ref url="http://securitytracker.com/id?1013703" source="SECTRACK">1013703</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_hosting_control_system" name="virtual_hosting_control_system">
        <vers num="2.2" />
        <vers prev="1" num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1129" published="2005-05-02" name="CVE-2005-1129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, which may cause sensitive information to be sent to the wrong recipient.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20088" source="XF">egroupware-email-information-disclosure(20088)</ref>
      <ref url="http://www.securityfocus.com/bid/13137" source="BID">13137</ref>
      <ref url="http://www.osvdb.org/15499" source="OSVDB">15499</ref>
      <ref url="http://secunia.com/advisories/14940" source="SECUNIA">14940</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0157.html" source="BUGTRAQ">20050412 eGroupWare Leaks Files</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1130" published="2005-04-12" name="CVE-2005-1130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart allows remote attackers to inject arbitrary web script or HTML via the pg parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20092" source="XF" adv="1">pinnaclecart-index-xss(20092)</ref>
      <ref url="http://www.securityfocus.com/bid/13138" source="BID" adv="1">13138</ref>
      <ref url="http://www.osvdb.org/15485" source="OSVDB" adv="1">15485</ref>
      <ref url="http://systemsecure.org/board/index.php?showtopic=8" source="MISC" adv="1">http://systemsecure.org/board/index.php?showtopic=8</ref>
      <ref url="http://secunia.com/advisories/14924" source="SECUNIA" adv="1">14924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="desert_dog_software" name="pinnacle_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1131" published="2005-05-02" name="CVE-2005-1131" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Veritas i3 Focalpoint Server 7.1 and earlier has unknown attack vectors and unknown but "critical" impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13142" source="BID" patch="1">13142</ref>
      <ref url="http://seer.support.veritas.com/docs/276119.htm" source="MISC" patch="1">http://seer.support.veritas.com/docs/276119.htm</ref>
      <ref url="http://securitytracker.com/id?1013694" source="SECTRACK" patch="1">1013694</ref>
      <ref url="http://secunia.com/advisories/14934" source="SECUNIA" patch="1">14934</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0008.html" source="VULNWATCH" patch="1">20040413 Patch available for critical Veritas i3 Server vulnerability</ref>
      <ref url="http://www.osvdb.org/15498" source="OSVDB">15498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="i3_focalpoint_server">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1132" published="2005-05-02" name="CVE-2005-1132" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20091" source="XF">lg-u8120-mobile-phone-dos(20091)</ref>
      <ref url="http://www.securityfocus.com/bid/13154" source="BID" sig="1">13154</ref>
      <ref url="http://www.securityfocus.com/archive/1/395714" source="BUGTRAQ" sig="1">20050413 LG U8120 Mobile Phone Denial of Service</ref>
      <ref url="http://securitytracker.com/id?1013777" source="SECTRACK" sig="1">1013777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lg_electronics" name="lg_mobile_phone">
        <vers num="u8120" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1133" published="2005-05-02" name="CVE-2005-1133" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13156" source="BID">13156</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358863001693&amp;w=2" source="BUGTRAQ">20050414 Enumeration of AS/400 users and their status via POP3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="iseries_as_400">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1134" published="2005-04-13" name="CVE-2005-1134" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13161" source="BID" patch="1" adv="1">13161</ref>
      <ref url="http://www.s9y.org/63.html#A9" source="CONFIRM" patch="1" adv="1">http://www.s9y.org/63.html#A9</ref>
      <ref url="http://www.s9y.org/5.html" source="CONFIRM" patch="1" adv="1">http://www.s9y.org/5.html</ref>
      <ref url="http://secunia.com/advisories/15145" source="SECUNIA" patch="1" adv="1">15145</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20119" source="XF" adv="1">serendipity-urlid-entryid-sql-injection(20119)</ref>
      <ref url="http://www.osvdb.org/15542" source="OSVDB" adv="1">15542</ref>
      <ref url="http://securitytracker.com/id?1013699" source="SECTRACK" adv="1">1013699</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Apr/0195.html" source="BUGTRAQ">20050413 serendipity SQL Injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5_pl1" />
        <vers num="0.6" />
        <vers num="0.6_pl1" />
        <vers num="0.6_pl2" />
        <vers num="0.6_pl3" />
        <vers num="0.6_rc1" />
        <vers num="0.6_rc2" />
        <vers num="0.7" />
        <vers num="0.7_beta1" />
        <vers num="0.7_beta2" />
        <vers num="0.7_beta3" />
        <vers num="0.7_beta4" />
        <vers num="0.7_rc1" />
        <vers num="0.8_beta5" />
        <vers num="0.8_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1135" published="2005-05-02" name="CVE-2005-1135" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/ftopict-651.html" source="MISC">http://www.waraxe.us/ftopict-651.html</ref>
      <ref url="http://www.securityfocus.com/bid/13170" source="BID">13170</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359320312609&amp;w=2" source="BUGTRAQ">20050415 [ECHO_ADV_12$2005] Vulnerabilities in sphpblog</ref>
      <ref url="http://echo.or.id/adv/adv12-y3dips-2005.txt" source="MISC">http://echo.or.id/adv/adv12-y3dips-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_palmo" name="simple_php_blog">
        <vers num="0.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1136" published="2005-04-14" name="CVE-2005-1136" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords via a direct request to these files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/ftopict-651.html" source="MISC" adv="1">http://www.waraxe.us/ftopict-651.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359320312609&amp;w=2" source="BUGTRAQ" adv="1">20050415 [ECHO_ADV_12$2005] Vulnerabilities in sphpblog</ref>
      <ref url="http://echo.or.id/adv/adv12-y3dips-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv12-y3dips-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sphpblog" name="sphpblog">
        <vers num="0.4_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1137" published="2005-05-02" name="CVE-2005-1137" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359320312609&amp;w=2" source="BUGTRAQ">20050415 [ECHO_ADV_12$2005] Vulnerabilities in sphpblog</ref>
      <ref url="http://echo.or.id/adv/adv12-y3dips-2005.txt" source="MISC">http://echo.or.id/adv/adv12-y3dips-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_palmo" name="simple_php_blog">
        <vers num="0.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1138" published="2005-04-18" name="CVE-2005-1138" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kerio.com/kms_history.html" source="CONFIRM" patch="1" adv="1">http://www.kerio.com/kms_history.html</ref>
      <ref url="http://securitytracker.com/id?1013708" source="SECTRACK" patch="1" adv="1">1013708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.6.3" />
        <vers num="5.6.4" />
        <vers num="5.6.5" />
        <vers num="5.7.0" />
        <vers num="5.7.1" />
        <vers num="5.7.10" />
        <vers num="5.7.2" />
        <vers num="5.7.3" />
        <vers num="5.7.4" />
        <vers num="5.7.5" />
        <vers num="5.7.6" />
        <vers num="5.7.7" />
        <vers num="5.7.8" />
        <vers num="5.7.9" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1139" published="2005-04-14" name="CVE-2005-1139" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Opera 8 Beta 3, when using first-generation vetted digital certificates, displays the Organizational information of an SSL certificate, which is easily spoofed and can facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.geotrust.com/resources/advisory/sslorg/sslorg-advisory.htm" source="MISC" patch="1" adv="1">http://www.geotrust.com/resources/advisory/sslorg/sslorg-advisory.htm</ref>
      <ref url="http://www.securityfocus.com/bid/13176" source="BID" adv="1">13176</ref>
      <ref url="http://www.geotrust.com/resources/advisory/sslorg/index.htm" source="MISC" adv="1">http://www.geotrust.com/resources/advisory/sslorg/index.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40503" source="XF">opera-ssl-spoofing(40503)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_31_opera.html" source="SUSE">SUSE-SA:2005:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="8_beta_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1140" published="2005-04-15" name="CVE-2005-1140" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13192" source="BID" adv="1">13192</ref>
      <ref url="http://www.securityfocus.com/archive/1/395988" source="BUGTRAQ" adv="1">20050415 myBloggie 2.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1141" published="2005-04-15" name="CVE-2005-1141" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via a PNM file with large width and height values, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.overflow.pl/adv/gocr.txt" source="MISC" adv="1">http://www.overflow.pl/adv/gocr.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358557823673&amp;w=2" source="BUGTRAQ" adv="1">20050415 [Overflow.pl] GOCR - Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gocr" name="optical_character_recognition_utility">
        <vers num="0.3.2" />
        <vers num="0.3.4" />
        <vers num="0.37" />
        <vers num="0.39" />
        <vers num="0.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1142" published="2005-04-15" name="CVE-2005-1142" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.overflow.pl/adv/gocr.txt" source="MISC" adv="1">http://www.overflow.pl/adv/gocr.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358557823673&amp;w=2" source="BUGTRAQ" adv="1">20050415 [Overflow.pl] GOCR - Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gocr" name="optical_character_recognition_utility">
        <vers num="0.3.2" />
        <vers num="0.3.4" />
        <vers num="0.37" />
        <vers num="0.39" />
        <vers num="0.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1143" published="2005-04-12" name="CVE-2005-1143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.snkenjoi.com/secadv/secadv4.txt" source="MISC" adv="1">http://www.snkenjoi.com/secadv/secadv4.txt</ref>
      <ref url="http://www.osvdb.org/15544" source="OSVDB" adv="1">15544</ref>
      <ref url="http://securitytracker.com/id?1013704" source="SECTRACK" adv="1">1013704</ref>
      <ref url="http://docs.easyphpcalendar.com/Change%20Log/changeLog.htm" source="CONFIRM">http://docs.easyphpcalendar.com/Change%20Log/changeLog.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyphpcalendar" name="easyphpcalendar">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1144" published="2005-04-12" name="CVE-2005-1144" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.</descript>
    </desc>
    <sols>
      <sol source="nvd">Version 6.2.8 and above are fixed.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.snkenjoi.com/secadv/secadv4.txt" source="MISC" adv="1">http://www.snkenjoi.com/secadv/secadv4.txt</ref>
      <ref url="http://www.osvdb.org/15545" source="OSVDB" adv="1">15545</ref>
      <ref url="http://securitytracker.com/id?1013704" source="SECTRACK" adv="1">1013704</ref>
      <ref url="http://docs.easyphpcalendar.com/Change%20Log/changeLog.htm" source="CONFIRM">http://docs.easyphpcalendar.com/Change%20Log/changeLog.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyphpcalendar" name="easyphpcalendar">
        <vers prev="1" num="6.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1145" published="2005-04-12" name="CVE-2005-1145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.snkenjoi.com/secadv/secadv3.txt" source="MISC" adv="1">http://www.snkenjoi.com/secadv/secadv3.txt</ref>
      <ref url="http://www.osvdb.org/15547" source="OSVDB" adv="1">15547</ref>
      <ref url="http://securitytracker.com/id?1013705" source="SECTRACK" adv="1">1013705</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calendarscript" name="calendarscript">
        <vers num="3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1146" published="2005-04-12" name="CVE-2005-1146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20103" source="XF" adv="1">calendarscript-calendarpl-xss(20103)</ref>
      <ref url="http://www.snkenjoi.com/secadv/secadv3.txt" source="MISC" adv="1">http://www.snkenjoi.com/secadv/secadv3.txt</ref>
      <ref url="http://securitytracker.com/id?1013705" source="SECTRACK" adv="1">1013705</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calendarscript" name="calendarscript">
        <vers num="3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1147" published="2005-04-12" name="CVE-2005-1147" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20102" source="XF" adv="1">calendarscript-path-disclosure(20102)</ref>
      <ref url="http://www.snkenjoi.com/secadv/secadv3.txt" source="MISC" adv="1">http://www.snkenjoi.com/secadv/secadv3.txt</ref>
      <ref url="http://www.osvdb.org/15546" source="OSVDB" adv="1">15546</ref>
      <ref url="http://securitytracker.com/id?1013705" source="SECTRACK" adv="1">1013705</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1148" published="2005-05-02" name="CVE-2005-1148" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20102" source="XF">calendarscript-path-disclosure(20102)</ref>
      <ref url="http://www.snkenjoi.com/secadv/secadv3.txt" source="MISC" adv="1">http://www.snkenjoi.com/secadv/secadv3.txt</ref>
      <ref url="http://securitytracker.com/id?1013705" source="SECTRACK">1013705</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calendarscript" name="calendarscript">
        <vers num="3.20" />
        <vers num="3.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1149" published="2005-04-13" name="CVE-2005-1149" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13148" source="BID" adv="1">13148</ref>
      <ref url="http://www.osvdb.org/15494" source="OSVDB" adv="1">15494</ref>
      <ref url="http://securitytracker.com/id?1013681" source="SECTRACK" adv="1">1013681</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1150" published="2005-05-02" name="CVE-2005-1150" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57760-1" source="SUNALERT" patch="1" adv="1">57760</ref>
      <ref url="http://secunia.com/advisories/14961" source="SECUNIA" patch="1" adv="1">14961</ref>
      <ref url="http://www.osvdb.org/15504" source="OSVDB">15504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.0" edition="sp4" />
        <vers num="6.0" edition="sp5" />
        <vers num="6.0" edition="sp6" />
        <vers num="6.0" edition="sp7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1151" published="2005-05-25" name="CVE-2005-1151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-728" source="DEBIAN" patch="1">DSA-728</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200505-17.xml" source="GENTOO">GLSA-200505-17</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=90622" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=90622</ref>
      <ref url="http://secunia.com/advisories/15505" source="SECUNIA">15505</ref>
      <ref url="http://secunia.com/advisories/15478" source="SECUNIA">15478</ref>
      <ref url="http://secunia.com/advisories/15475" source="SECUNIA">15475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="qpopper">
        <vers prev="1" num="4.0.4" />
        <vers num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1152" published="2005-05-25" name="CVE-2005-1152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-728" source="DEBIAN" patch="1">DSA-728</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200505-17.xml" source="GENTOO">GLSA-200505-17</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=90622" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=90622</ref>
      <ref url="http://bugs.gentoo.org/attachment.cgi?id=58329&amp;action=view" source="MISC">http://bugs.gentoo.org/attachment.cgi?id=58329&amp;action=view</ref>
      <ref url="http://secunia.com/advisories/15505" source="SECUNIA">15505</ref>
      <ref url="http://secunia.com/advisories/15478" source="SECUNIA">15478</ref>
      <ref url="http://secunia.com/advisories/15475" source="SECUNIA">15475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="qpopper">
        <vers prev="1" num="4.0.4" />
        <vers num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1153" published="2005-05-02" name="CVE-2005-1153" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-386.html" source="REDHAT" patch="1" adv="1">RHSA-2005:386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml" source="GENTOO" patch="1">GLSA-200504-18</ref>
      <ref url="http://secunia.com/advisories/14992" source="SECUNIA" patch="1" adv="1">14992</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=289204" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=289204</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-35.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-35.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9584" source="OVAL">oval:org.mitre.oval:def:9584</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100023" source="OVAL" sig="1">oval:org.mitre.oval:def:100023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1154" published="2005-05-02" name="CVE-2005-1154" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=289675" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=289675</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-386.html" source="REDHAT" patch="1" adv="1">RHSA-2005:386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml" source="GENTOO" patch="1">GLSA-200504-18</ref>
      <ref url="http://secunia.com/advisories/14992" source="SECUNIA" patch="1" adv="1">14992</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-36.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-36.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10339" source="OVAL">oval:org.mitre.oval:def:10339</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.securityfocus.com/bid/13230" source="BID">13230</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100022" source="OVAL" sig="1">oval:org.mitre.oval:def:100022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1155" published="2005-05-02" name="CVE-2005-1155" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a &lt;LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/973309" source="CERT-VN" patch="1" adv="1">VU#973309</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=290036" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=290036</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-386.html" source="REDHAT" patch="1" adv="1">RHSA-2005:386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-18</ref>
      <ref url="http://secunia.com/advisories/14992" source="SECUNIA" patch="1" adv="1">14992</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.securityfocus.com/bid/13216" source="BID">13216</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-37.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-37.html</ref>
      <ref url="http://www.mikx.de/firelinking/" source="MISC">http://www.mikx.de/firelinking/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10655" source="OVAL">oval:org.mitre.oval:def:10655</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100021" source="OVAL" sig="1">oval:org.mitre.oval:def:100021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1156" published="2005-05-02" name="CVE-2005-1156" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=290037" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=290037</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20125" source="XF" patch="1">mozilla-plugin-xss(20125)</ref>
      <ref url="http://www.securityfocus.com/bid/13211" source="BID" patch="1">13211</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-386.html" source="REDHAT" patch="1" adv="1">RHSA-2005:386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-18</ref>
      <ref url="http://securitytracker.com/id?1013745" source="SECTRACK" patch="1">1013745</ref>
      <ref url="http://secunia.com/advisories/14996" source="SECUNIA" patch="1" adv="1">14996</ref>
      <ref url="http://secunia.com/advisories/14992" source="SECUNIA" patch="1" adv="1">14992</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-38.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-38.html</ref>
      <ref url="http://www.mikx.de/firesearching/" source="MISC">http://www.mikx.de/firesearching/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11230" source="OVAL">oval:org.mitre.oval:def:11230</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100020" source="OVAL" sig="1">oval:org.mitre.oval:def:100020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1157" published="2005-05-02" name="CVE-2005-1157" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=290037" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=290037</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20125" source="XF" patch="1">mozilla-plugin-xss(20125)</ref>
      <ref url="http://www.securityfocus.com/bid/13211" source="BID" patch="1">13211</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-386.html" source="REDHAT" patch="1" adv="1">RHSA-2005:386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://secunia.com/advisories/14996" source="SECUNIA" patch="1" adv="1">14996</ref>
      <ref url="http://secunia.com/advisories/14992" source="SECUNIA" patch="1" adv="1">14992</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-38.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-38.html</ref>
      <ref url="http://www.mikx.de/firesearching/" source="MISC">http://www.mikx.de/firesearching/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9961" source="OVAL">oval:org.mitre.oval:def:9961</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1158" published="2005-05-02" name="CVE-2005-1158" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=290079" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=290079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-39.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-39.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11734" source="OVAL">oval:org.mitre.oval:def:11734</ref>
      <ref url="http://www.securityfocus.com/bid/13231" source="BID">13231</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100019" source="OVAL" sig="1">oval:org.mitre.oval:def:100019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1159" published="2005-05-02" name="CVE-2005-1159" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=290162" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=290162</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20123" source="XF" patch="1">mozilla-installtrigger-command-execution(20123)</ref>
      <ref url="http://www.securityfocus.com/bid/13232" source="BID" patch="1">13232</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-386.html" source="REDHAT" patch="1" adv="1">RHSA-2005:386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-18</ref>
      <ref url="http://securitytracker.com/id?1013743" source="SECTRACK" patch="1">1013743</ref>
      <ref url="http://securitytracker.com/id?1013742" source="SECTRACK" patch="1">1013742</ref>
      <ref url="http://secunia.com/advisories/14992" source="SECUNIA" patch="1" adv="1">14992</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-40.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-40.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10629" source="OVAL">oval:org.mitre.oval:def:10629</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100018" source="OVAL" sig="1">oval:org.mitre.oval:def:100018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1160" published="2005-05-02" name="CVE-2005-1160" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=289961" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=289961</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=289083" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=289083</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=289074" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=289074</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-386.html" source="REDHAT" patch="1" adv="1">RHSA-2005:386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-383.html" source="REDHAT" patch="1" adv="1">RHSA-2005:383</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-18</ref>
      <ref url="http://secunia.com/advisories/14992" source="SECUNIA" patch="1" adv="1">14992</ref>
      <ref url="http://secunia.com/advisories/14938" source="SECUNIA" patch="1" adv="1">14938</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-41.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-41.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11291" source="OVAL">oval:org.mitre.oval:def:11291</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.securityfocus.com/bid/13233" source="BID">13233</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100017" source="OVAL" sig="1">oval:org.mitre.oval:def:100017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1161" published="2005-05-02" name="CVE-2005-1161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13183" source="BID" patch="1">13183</ref>
      <ref url="http://www.securityfocus.com/bid/13182" source="BID" patch="1">13182</ref>
      <ref url="http://www.securityfocus.com/bid/13181" source="BID" patch="1">13181</ref>
      <ref url="http://secunia.com/advisories/14969" source="SECUNIA" patch="1">14969</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20097" source="XF">oneworldstore-product-category-sql-injection(20097)</ref>
      <ref url="http://www.osvdb.org/15520" source="OSVDB">15520</ref>
      <ref url="http://www.osvdb.org/15519" source="OSVDB">15519</ref>
      <ref url="http://www.osvdb.org/15518" source="OSVDB">15518</ref>
      <ref url="http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab" source="CONFIRM">http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab</ref>
      <ref url="http://securitytracker.com/id?1013720" source="SECTRACK">1013720</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352017704126&amp;w=2" source="BUGTRAQ">20050414 Multiple multiple sql injection/errors and xss vulnerabilities in OneWorldStore</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneworldstore" name="oneworldstore">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1162" published="2005-05-02" name="CVE-2005-1162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail parameter to owContactUs.asp, (2) bSub parameter to owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields in owProductDetail.asp.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13186" source="BID" patch="1">13186</ref>
      <ref url="http://www.securityfocus.com/bid/13185" source="BID" patch="1">13185</ref>
      <ref url="http://www.securityfocus.com/bid/13184" source="BID" patch="1">13184</ref>
      <ref url="http://securitytracker.com/id?1013720" source="SECTRACK" patch="1">1013720</ref>
      <ref url="http://secunia.com/advisories/14969" source="SECUNIA" patch="1" adv="1">14969</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20096" source="XF">oneworldstore-xss(20096)</ref>
      <ref url="http://www.osvdb.org/15523" source="OSVDB">15523</ref>
      <ref url="http://www.osvdb.org/15522" source="OSVDB">15522</ref>
      <ref url="http://www.osvdb.org/15521" source="OSVDB">15521</ref>
      <ref url="http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab" source="CONFIRM" adv="1">http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352017704126&amp;w=2" source="BUGTRAQ" adv="1">20050414 Multiple multiple sql injection/errors and xss vulnerabilities in OneWorldStore</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneworldstore" name="oneworldstore">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1163" published="2005-05-02" name="CVE-2005-1163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20101" source="XF">yager-datablock-bo(20101)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20100" source="XF">yager-nickname-bo(20100)</ref>
      <ref url="http://www.securityfocus.com/bid/13178" source="BID">13178</ref>
      <ref url="http://www.securityfocus.com/bid/13177" source="BID">13177</ref>
      <ref url="http://www.osvdb.org/15508" source="OSVDB">15508</ref>
      <ref url="http://www.osvdb.org/15507" source="OSVDB">15507</ref>
      <ref url="http://secunia.com/advisories/14967" source="SECUNIA" adv="1">14967</ref>
      <ref url="http://aluigi.altervista.org/adv/yagerbof-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/yagerbof-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352154820865&amp;w=2" source="BUGTRAQ">20050414 Multiple vulnerabilities in Yager 5.24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yager_development" name="yager_game">
        <vers num="5.0" />
        <vers num="5.20" />
        <vers num="5.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1164" published="2005-05-02" name="CVE-2005-1164" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data than indicated by the length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20104" source="XF">yager-freeze-datablock-dos(20104)</ref>
      <ref url="http://www.securityfocus.com/bid/13179" source="BID">13179</ref>
      <ref url="http://www.osvdb.org/15509" source="OSVDB">15509</ref>
      <ref url="http://secunia.com/advisories/14967" source="SECUNIA">14967</ref>
      <ref url="http://aluigi.altervista.org/adv/yagerbof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/yagerbof-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352154820865&amp;w=2" source="BUGTRAQ">20050414 Multiple vulnerabilities in Yager 5.24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yager_development" name="yager_game">
        <vers num="5.0" />
        <vers num="5.20" />
        <vers num="5.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1165" published="2005-05-02" name="CVE-2005-1165" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Yager 5.24 and earlier allows remote attackers to cause a denial of service (application crash) via certain malformed data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20105" source="XF">yager-corrupt-data-dos(20105)</ref>
      <ref url="http://aluigi.altervista.org/adv/yagerbof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/yagerbof-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352154820865&amp;w=2" source="BUGTRAQ">20050414 Multiple vulnerabilities in Yager 5.24</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1166" published="2005-05-02" name="CVE-2005-1166" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.shellsec.net/leer_advisory.php?id=7" source="MISC">http://www.shellsec.net/leer_advisory.php?id=7</ref>
      <ref url="http://securitytracker.com/id?1013725" source="SECTRACK">1013725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358825101305&amp;w=2" source="BUGTRAQ">20050415 Dameware NT Utilities and MiniRemote Control &lt;= 4.9 vulnerability</ref>
      <ref url="http://www.osvdb.org/15275" source="OSVDB">15275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dameware_development" name="dameware_nt_utilities">
        <vers prev="1" num="4.9" />
      </prod>
      <prod vendor="dameware_development" name="miniremote_control">
        <vers prev="1" num="4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1167" published="2005-05-02" name="CVE-2005-1167" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Musicmatch 10.00.2047 and earlier store log files in the Program Files directory instead of the user profile, which may allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.hyperdose.com/advisories/H2005-02.txt" source="MISC">http://www.hyperdose.com/advisories/H2005-02.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358261404682&amp;w=2" source="BUGTRAQ">20050415 Improper log file storage in Musicmatch software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicmatch" name="jukebox">
        <vers prev="1" num="10.00.2047" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1168" published="2005-05-02" name="CVE-2005-1168" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DiagCollectionControl.dll in Musicmatch 10.00.2047 and earlier allows remote attackers to overwrite arbitrary files via the bstrSavePath argument.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13167" source="BID" patch="1">13167</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359007928030&amp;w=2" source="BUGTRAQ">20050415 Arbitrary file overwrite possible by Musicmatch ActiveX control</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicmatch" name="jukebox">
        <vers prev="1" num="10.00.2047" />
        <vers num="9.0.5059" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1169" published="2005-05-02" name="CVE-2005-1169" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13194" source="BID">13194</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359511826958&amp;w=2" source="BUGTRAQ">20050415 Mafia Blog</ref>
      <ref url="http://chrisnowak.org/projects/mafia/" source="CONFIRM">http://chrisnowak.org/projects/mafia/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mafia" name="mafia_blog">
        <vers num="4_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1170" published="2005-05-02" name="CVE-2005-1170" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111367077709726&amp;w=2" source="BUGTRAQ">20050416 phpBB datenbank mod has XSS/SQL Injection in the id variable</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datenbank_module" name="datenbank_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1171" published="2005-05-02" name="CVE-2005-1171" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111367077709726&amp;w=2" source="BUGTRAQ">20050416 phpBB datenbank mod has XSS/SQL Injection in the id variable</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20146" source="XF">phpbb-modphp-xss(20146)</ref>
      <ref url="http://www.securityfocus.com/bid/13210" source="BID">13210</ref>
      <ref url="http://www.osvdb.org/15812" source="OSVDB">15812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datenbank_module" name="datenbank_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1172" published="2005-05-02" name="CVE-2005-1172" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13218" source="BID" patch="1">13218</ref>
      <ref url="http://secunia.com/advisories/15004" source="SECUNIA" patch="1">15004</ref>
      <ref url="http://coppermine.sourceforge.net/board/index.php?topic=17134" source="CONFIRM" patch="1">http://coppermine.sourceforge.net/board/index.php?topic=17134</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111383800707880&amp;w=2" source="BUGTRAQ">20050418 Vulnerability in Coppermine Photo Gallery 1.3.*</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0_rc3" />
        <vers num="1.1_.0" />
        <vers num="1.1_beta_2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2_b" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1173" published="2005-05-02" name="CVE-2005-1173" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111384806002021&amp;w=2" source="BUGTRAQ">20050418 ERNW Security Advisory 01/2005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmsoftware" name="simple_web_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1174" published="2005-07-18" name="CVE-2005-1174" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/259798" source="CERT-VN" patch="1" adv="1">VU#259798</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/2005-002-patch_1.4.1.txt" source="CONFIRM" patch="1">http://web.mit.edu/kerberos/advisories/2005-002-patch_1.4.1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112122123211974&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050712 MITKRB5-SA-2005-002: buffer overflow, heap corruption in KDC</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2074" source="VUPEN">ADV-2006-2074</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1066" source="VUPEN">ADV-2005-1066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10229" source="OVAL">oval:org.mitre.oval:def:10229</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21327" source="XF">kerberos-kdc-krb5-tcp-connection-dos(21327)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1" source="UBUNTU">USN-224-1</ref>
      <ref url="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt" source="TURBO">TLSA-2005-78</ref>
      <ref url="http://www.trustix.org/errata/2005/0036" source="TRUSTIX">2005-0036</ref>
      <ref url="http://www.securityfocus.com/bid/14240" source="BID">14240</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-567.html" source="REDHAT">RHSA-2005:567</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_sr.html" source="SUSE">SUSE-SR:2005:017</ref>
      <ref url="http://www.debian.org/security/2005/dsa-757" source="DEBIAN">DSA-757</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY85474" source="AIXAPAR">IY85474</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101809-1" source="SUNALERT">101809</ref>
      <ref url="http://securitytracker.com/id?1014460" source="SECTRACK">1014460</ref>
      <ref url="http://secunia.com/advisories/20364" source="SECUNIA">20364</ref>
      <ref url="http://secunia.com/advisories/17899" source="SECUNIA">17899</ref>
      <ref url="http://secunia.com/advisories/16041" source="SECUNIA">16041</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc" source="SGI">20050703-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:397" source="OVAL" sig="1">oval:org.mitre.oval:def:397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.3" />
        <vers num="5-1.3.1" />
        <vers num="5-1.3.2" />
        <vers num="5-1.3.3" />
        <vers num="5-1.3.4" />
        <vers num="5-1.3.5" />
        <vers num="5-1.3.6" />
        <vers num="5-1.4" />
        <vers num="5-1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1175" published="2005-07-18" name="CVE-2005-1175" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/885830" source="CERT-VN" patch="1" adv="1">VU#885830</ref>
      <ref url="http://www.debian.org/security/2005/dsa-757" source="DEBIAN" patch="1" adv="1">DSA-757</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-002-kdc.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-002-kdc.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2074" source="VUPEN">ADV-2006-2074</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1066" source="VUPEN">ADV-2005-1066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9902" source="OVAL">oval:org.mitre.oval:def:9902</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21328" source="XF">kerberos-kdc-krb5-udp-tcp-bo(21328)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1" source="UBUNTU">USN-224-1</ref>
      <ref url="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt" source="TURBO">TLSA-2005-78</ref>
      <ref url="http://www.trustix.org/errata/2005/0036" source="TRUSTIX">2005-0036</ref>
      <ref url="http://www.securityfocus.com/bid/14236" source="BID">14236</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-567.html" source="REDHAT">RHSA-2005:567</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-562.html" source="REDHAT">RHSA-2005:562</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_sr.html" source="SUSE">SUSE-SR:2005:017</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY85474" source="AIXAPAR">IY85474</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101809-1" source="SUNALERT">101809</ref>
      <ref url="http://securitytracker.com/id?1014460" source="SECTRACK">1014460</ref>
      <ref url="http://secunia.com/advisories/20364" source="SECUNIA">20364</ref>
      <ref url="http://secunia.com/advisories/17899" source="SECUNIA">17899</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA">17135</ref>
      <ref url="http://secunia.com/advisories/16041" source="SECUNIA">16041</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112122123211974&amp;w=2" source="BUGTRAQ">20050712 MITKRB5-SA-2005-002: buffer overflow, heap corruption in KDC</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc" source="SGI">20050703-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:736" source="OVAL" sig="1">oval:org.mitre.oval:def:736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.3" />
        <vers num="5-1.3.1" />
        <vers num="5-1.3.2" />
        <vers num="5-1.3.3" />
        <vers num="5-1.3.4" />
        <vers num="5-1.3.5" />
        <vers num="5-1.3.6" />
        <vers num="5-1.4" />
        <vers num="5-1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1176" published="2005-05-02" name="CVE-2005-1176" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20604" source="XF">aix-jfs2-race-condition(20604)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY70034&amp;apar=only" source="AIXAPAR">IY70034</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY70032&amp;apar=only" source="AIXAPAR">IY70032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2.0.50" />
        <vers num="5.2.0.54" />
        <vers num="5.3.0.10" />
        <vers num="5.3.0.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1177" published="2005-05-02" name="CVE-2005-1177" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20607" source="XF" patch="1">webmin-config-file-permissions(20607)</ref>
      <ref url="http://securitytracker.com/id?1013723" source="SECTRACK" patch="1">1013723</ref>
      <ref url="http://www.webmin.com/uchanges.html" source="CONFIRM">http://www.webmin.com/uchanges.html</ref>
      <ref url="http://www.webmin.com/changes.html" source="CONFIRM">http://www.webmin.com/changes.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usermin" name="usermin">
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.97" />
        <vers num="0.98" />
        <vers num="0.99" />
        <vers num="1.000" />
        <vers num="1.010" />
        <vers num="1.020" />
        <vers num="1.030" />
        <vers num="1.040" />
        <vers num="1.051" />
        <vers num="1.060" />
        <vers num="1.070" />
        <vers num="1.080" />
        <vers num="1.090" />
        <vers num="1.100" />
        <vers num="1.110" />
        <vers num="1.120" />
        <vers num="1.130" />
        <vers num="1.140" />
      </prod>
      <prod vendor="webmin" name="webmin">
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.97" />
        <vers num="0.98" />
        <vers num="0.99" />
        <vers num="1.0.00" />
        <vers num="1.0.10" />
        <vers num="1.0.20" />
        <vers num="1.0.30" />
        <vers num="1.0.40" />
        <vers num="1.0.51" />
        <vers num="1.0.60" />
        <vers num="1.0.70" />
        <vers num="1.0.80" />
        <vers num="1.0.90" />
        <vers num="1.1.00" />
        <vers num="1.1.10" />
        <vers num="1.1.20" />
        <vers num="1.1.30" />
        <vers num="1.1.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1178" published="2005-05-02" name="CVE-2005-1178" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Oracle Forms 10g allows remote attackers to execute arbitrary SQL commands via the Query/Where feature.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20080" source="XF">oracle-forms-query-where-popup-sql-injection(20080)</ref>
      <ref url="http://www.securiteam.com/securitynews/5HP0I0UFFI.html" source="MISC" adv="1">http://www.securiteam.com/securitynews/5HP0I0UFFI.html</ref>
      <ref url="http://www.red-database-security.com/wp/sql_injection_forms_us.pdf" source="MISC" adv="1">http://www.red-database-security.com/wp/sql_injection_forms_us.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="forms">
        <vers num="10g" />
        <vers num="3.0" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6i" />
        <vers num="9i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1179" published="2005-05-02" name="CVE-2005-1179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, related to SNMP authentication, allows remote attackers to modify system configuration, a different vulnerability than CVE-2005-0703.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20192" source="XF" patch="1">xerox-workcentre-snmp-auth-bypass(20192)</ref>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/13196" source="BID" patch="1">13196</ref>
      <ref url="http://secunia.com/advisories/14507" source="SECUNIA" patch="1" adv="1">14507</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre">
        <vers num="32_color_1.2.81" />
        <vers num="40_color_1.2.81" />
      </prod>
      <prod vendor="xerox" name="workcentre_165">
        <vers num="7.47.30.000" edition="" />
        <vers num="7.47.30.000" edition=":pro" />
        <vers num="7.47.33.008" edition="" />
        <vers num="7.47.33.008" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_175">
        <vers num="7.47.30.000" edition="" />
        <vers num="7.47.30.000" edition=":pro" />
        <vers num="7.47.33.008" edition="" />
        <vers num="7.47.33.008" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_2128">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_2636">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_32_color">
        <vers num="01.00.060" />
        <vers num="01.02.053.1" />
        <vers num="01.02.058.4" />
        <vers num="01.02.077.1" />
      </prod>
      <prod vendor="xerox" name="workcentre_35">
        <vers num="3.028.11.000" edition="" />
        <vers num="3.028.11.000" edition=":pro" />
        <vers num="3.97.20.032" edition="" />
        <vers num="3.97.20.032" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_3545">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_40_color">
        <vers num="01.00.060" />
        <vers num="01.02.053.1" />
        <vers num="01.02.058.4" />
        <vers num="01.02.077.1" />
        <vers num="01.02.65.1" />
      </prod>
      <prod vendor="xerox" name="workcentre_45">
        <vers num="3.028.11.000" edition="" />
        <vers num="3.028.11.000" edition=":pro" />
        <vers num="3.97.20.032" edition="" />
        <vers num="3.97.20.032" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_55">
        <vers num="3.028.11.000" edition="" />
        <vers num="3.028.11.000" edition=":pro" />
        <vers num="3.97.20.032" edition="" />
        <vers num="3.97.20.032" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_65">
        <vers num="1.001.00.060" edition="" />
        <vers num="1.001.00.060" edition=":pro" />
        <vers num="1.001.02.084" edition="" />
        <vers num="1.001.02.084" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_75">
        <vers num="1.001.00.060" edition="" />
        <vers num="1.001.00.060" edition=":pro" />
        <vers num="1.001.02.084" edition="" />
        <vers num="1.001.02.084" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_90">
        <vers num="1.001.00.060" edition="" />
        <vers num="1.001.00.060" edition=":pro" />
        <vers num="1.001.02.084" edition="" />
        <vers num="1.001.02.084" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_m165">
        <vers num="6.47.30.000" />
        <vers num="6.47.33.008" />
        <vers num="8.47.30.000" />
        <vers num="8.47.33.008" />
      </prod>
      <prod vendor="xerox" name="workcentre_m175">
        <vers num="6.47.30.000" />
        <vers num="6.47.33.008" />
        <vers num="8.47.30.000" />
        <vers num="8.47.33.008" />
      </prod>
      <prod vendor="xerox" name="workcentre_m35">
        <vers num="2.28.11.000" />
        <vers num="2.97.20.032" />
        <vers num="4.84.16.000" />
        <vers num="4.97.20.025" />
        <vers num="4.97.20.032" />
      </prod>
      <prod vendor="xerox" name="workcentre_m45">
        <vers num="2.28.11.000" />
        <vers num="2.97.20.032" />
        <vers num="4.84.16.000" />
        <vers num="4.97.20.025" />
        <vers num="4.97.20.032" />
      </prod>
      <prod vendor="xerox" name="workcentre_m55">
        <vers num="2.28.11.000" />
        <vers num="2.97.20.032" />
        <vers num="4.84.16.000" />
        <vers num="4.97.20.025" />
        <vers num="4.97.20.032" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1180" published="2005-05-02" name="CVE-2005-1180" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20116" source="XF">php-nuke-http-response-splitting(20116)</ref>
      <ref url="http://www.osvdb.org/15647" source="OSVDB">15647</ref>
      <ref url="http://www.digitalparadox.org/advisories/pnuke.txt" source="MISC" adv="1">http://www.digitalparadox.org/advisories/pnuke.txt</ref>
      <ref url="http://secunia.com/advisories/14965" source="SECUNIA">14965</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359804013536&amp;w=2" source="BUGTRAQ">20050415 Http Response Splitting Vulnerability In PHP-NUKE 7.6 and below</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="7.5" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1181" published="2005-05-02" name="CVE-2005-1181" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  PHP remote code injection vulnerability in loader.php for Ariadne CMS 2.4 allows remote attackers to execute arbitrary PHP code by modifying the ariadne parameter to reference a URL on a remote web server that contains the code.  NOTE: the vendor has disputed this issue, saying that loader.php first requires the "ariadne.inc" file, which defines the $ariadne variable, and thus it cannot be modified by an attacker. In addition, CVE personnel have partially verified the dispute via source code inspection of Ariadne 2.4 as available on July 5, 2005.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20611" source="XF">ariadne-loaderphp-file-include(20611)</ref>
      <ref url="http://www.osvdb.org/15549" source="OSVDB">15549</ref>
      <ref url="http://securitytracker.com/id?1013721" source="SECTRACK">1013721</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ariadne" name="ariadne_cms">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1182" published="2005-05-02" name="CVE-2005-1182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attackers to cause a denial of service (IRC shutdown) via certain inputs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20612" source="XF">ibm-irc-dos(20612)</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=nas29afd3991f5f290b086256fdb0053b293" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=nas29afd3991f5f290b086256fdb0053b293</ref>
      <ref url="http://secunia.com/advisories/14970" source="SECUNIA">14970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="os_400">
        <vers num="r510" />
        <vers num="r520" />
        <vers num="r530" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1183" published="2005-05-02" name="CVE-2005-1183" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mvnForum 1.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the Search parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20613" source="XF">mvnforum-search-xss(20613)</ref>
      <ref url="http://www.securityfocus.com/bid/13213" source="BID">13213</ref>
      <ref url="http://www.osvdb.org/15760" source="OSVDB">15760</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mvnforum" name="mvnforum">
        <vers num="1.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1184" published="2005-05-02" name="CVE-2005-1184" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of "keep alive" packets.  NOTE: some followups indicate that this issue could not be replicated.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13215" source="BID">13215</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Apr/0385.html" source="FULLDISC">20050418 Re: TCP/IP Stack Vulnerability</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Apr/0383.html" source="FULLDISC">20050418 Re: TCP/IP Stack Vulnerability</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Apr/0358.html" source="FULLDISC">20050416 TCP/IP Stack Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40502" source="XF">multiple-tcpip-dos(40502)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1185" published="2005-05-02" name="CVE-2005-1185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unquoted Windows search path vulnerability in Musicmatch Jukebox 10.00.2047 and earlier allows local users to gain privileges via a malicious C:\program.exe file, which is run by MMFWLaunch.exe when it attempts to execute launch.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.hyperdose.com/advisories/H2005-05.txt" source="MISC" patch="1">http://www.hyperdose.com/advisories/H2005-05.txt</ref>
      <ref url="http://securitytracker.com/id?1013718" source="SECTRACK" patch="1">1013718</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20129" source="XF">jukebox-mmfwlaunch-gain-privileges(20129)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352290711509&amp;w=2" source="BUGTRAQ">20050414 Trojan file issue in Musicmatch software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicmatch" name="jukebox">
        <vers prev="1" num="10.00.2047" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1186" published="2005-05-02" name="CVE-2005-1186" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hyperdose.com/advisories/H2005-04.txt" source="MISC" patch="1">http://www.hyperdose.com/advisories/H2005-04.txt</ref>
      <ref url="http://securitytracker.com/id?1013718" source="SECTRACK" patch="1">1013718</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Apr/0212.html" source="BUGTRAQ" patch="1">20050414 Trusted Site Cross Site Scripting Elevation of Privilege in Musicmatch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20129" source="XF">jukebox-mmfwlaunch-gain-privileges(20129)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicmatch" name="jukebox">
        <vers prev="1" num="10.00.2047" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1187" published="2005-05-02" name="CVE-2005-1187" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument.  NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20139" source="XF">winhex-filename-bo(20139)</ref>
      <ref url="http://www.unl0ck.org/files/papers/winhex.txt" source="MISC">http://www.unl0ck.org/files/papers/winhex.txt</ref>
      <ref url="http://securitytracker.com/id?1013727" source="SECTRACK">1013727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-ways_software_technology_ag" name="winhex">
        <vers num="12.05_sr-14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1188" published="2005-05-02" name="CVE-2005-1188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13125" source="BID" patch="1">13125</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20147" source="XF">comersus-comersussearchitem-xss(20147)</ref>
      <ref url="http://www.osvdb.org/15539" source="OSVDB">15539</ref>
      <ref url="http://securitytracker.com/id?1013747" source="SECTRACK">1013747</ref>
      <ref url="http://lostmon.blogspot.com/2005/04/comersus-asp-shopping-cart-variable.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/04/comersus-asp-shopping-cart-variable.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_cart">
        <vers num="3.90" />
        <vers num="4.00" />
        <vers num="4.051" />
        <vers num="4.14" />
        <vers num="4.20b" />
        <vers num="4.23" />
        <vers num="4.27" />
        <vers num="4.28" />
        <vers num="4.29" />
        <vers num="4.36" />
        <vers num="4.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1189" published="2005-05-02" name="CVE-2005-1189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vulnerability has reportedly been fixed in the beta version 2.16.478.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20166" source="XF">webcamxp-chat-xss(20166)</ref>
      <ref url="http://securitytracker.com/id?1013753" source="SECTRACK">1013753</ref>
      <ref url="http://secunia.com/advisories/14999" source="SECUNIA">14999</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcamxp" name="webcamxp_pro">
        <vers prev="1" num="2.16.467" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1190" published="2005-05-02" name="CVE-2005-1190" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebcamXP PRO v2.16.468 and earlier allows remote attackers to cause a denial of service via a long chat name, which takes up too much display space and prevents the chat frame from being properly rendered.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013753" source="SECTRACK" patch="1">1013753</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20615" source="XF">webcamxp-chatname-dos(20615)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcamxp" name="webcamxp_pro">
        <vers prev="1" num="2.16.468" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1191" published="2005-05-02" name="CVE-2005-1191" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13248" source="BID" patch="1" adv="1">13248</ref>
      <ref url="http://security.greymagic.com/security/advisories/gm015-ie" source="MISC" patch="1">http://security.greymagic.com/security/advisories/gm015-ie</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20380" source="XF">windows-web-view-command-execution(20380)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0509" source="VUPEN">ADV-2005-0509</ref>
      <ref url="http://www.securityfocus.com/archive/1/396224" source="BUGTRAQ">20050419 File Selection May Lead to Command Execution (GM#015-IE)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-024.mspx" source="MS">MS05-024</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3585" source="OVAL" sig="1">oval:org.mitre.oval:def:3585</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1192" published="2005-05-02" name="CVE-2005-1192" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01137" source="HP">SSRT5954</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01137" source="HP">HPSBUX01137</ref>
      <ref url="http://www.securityfocus.com/bid/13367" source="BID">13367</ref>
      <ref url="http://securityreason.com/securityalert/262" source="SREASON">262</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:935" source="OVAL" sig="1">oval:org.mitre.oval:def:935</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1607" source="OVAL" sig="1">oval:org.mitre.oval:def:1607</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1552" source="OVAL" sig="1">oval:org.mitre.oval:def:1552</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1533" source="OVAL" sig="1">oval:org.mitre.oval:def:1533</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1407" source="OVAL" sig="1">oval:org.mitre.oval:def:1407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.22" />
        <vers num="11.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1193" published="2005-05-16" name="CVE-2005-1193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/113196" source="CERT-VN">VU#113196</ref>
      <ref url="http://www.securityfocus.com/bid/13545" source="BID" patch="1">13545</ref>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=288194" source="CONFIRM" patch="1">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=288194</ref>
      <ref url="http://securitytracker.com/id?1013918" source="SECTRACK" patch="1">1013918</ref>
      <ref url="http://secunia.com/advisories/15298" source="SECUNIA" patch="1">15298</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20574" source="XF">phpbb-url-bbcode-file-include(20574)</ref>
      <ref url="http://www.osvdb.org/16439" source="OSVDB">16439</ref>
      <ref url="http://securitytracker.com/id?1014117" source="SECTRACK">1014117</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/May/0098.html" source="BUGTRAQ">20050507 phpbb 2.0.15 released - patches high critical vuln</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111552510000088&amp;w=2" source="FULLDISC">20050508 phpbb 2.0.15 released - patches high critical vuln</ref>
      <ref url="http://castlecops.com/t123194-.html" source="MISC">http://castlecops.com/t123194-.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1194" published="2005-05-04" name="CVE-2005-1194" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-381.html" source="REDHAT" patch="1" adv="1">RHSA-2005:381</ref>
      <ref url="http://www.securityfocus.com/bid/13506" source="BID">13506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11256" source="OVAL">oval:org.mitre.oval:def:11256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1195" published="2005-05-02" name="CVE-2005-1195" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in the code used to handle (1) MMS over TCP (MMST) streams or (2) RealMedia RTSP streams in xine-lib before 1.0, and other products that use xine-lib such as MPlayer 1.0pre6 and earlier, allow remote malicious servers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mplayerhq.hu/homepage/design7/news.html#vuln11" source="CONFIRM" patch="1">http://www.mplayerhq.hu/homepage/design7/news.html#vuln11</ref>
      <ref url="http://www.mplayerhq.hu/homepage/design7/news.html#vuln10" source="CONFIRM" patch="1">http://www.mplayerhq.hu/homepage/design7/news.html#vuln10</ref>
      <ref url="http://secunia.com/advisories/15014" source="SECUNIA" patch="1">15014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20175" source="XF">mplayer-mmst-stream-bo(20175)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20171" source="XF">mplayer-rtsp-stream-bo(20171)</ref>
      <ref url="http://www.securityfocus.com/bid/13271" source="BID">13271</ref>
      <ref url="http://www.securityfocus.com/archive/1/396703" source="BUGTRAQ">20050421 [PLSN-0003] - Remote exploits in MPlayer</ref>
      <ref url="http://www.osvdb.org/15712" source="OSVDB">15712</ref>
      <ref url="http://www.osvdb.org/15711" source="OSVDB">15711</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-19.xml" source="GENTOO">GLSA-200504-19</ref>
      <ref url="http://securitytracker.com/id?1013771" source="SECTRACK">1013771</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Apr/0337.html" source="BUGTRAQ">20050421 xine security announcement: multiple heap overflows in MMS and Real RTSP streaming clients</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/mms.c?r1=1.55&amp;r2=1.56&amp;diff_format=u" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/mms.c?r1=1.55&amp;r2=1.56&amp;diff_format=u</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/librtsp/rtsp.c?r1=1.18&amp;r2=1.19&amp;diff_format=u" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/librtsp/rtsp.c?r1=1.18&amp;r2=1.19&amp;diff_format=u</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers prev="1" num="1.0_pre6" />
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc2" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1196" published="2005-05-02" name="CVE-2005-1196" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111384185116335&amp;w=2" source="BUGTRAQ">20050418 phpBB - Knowledge Base MOD - SQL-Injection and Full Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1197" published="2005-05-02" name="CVE-2005-1197" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-117A.html" source="CERT">TA05-117A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/948486" source="CERT-VN">VU#948486</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111385690419118&amp;w=2" source="BUGTRAQ">20050418 [AppSecInc Team SHATTER Security Advisory] SQL Injection in CREATE_SCN_CHANGE_SET procedure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.2" />
        <vers num="10.1.0.3" />
        <vers num="10.1.0.3.1" />
        <vers num="10.1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1198" published="2005-05-02" name="CVE-2005-1198" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in apexec.pl for Anaconda Foundation Directory allows remote attackers to read arbitrary files via hex-encoded null characters (%00) in the middle of ".." sequences in the template parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111393495916656&amp;w=2" source="BUGTRAQ">20050419 Directoy Traversal Attack in apexec.pl (.%00./-Bug)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="anaconda_partners" name="foundation_directory">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1199" published="2005-05-02" name="CVE-2005-1199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands via the main parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15024" source="SECUNIA" patch="1">15024</ref>
      <ref url="http://www.securityfocus.com/bid/13253" source="BID">13253</ref>
      <ref url="http://www.osvdb.org/15698" source="OSVDB">15698</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111393619021575&amp;w=2" source="BUGTRAQ">20050419 UBB Thread printthread.php SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infopop" name="ultimate_bulletin_board">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1200" published="2005-05-02" name="CVE-2005-1200" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15013" source="SECUNIA" patch="1">15013</ref>
      <ref url="http://azbb.cyaccess.com/azbb.php?1091778548" source="CONFIRM" patch="1">http://azbb.cyaccess.com/azbb.php?1091778548</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20181" source="XF" adv="1">az-bulletin-board-file-include(20181)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00068-04192005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00068-04192005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401838521857&amp;w=2" source="BUGTRAQ">20050420 Multiple Security Issues Found In AZBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="azbb" name="az_bulletin_board">
        <vers num="1.0.07a" />
        <vers num="1.0.07b" />
        <vers num="1.0.07c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1201" published="2005-05-02" name="CVE-2005-1201" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15013" source="SECUNIA" patch="1">15013</ref>
      <ref url="http://azbb.cyaccess.com/azbb.php?1091778548" source="CONFIRM" patch="1">http://azbb.cyaccess.com/azbb.php?1091778548</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20183" source="XF">az-bulletin-board-file-existence(20183)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20180" source="XF">az-bulletin-board-file-modification(20180)</ref>
      <ref url="http://www.osvdb.org/15702" source="OSVDB">15702</ref>
      <ref url="http://www.osvdb.org/15701" source="OSVDB">15701</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00068-04192005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00068-04192005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401838521857&amp;w=2" source="BUGTRAQ">20050420 Multiple Security Issues Found In AZBB</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1202" published="2005-05-02" name="CVE-2005-1202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13212" source="BID" patch="1">13212</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=320768" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=320768</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-24.xml" source="GENTOO" patch="1">GLSA-200504-24</ref>
      <ref url="http://secunia.com/advisories/14982" source="SECUNIA">14982</ref>
      <ref url="http://www.osvdb.org/15751" source="OSVDB">15751</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00069-04202005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00069-04202005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401760125555&amp;w=2" source="BUGTRAQ">20050420 Multiple eGroupware Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="egroupware" name="egroupware">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.3" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1203" published="2005-05-02" name="CVE-2005-1203" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13212" source="BID" patch="1">13212</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=320768" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=320768</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-24.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-24</ref>
      <ref url="http://secunia.com/advisories/14982" source="SECUNIA" patch="1">14982</ref>
      <ref url="http://www.osvdb.org/15753" source="OSVDB">15753</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00069-04202005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00069-04202005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401760125555&amp;w=2" source="BUGTRAQ">20050420 Multiple eGroupware Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="egroupware" name="egroupware">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.3" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1204" published="2005-05-02" name="CVE-2005-1204" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a crafted packet to TCP port 61427, which causes an invalid memory access.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.evilpacket.net/advisories/EP-000-0003.html" source="MISC">http://www.evilpacket.net/advisories/EP-000-0003.html</ref>
      <ref url="http://secunia.com/advisories/15032" source="SECUNIA">15032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401676906915&amp;w=2" source="BUGTRAQ">20050420 Neslo Desktop Rover Remote DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nelso_software" name="desktop_rover">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1205" published="2005-06-14" name="CVE-2005-1205" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/800829" source="CERT-VN" patch="1" adv="1">VU#800829</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-033.mspx" source="MS" patch="1" adv="1">MS05-033</ref>
      <ref url="http://secunia.com/advisories/15690/" source="SECUNIA" patch="1" adv="1">15690</ref>
      <ref url="http://idefense.com/application/poi/display?id=260&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050614 Multiple Vendor Telnet Client Information Disclosure Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/13940" source="BID">13940</ref>
      <ref url="http://securitytracker.com/id?1014203" source="SECTRACK">1014203</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:784" source="OVAL" sig="1">oval:org.mitre.oval:def:784</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:605" source="OVAL" sig="1">oval:org.mitre.oval:def:605</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1132" source="OVAL" sig="1">oval:org.mitre.oval:def:1132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1206" published="2005-06-14" name="CVE-2005-1206" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-165A.html" source="CERT" patch="1" adv="1">TA05-165A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/489397" source="CERT-VN" patch="1" adv="1">VU#489397</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-027.mspx" source="MS" patch="1" adv="1">MS05-027</ref>
      <ref url="http://secunia.com/advisories/15694" source="SECUNIA" patch="1" adv="1">15694</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:467" source="OVAL" sig="1">oval:org.mitre.oval:def:467</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:259" source="OVAL" sig="1">oval:org.mitre.oval:def:259</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1142" source="OVAL" sig="1">oval:org.mitre.oval:def:1142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
        <vers num="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1207" published="2005-06-14" name="CVE-2005-1207" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-028.mspx" source="MS" patch="1" adv="1">MS05-028</ref>
      <ref url="http://secunia.com/advisories/15696/" source="SECUNIA" patch="1" adv="1">15696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:721" source="OVAL" sig="1">oval:org.mitre.oval:def:721</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1255" source="OVAL" sig="1">oval:org.mitre.oval:def:1255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1208" published="2005-06-14" name="CVE-2005-1208" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-165A.html" source="CERT" patch="1" adv="1">TA05-165A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/851869" source="CERT-VN" patch="1" adv="1">VU#851869</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-026.mspx" source="MS" patch="1" adv="1">MS05-026</ref>
      <ref url="http://secunia.com/advisories/15683" source="SECUNIA" patch="1" adv="1">15683</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0062.html" source="VULNWATCH" patch="1" adv="1">20050614 eEye Advisory - EEYEB-20050316 - HTML Help File Parsing Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/13953" source="BID">13953</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:463" source="OVAL" sig="1">oval:org.mitre.oval:def:463</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:381" source="OVAL" sig="1">oval:org.mitre.oval:def:381</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1057" source="OVAL" sig="1">oval:org.mitre.oval:def:1057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="datacenter_64-bit" edition="sp1_beta_1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1_beta_1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="r2" edition="sp1_beta_1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1211" published="2005-06-14" name="CVE-2005-1211" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-165A.html" source="CERT" patch="1" adv="1">TA05-165A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/189754" source="CERT-VN" patch="1" adv="1">VU#189754</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-025.mspx" source="MS" patch="1" adv="1">MS05-025</ref>
      <ref url="http://www.securityfocus.com/bid/13941" source="BID">13941</ref>
      <ref url="http://securitytracker.com/id?1014201" source="SECTRACK">1014201</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:782" source="OVAL" sig="1">oval:org.mitre.oval:def:782</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:770" source="OVAL" sig="1">oval:org.mitre.oval:def:770</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:258" source="OVAL" sig="1">oval:org.mitre.oval:def:258</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1239" source="OVAL" sig="1">oval:org.mitre.oval:def:1239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1115" source="OVAL" sig="1">oval:org.mitre.oval:def:1115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1212" published="2005-06-14" name="CVE-2005-1212" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-031.mspx" source="MS" patch="1" adv="1">MS05-031</ref>
      <ref url="http://secunia.com/advisories/15669/" source="SECUNIA" patch="1" adv="1">15669</ref>
      <ref url="http://idefense.com/application/poi/display?id=262&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" patch="1" adv="1">20050614 Microsoft Windows Interactive Training Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/13944" source="BID">13944</ref>
      <ref url="http://securitytracker.com/id?1014194" source="SECTRACK">1014194</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1224" source="OVAL" sig="1">oval:org.mitre.oval:def:1224</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="datacenter_64-bit" edition="sp1_beta_1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1_beta_1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="r2" edition="sp1_beta_1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" edition=":second_edition" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1213" published="2005-06-14" name="CVE-2005-1213" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/130614" source="CERT-VN">VU#130614</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-030.mspx" source="MS" patch="1" adv="1">MS05-030</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=263&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050614 Microsoft Outlook Express NNTP Response Parsing Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/13951" source="BID">13951</ref>
      <ref url="http://securitytracker.com/id?1014200" source="SECTRACK">1014200</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:989" source="OVAL" sig="1">oval:org.mitre.oval:def:989</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:167" source="OVAL" sig="1">oval:org.mitre.oval:def:167</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1088" source="OVAL" sig="1">oval:org.mitre.oval:def:1088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1214" published="2005-06-14" name="CVE-2005-1214" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-032.mspx" source="MS" patch="1" adv="1">MS05-032</ref>
      <ref url="http://secunia.com/advisories/15689" source="SECUNIA" patch="1" adv="1">15689</ref>
      <ref url="http://www.securityfocus.com/bid/13948" source="BID">13948</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:906" source="OVAL" sig="1">oval:org.mitre.oval:def:906</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:682" source="OVAL" sig="1">oval:org.mitre.oval:def:682</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1194" source="OVAL" sig="1">oval:org.mitre.oval:def:1194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="datacenter_64-bit" edition="sp1_beta_1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1_beta_1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="r2" edition="sp1_beta_1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" edition=":second_edition" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1215" published="2005-06-14" name="CVE-2005-1215" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-034.mspx" source="MS" patch="1" adv="1">MS05-034</ref>
      <ref url="http://secunia.com/advisories/15693/" source="SECUNIA" patch="1" adv="1">15693</ref>
      <ref url="http://www.securityfocus.com/bid/13956" source="BID">13956</ref>
      <ref url="http://securitytracker.com/id?1014193" source="SECTRACK">1014193</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1145" source="OVAL" sig="1">oval:org.mitre.oval:def:1145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1216" published="2005-06-14" name="CVE-2005-1216" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/367077" source="CERT-VN">VU#367077</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-034.mspx" source="MS" patch="1" adv="1">MS05-034</ref>
      <ref url="http://secunia.com/advisories/15693/" source="SECUNIA" patch="1" adv="1">15693</ref>
      <ref url="http://www.securityfocus.com/bid/13954" source="BID">13954</ref>
      <ref url="http://securitytracker.com/id?1014193" source="SECTRACK">1014193</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:468" source="OVAL" sig="1">oval:org.mitre.oval:def:468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1218" published="2005-08-10" name="CVE-2005-1218" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html" source="CERT" patch="1">TA05-221A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/490628" source="CERT-VN">VU#490628</ref>
      <ref url="http://www.securityfocus.com/bid/14259" source="BID" patch="1">14259</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-041.mspx" source="MS" patch="1">MS05-041</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/904797.mspx" source="CONFIRM" patch="1" adv="1">http://www.microsoft.com/technet/security/advisory/904797.mspx</ref>
      <ref url="https://www.immunitysec.com/pipermail/dailydave/2005-July/002188.html" source="MLIST">[Dailydave] 20050714 SPIKE actually scores.</ref>
      <ref url="http://security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=2783" source="MISC">http://security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=2783</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112146383919436&amp;w=2" source="BUGTRAQ">20050715 Any info on potential 0day RDP vuln?</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:618" source="OVAL" sig="1">oval:org.mitre.oval:def:618</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:609" source="OVAL" sig="1">oval:org.mitre.oval:def:609</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:376" source="OVAL" sig="1">oval:org.mitre.oval:def:376</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:346" source="OVAL" sig="1">oval:org.mitre.oval:def:346</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:180" source="OVAL" sig="1">oval:org.mitre.oval:def:180</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100092" source="OVAL" sig="1">oval:org.mitre.oval:def:100092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1219" published="2005-07-12" name="CVE-2005-1219" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-193A.html" source="CERT">TA05-193A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/720742" source="CERT-VN">VU#720742</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-036.mspx" source="MS" patch="1" adv="1">MS05-036</ref>
      <ref url="http://secunia.com/advisories/16004/" source="SECUNIA" patch="1" adv="1">16004</ref>
      <ref url="http://www.securityfocus.com/bid/14214" source="BID">14214</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:769" source="OVAL" sig="1">oval:org.mitre.oval:def:769</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:440" source="OVAL" sig="1">oval:org.mitre.oval:def:440</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:330" source="OVAL" sig="1">oval:org.mitre.oval:def:330</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1280" source="OVAL" sig="1">oval:org.mitre.oval:def:1280</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1125" source="OVAL" sig="1">oval:org.mitre.oval:def:1125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="image_color_management">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1220" published="2005-05-02" name="CVE-2005-1220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20177" source="XF">knusperleicht-settings-info-disclosure(20177)</ref>
      <ref url="http://www.osvdb.org/15695" source="OSVDB">15695</ref>
      <ref url="http://secunia.com/advisories/15015" source="SECUNIA">15015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402253108991&amp;w=2" source="BUGTRAQ">20050419 Shoutbox SCRIPT &lt;= 3.0.2 Administrative MD5 Username and Password Retrieval [x0n3-h4ck]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knusperleicht" name="shoutbox_script">
        <vers prev="1" num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1221" published="2005-05-02" name="CVE-2005-1221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp for Ecommerce-Carts EcommPro 3.0 allows remote attackers to execute arbitrary SQL commands via the password field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20200" source="XF">ecomm-pro-sql-injection(20200)</ref>
      <ref url="http://www.ihssecurity.com/download/advisory/ecomerce-cart.txt" source="MISC">http://www.ihssecurity.com/download/advisory/ecomerce-cart.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402179605925&amp;w=2" source="BUGTRAQ">20050419 Ecommerce-Carts SQL injection vulnerability ( IHSTeam )</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecommerce-carts" name="ecommpro">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1222" published="2005-05-02" name="CVE-2005-1222" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the code in the m_for_racine parameter, which is then written to cat_for_gen.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20198" source="XF">netref-catforgen-code-execution(20198)</ref>
      <ref url="http://www.osvdb.org/15717" source="OSVDB">15717</ref>
      <ref url="http://secunia.com/advisories/15040" source="SECUNIA" adv="1">15040</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111403947305600&amp;w=2" source="BUGTRAQ">20050419 Annuaire Netref v4.2 [ fwrite php ] vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netref" name="netref">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1223" published="2005-05-02" name="CVE-2005-1223" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Ocean12 Calendar manager 1.01 allow remote attackers to execute arbitrary SQL commands via the Admin_id field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20174" source="XF">ocean12-calendar-manager-sql-injection(20174)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Apr/1013762.html" source="SECTRACK">1013762</ref>
      <ref url="http://secunia.com/advisories/15026" source="SECUNIA">15026</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401502007772&amp;w=2" source="BUGTRAQ">20050420 [HSC Security Group] Ocean12 Calendar manager 1.01 SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocean12_technologies" name="calendar_manager_pro">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1224" published="2005-05-02" name="CVE-2005-1224" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result.asp, cat.asp, or detail.asp (3) the iCat parameter to cat.asp or detail.asp, (4) the iData parameter to detail.asp or result.asp, the (5) POL_ID, (6) POL_PARENT, (7) POL_CATEGORY, (8) CHA_NAME, or (9) CHA_ID parameters to inc_vote.asp, or the (10) tfm_order or (11) tfm_orderby parameters to toppages.asp, a different set of vulnerabilities than CVE-2005-1236.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20197" source="XF">duportal-multiple-sql-injection(20197)</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5TP0O0AFFQ.html" source="MISC">http://www.securiteam.com/windowsntfocus/5TP0O0AFFQ.html</ref>
      <ref url="http://secunia.com/advisories/15031" source="SECUNIA">15031</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/30671" source="XF">duportal-default-cat-sql-injection(30671)</ref>
      <ref url="http://www.securityfocus.com/bid/13285" source="BID">13285</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/453316/100/0/threaded" source="BUGTRAQ">20061202 [Aria-Security Team] DuWare DuPortal SQL Injection Vuln</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401172901705&amp;w=2" source="BUGTRAQ">20050420 DUportal Pro 3.4 has MANY Sql injection and Sql Errors.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duware" name="duportal">
        <vers num="3.4" />
        <vers num="pro_3.4" />
        <vers num="sql_3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1225" published="2005-05-02" name="CVE-2005-1225" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Coppermine Photo Gallery 1.3.2 allows remote attackers to execute arbitrary SQL commands via the favs parameter to (1) init.inc.php or (2) zipdownload.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15004" source="SECUNIA" patch="1">15004</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20205" source="XF">coppermine-initincphp-sql-injection(20205)</ref>
      <ref url="http://www.waraxe.us/advisory-42.html" source="MISC">http://www.waraxe.us/advisory-42.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402186304179&amp;w=2" source="BUGTRAQ">20050420 [waraxe-2005-SA#042] - Multiple vulnerabilities in Coppermine Photo Gallery 1.3.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1226" published="2005-05-02" name="CVE-2005-1226" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Coppermine Photo Gallery 1.3.2 stores passwords in plaintext, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20206" source="XF" patch="1">coppermine-password-plaintext(20206)</ref>
      <ref url="http://www.waraxe.us/advisory-42.html" source="MISC" patch="1">http://www.waraxe.us/advisory-42.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402186304179&amp;w=2" source="BUGTRAQ">20050420 [waraxe-2005-SA#042] - Multiple vulnerabilities in Coppermine Photo Gallery 1.3.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1227" published="2005-04-20" name="CVE-2005-1227" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHProjekt 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatroom text submission form.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20212" source="XF">phprojekt-url-tag-xss(20212)</ref>
      <ref url="http://www.osvdb.org/15720" source="OSVDB">15720</ref>
      <ref url="http://secunia.com/advisories/15039" source="SECUNIA">15039</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402374504496&amp;w=2" source="BUGTRAQ">20050420 Secure Science Corporation Application Software Advisory 055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprojekt" name="phprojekt">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1228" published="2005-05-02" name="CVE-2005-1228" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305255" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305255</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20199" source="XF">gzip-n-directory-traversal(20199)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://secunia.com/advisories/15047" source="SECUNIA" adv="1">15047</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11057" source="OVAL">oval:org.mitre.oval:def:11057</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.osvdb.org/15721" source="OSVDB">15721</ref>
      <ref url="http://www.debian.org/security/2005/dsa-752" source="DEBIAN">DSA-752</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1" source="SUNALERT">101816</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.555852" source="SLACKWARE">SSA:2006-262</ref>
      <ref url="http://secunia.com/advisories/22033" source="SECUNIA">22033</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://secunia.com/advisories/18100" source="SECUNIA">18100</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-357.html" source="REDHAT">RHSA-2005:357</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402732406477&amp;w=2" source="BUGTRAQ">20050420 gzip directory traversal vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt" source="SCO">SCOSA-2005.58</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:382" source="OVAL" sig="1">oval:org.mitre.oval:def:382</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:170" source="OVAL" sig="1">oval:org.mitre.oval:def:170</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gzip">
        <vers num="1.2.4" />
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1229" published="2005-05-02" name="CVE-2005-1229" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20204" source="XF">cpio-directory-traversal(20204)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-189-1" source="UBUNTU">USN-189-1</ref>
      <ref url="http://www.securityfocus.com/bid/13291" source="BID">13291</ref>
      <ref url="http://www.osvdb.org/17939" source="OSVDB">17939</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:233" source="MANDRIVA">MDKSA-2007:233</ref>
      <ref url="http://www.debian.org/security/2005/dsa-846" source="DEBIAN">DSA-846</ref>
      <ref url="http://secunia.com/advisories/27857" source="SECUNIA">27857</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/18395" source="SECUNIA">18395</ref>
      <ref url="http://secunia.com/advisories/18290" source="SECUNIA">18290</ref>
      <ref url="http://secunia.com/advisories/17123" source="SECUNIA">17123</ref>
      <ref url="http://secunia.com/advisories/16998" source="SECUNIA">16998</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111403177526312&amp;w=2" source="BUGTRAQ">20050420 cpio directory traversal vulnerability</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txt" source="SCO">SCOSA-2005.32</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txt" source="SCO">SCOSA-2006.2</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.asc" source="FREEBSD">FreeBSD-SA-06:03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="cpio">
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1230" published="2005-05-02" name="CVE-2005-1230" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Yawcam 0.2.5 allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in a GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15732" source="OSVDB">15732</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/Yawcam0.2.5-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/Yawcam0.2.5-adv.txt</ref>
      <ref url="http://secunia.com/advisories/15052" source="SECUNIA">15052</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111410564915961&amp;w=2" source="BUGTRAQ">20050421 directory traversal in Yawcam 0.2.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magnus_lundvall" name="yawcam">
        <vers num="0.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1231" published="2005-05-02" name="CVE-2005-1231" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrary web script or HTML via the (1) term or (2) description.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13254" source="BID" patch="1">13254</ref>
      <ref url="http://www.securiteam.com/unixfocus/5RP0M0AFFS.html" source="MISC" patch="1">http://www.securiteam.com/unixfocus/5RP0M0AFFS.html</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Apr/0416.html" source="FULLDISC" patch="1">20050418 XSS bug in JAWS gadget Glossary (0.4-latestbeta (beta 2))</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jaws" name="jaws">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1232" published="2005-05-02" name="CVE-2005-1232" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Sun Java System Web Proxy Server (aka Sun ONE Proxy Server) 3.6 SP6 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57763-1" source="SUNALERT">57763</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_proxy_server">
        <vers num="3.6" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1233" published="2005-04-20" name="CVE-2005-1233" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20169" source="XF" adv="1">profile-indexphp-xss(20169)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0370" source="VUPEN">ADV-2005-0370</ref>
      <ref url="http://www.snkenjoi.com/secadv/secadv7.txt" source="MISC" adv="1">http://www.snkenjoi.com/secadv/secadv7.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13282" source="BID" adv="1">13282</ref>
      <ref url="http://www.securityfocus.com/bid/13276" source="BID" adv="1">13276</ref>
      <ref url="http://www.osvdb.org/15697" source="OSVDB" adv="1">15697</ref>
      <ref url="http://securitytracker.com/id?1013756" source="SECTRACK" adv="1">1013756</ref>
      <ref url="http://secunia.com/advisories/15027" source="SECUNIA" adv="1">15027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_labs" name="profile">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1234" published="2005-05-02" name="CVE-2005-1234" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15029" source="SECUNIA" patch="1">15029</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20203" source="XF">phpbb-auction-sql-injection(20203)</ref>
      <ref url="http://www.snkenjoi.com/secadv/secadv9.txt" source="MISC">http://www.snkenjoi.com/secadv/secadv9.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13284" source="BID">13284</ref>
      <ref url="http://www.securityfocus.com/bid/13283" source="BID">13283</ref>
      <ref url="http://www.phpbb-auction.com/sutra5600.html" source="CONFIRM">http://www.phpbb-auction.com/sutra5600.html</ref>
      <ref url="http://www.osvdb.org/15705" source="OSVDB">15705</ref>
      <ref url="http://www.osvdb.org/15704" source="OSVDB">15704</ref>
      <ref url="http://securitytracker.com/id?1013779" source="SECTRACK">1013779</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/441190/100/0/threaded" source="BUGTRAQ">20060725 PHP-Auction SQL injection</ref>
      <ref url="http://www.aria-security.net/advisory/phpauction.txt" source="MISC">http://www.aria-security.net/advisory/phpauction.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb-auction">
        <vers num="1.0m" />
        <vers num="1.2m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1235" published="2005-05-02" name="CVE-2005-1235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed updated version on http://www.phpbb-auction.com/</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpbb-auction.com/sutra5600.html" source="CONFIRM" patch="1">http://www.phpbb-auction.com/sutra5600.html</ref>
      <ref url="http://www.snkenjoi.com/secadv/secadv9.txt" source="MISC">http://www.snkenjoi.com/secadv/secadv9.txt</ref>
      <ref url="http://www.osvdb.org/15706" source="OSVDB">15706</ref>
      <ref url="http://securitytracker.com/id?1013779" source="SECTRACK">1013779</ref>
      <ref url="http://secunia.com/advisories/15029" source="SECUNIA">15029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb-auction">
        <vers num="1.0m" />
        <vers num="1.2m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1236" published="2005-05-02" name="CVE-2005-1236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2) iData parameter to detail.asp or inc_rating.asp, (3) iCat parameter to detail.asp or type.asp, (4) DAT_PARENT parameter to inc_poll_voting.asp, or (5) iRate parameter to inc_rating.asp, a different set of vulnerabilities than CVE-2005-1224.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13288" source="BID">13288</ref>
      <ref url="http://www.digitalparadox.org/advisories/dup.txt" source="MISC">http://www.digitalparadox.org/advisories/dup.txt</ref>
      <ref url="http://secunia.com/advisories/15044" source="SECUNIA">15044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duware" name="duportal">
        <vers num="3.1.2" />
        <vers num="3.1.2_sql" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1237" published="2005-05-02" name="CVE-2005-1237" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20214" source="XF">flexphpnews-newsphp-sql-injection(20214)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0373" source="VUPEN">ADV-2005-0373</ref>
      <ref url="http://www.securityfocus.com/bid/13297" source="BID">13297</ref>
      <ref url="http://www.osvdb.org/15715" source="OSVDB">15715</ref>
      <ref url="http://secunia.com/advisories/14905" source="SECUNIA">14905</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33362" source="XF">flexphpnew-news-sql-injection(33362)</ref>
      <ref url="http://www.securityfocus.com/bid/23247" source="BID">23247</ref>
      <ref url="http://www.milw0rm.com/exploits/3631" source="MILW0RM">3631</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001506.html" source="VIM">20070411 Rediscovery: Flexphpnews news.php/newsid SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="china-on-site" name="flexphpnews">
        <vers prev="1" num="0.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1238" published="2005-05-02" name="CVE-2005-1238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf" source="MISC">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/396628" source="BUGTRAQ">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20260" source="XF">multiple-vendor-security-bypass(20260)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="iseries_as_400">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1239" published="2005-05-02" name="CVE-2005-1239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the third party tool from Raz-Lee, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fix is available on http://www.razlee.com/</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf" source="MISC">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/13310" source="BID">13310</ref>
      <ref url="http://www.securityfocus.com/archive/1/396628" source="BUGTRAQ">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20260" source="XF">multiple-vendor-security-bypass(20260)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raz-lee" name="security+++">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1240" published="2005-04-20" name="CVE-2005-1240" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the third party tool from Castlehill, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf" source="MISC">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/396628" source="BUGTRAQ">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20260" source="XF">multiple-vendor-security-bypass(20260)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="castlehill" name="secure_net">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1241" published="2005-04-20" name="CVE-2005-1241" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf" source="MISC">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/13312" source="BID">13312</ref>
      <ref url="http://www.securityfocus.com/archive/1/396628" source="BUGTRAQ">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20260" source="XF">multiple-vendor-security-bypass(20260)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powertech" name="powerlock_networksecurity">
        <vers num="4.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1242" published="2005-05-02" name="CVE-2005-1242" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the third party tool from Bsafe, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf" source="MISC">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/396628" source="BUGTRAQ">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20260" source="XF">multiple-vendor-security-bypass(20260)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsafe" name="global_security">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1243" published="2005-05-02" name="CVE-2005-1243" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the third party tool from SafeStone, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf" source="MISC">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/396628" source="BUGTRAQ">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20260" source="XF">multiple-vendor-security-bypass(20260)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="safestone_technologies" name="axcessit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1244" published="2005-04-20" name="CVE-2005-1244" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.  NOTE: the vendor has disputed this issue, saying that "neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20260" source="XF">multiple-vendor-security-bypass(20260)</ref>
      <ref url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf" source="MISC">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/396628" source="BUGTRAQ">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref>
      <ref url="http://www.osvdb.org/15791" source="OSVDB">15791</ref>
      <ref url="http://securitytracker.com/id?1013810" source="SECTRACK" adv="1">1013810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netiq" name="pssecure">
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1245" published="2005-05-02" name="CVE-2005-1245" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13301" source="BID" patch="1">13301</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=322146" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=322146</ref>
      <ref url="http://secunia.com/advisories/14993" source="SECUNIA" patch="1">14993</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20210" source="XF">mediawiki-unknown-xss(20210)</ref>
      <ref url="http://www.osvdb.org/15719" source="OSVDB">15719</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4_beta1" />
        <vers num="1.4_beta2" />
        <vers num="1.4_beta3" />
        <vers num="1.4_beta4" />
        <vers num="1.4_beta5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1246" published="2005-04-24" name="CVE-2005-1246" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2005-0x82-027-SNMPPD.txt" source="MISC" patch="1">http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2005-0x82-027-SNMPPD.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0022.html" source="VULNWATCH" patch="1">20050425 [INetCop Security Advisory] Snmppd potentially format string vulnerability.</ref>
      <ref url="http://secunia.com/advisories/15120" source="SECUNIA">15120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vladislav_bogdanov" name="snmppd">
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.3_special" />
        <vers num="0.4.4" />
        <vers num="0.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1247" published="2004-01-15" name="CVE-2005-1247" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0126.html" source="BUGTRAQ">20040115 OpenSSL ASN.1 parsing bugs PoC / brute forcer</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-31-advisory.pdf" source="MISC" adv="1">http://www.cirt.dk/advisories/cirt-31-advisory.pdf</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097379.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097379.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0021.html" source="VULNWATCH">20050424 [CIRT.DK - Advisory] Novell Nsure Audit 1.0.1 Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="nsure_audit">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1248" published="2005-05-16" name="CVE-2005-1248" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13565" source="BID" patch="1" adv="1">13565</ref>
      <ref url="http://securitytracker.com/id?1013927" source="SECTRACK" patch="1" adv="1">1013927</ref>
      <ref url="http://secunia.com/advisories/15310" source="SECUNIA" patch="1" adv="1">15310</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00003.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-05-09</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20498" source="XF" adv="1">apple-itunes-mpeg4-bo(20498)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0504" source="VUPEN">ADV-2005-0504</ref>
      <ref url="http://www.osvdb.org/16243" source="OSVDB" adv="1">16243</ref>
      <ref url="http://www.ngssoftware.com/advisories/itunes.txt" source="MISC">http://www.ngssoftware.com/advisories/itunes.txt</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=301596" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=301596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="4.2.72" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1249" published="2005-05-25" name="CVE-2005-1249" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html" source="CONFIRM" patch="1">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref>
      <ref url="http://www.securityfocus.com/bid/13727" source="BID">13727</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=245&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050524 Ipswitch IMail IMAP LSUB DoS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014047" source="SECTRACK">1014047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ipswitch_collaboration_suite">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1250" published="2005-06-22" name="CVE-2005-1250" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ipswitch.com/forums/shwmessage.aspx?ForumID=20&amp;MessageID=7699" source="CONFIRM" patch="1" adv="1">http://www.ipswitch.com/forums/shwmessage.aspx?ForumID=20&amp;MessageID=7699</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=268&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050622 IpSwitch WhatsUp Professional 2005 (SP1) SQL Injection Vulnerability</ref>
      <ref url="http://www.corsaire.com/advisories/c050323-001.txt" source="MISC">http://www.corsaire.com/advisories/c050323-001.txt</ref>
      <ref url="http://secunia.com/secunia_research/2005-13/advisory/" source="MISC">http://secunia.com/secunia_research/2005-13/advisory/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="whatsup">
        <vers num="professional_2005_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1252" published="2005-05-25" name="CVE-2005-1252" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string argument in a GET request to a non-existent .jsp file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html" source="CONFIRM" patch="1">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref>
      <ref url="http://www.securityfocus.com/bid/13727" source="BID">13727</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=242&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050524 Ipswitch IMail Web Calendaring Arbitrary File Read Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014047" source="SECTRACK">1014047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="8.13" />
      </prod>
      <prod vendor="ipswitch" name="imail_server">
        <vers prev="1" num="8.2_hotfix_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1254" published="2005-05-25" name="CVE-2005-1254" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html" source="CONFIRM" patch="1">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref>
      <ref url="http://www.securityfocus.com/bid/13727" source="BID">13727</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=241&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050524 Ipswitch IMail IMAP SELECT Command DoS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014047" source="SECTRACK">1014047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="8.12" />
        <vers num="8.13" />
        <vers prev="1" num="server_8.2_hotfix_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1255" published="2005-05-25" name="CVE-2005-1255" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html" source="CONFIRM" patch="1">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref>
      <ref url="http://www.securityfocus.com/bid/13727" source="BID">13727</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=243&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050524 Ipswitch IMail IMAP LOGIN Remote Buffer Overflow Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1014047" source="SECTRACK">1014047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="8.12" />
        <vers num="8.13" />
      </prod>
      <prod vendor="ipswitch" name="imail_server">
        <vers prev="1" num="8.2_hotfix_2" />
      </prod>
      <prod vendor="ipswitch" name="ipswitch_collaboration_suite">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1256" published="2005-05-25" name="CVE-2005-1256" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html" source="CONFIRM" patch="1">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref>
      <ref url="http://www.securityfocus.com/bid/13727" source="BID">13727</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=244&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050524 Ipswitch IMail IMAP STATUS Remote Buffer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014047" source="SECTRACK">1014047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="8.13" />
      </prod>
      <prod vendor="ipswitch" name="imail_server">
        <vers prev="1" num="8.2_hotfix_2" />
      </prod>
      <prod vendor="ipswitch" name="ipswitch_collaboration_suite">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1260" published="2005-05-19" name="CVE-2005-1260" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html" source="CERT">TA07-319A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3868" source="VUPEN">ADV-2007-3868</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3525" source="VUPEN">ADV-2007-3525</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10700" source="OVAL">oval:org.mitre.oval:def:10700</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-127-1" source="UBUNTU">USN-127-1</ref>
      <ref url="http://www.securityfocus.com/bid/26444" source="BID">26444</ref>
      <ref url="http://www.securityfocus.com/bid/13657" source="BID">13657</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-474.html" source="REDHAT">RHSA-2005:474</ref>
      <ref url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html" source="FEDORA">FLSA:158801</ref>
      <ref url="http://www.debian.org/security/2005/dsa-741" source="DEBIAN">DSA-741</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200191-1" source="SUNALERT">200191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103118-1" source="SUNALERT">103118</ref>
      <ref url="http://secunia.com/advisories/27643" source="SECUNIA">27643</ref>
      <ref url="http://secunia.com/advisories/27274" source="SECUNIA">27274</ref>
      <ref url="http://secunia.com/advisories/19183" source="SECUNIA">19183</ref>
      <ref url="http://secunia.com/advisories/15447" source="SECUNIA">15447</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html" source="APPLE">APPLE-SA-2007-11-14</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307041" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307041</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc" source="SGI">20060301-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:749" source="OVAL" sig="1">oval:org.mitre.oval:def:749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bzip" name="bzip2">
        <vers num="" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.10" />
        <vers num="5.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1261" published="2005-05-11" name="CVE-2005-1261" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=16" source="CONFIRM" patch="1" adv="1">http://gaim.sourceforge.net/security/index.php?id=16</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0519" source="VUPEN">ADV-2005-0519</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-432.html" source="REDHAT">RHSA-2005:432</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-429.html" source="REDHAT" adv="1">RHSA-2005:429</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10725" source="OVAL">oval:org.mitre.oval:def:10725</ref>
      <ref url="http://www.securityfocus.com/bid/13590" source="BID">13590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.76" />
        <vers num="0.77" />
        <vers num="0.78" />
        <vers num="0.79" />
        <vers num="0.80" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.82.1" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1262" published="2005-05-11" name="CVE-2005-1262" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gaim 1.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed MSN message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=17" source="CONFIRM" patch="1" adv="1">http://gaim.sourceforge.net/security/index.php?id=17</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0519" source="VUPEN">ADV-2005-0519</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-429.html" source="REDHAT" adv="1">RHSA-2005:429</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10861" source="OVAL">oval:org.mitre.oval:def:10861</ref>
      <ref url="http://www.securityfocus.com/bid/13591" source="BID">13591</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.76" />
        <vers num="0.77" />
        <vers num="0.78" />
        <vers num="0.79" />
        <vers num="0.80" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.82.1" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1263" published="2005-05-11" name="CVE-2005-1263" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0524" source="VUPEN">ADV-2005-0524</ref>
      <ref url="http://www.securityfocus.com/bid/13589" source="BID">13589</ref>
      <ref url="http://www.securityfocus.com/archive/1/397966" source="BUGTRAQ">20050511 Linux kernel ELF core dump privilege elevation</ref>
      <ref url="http://www.isec.pl/vulnerabilities/isec-0023-coredump.txt" source="MISC">http://www.isec.pl/vulnerabilities/isec-0023-coredump.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10909" source="OVAL">oval:org.mitre.oval:def:10909</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded" source="FEDORA">FLSA:157459-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded" source="FEDORA">FLSA:157459-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-551.html" source="REDHAT">RHSA-2005:551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-529.html" source="REDHAT">RHSA-2005:529</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-472.html" source="REDHAT">RHSA-2005:472</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="http://secunia.com/advisories/19185" source="SECUNIA">19185</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1122" source="OVAL" sig="1">oval:org.mitre.oval:def:1122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" />
        <vers num="2.2.16" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.27" edition="rc2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.30" />
        <vers num="2.4.31" edition="pre1" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1264" published="2005-05-17" name="CVE-2005-1264" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=111630512512222" source="MLIST" patch="1" adv="1">[linux-kernel] 20050517 [PATCH] Fix root hole in raw device</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0045.html" source="VULNWATCH" patch="1" adv="1">20050516 Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0557" source="VUPEN">ADV-2005-0557</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10264" source="OVAL">oval:org.mitre.oval:def:10264</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0046.html" source="VULNWATCH">20050517 Re: Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/13651" source="BID">13651</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-420.html" source="REDHAT">RHSA-2005:420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1265" published="2005-06-16" name="CVE-2005-1265" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The mmap function in the Linux Kernel 2.6.10 can be used to create memory maps with a start address beyond the end address, which allows local users to cause a denial of service (kernel crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-137-1" source="UBUNTU">USN-137-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10466" source="OVAL">oval:org.mitre.oval:def:10466</ref>
      <ref url="http://www.securityfocus.com/bid/13893" source="BID">13893</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://securitytracker.com/id?1014152" source="SECTRACK">1014152</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1266" published="2005-06-15" name="CVE-2005-1266" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/cc4ce06b-e01c-11d9-a8bd-000cf18bbe54.html" source="CONFIRM" patch="1">http://www.vuxml.org/freebsd/cc4ce06b-e01c-11d9-a8bd-000cf18bbe54.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-17.xml" source="GENTOO" patch="1">GLSA-200506-17</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=94722" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=94722</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:106" source="MANDRAKE">MDKSA-2005:106</ref>
      <ref url="http://www.debian.org/security/2005/dsa-736" source="DEBIAN">DSA-736</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10901" source="OVAL">oval:org.mitre.oval:def:10901</ref>
      <ref url="http://mail-archives.apache.org/mod_mbox/spamassassin-announce/200506.mbox/%3c17072.35054.586017.822288@proton.pathname.com%3e" source="MLIST">[spamassassin-announce] 20050615 Denial of Service Vulnerability in Apache SpamAssassin 3.0.1-3.0.3</ref>
      <ref url="http://www.securityfocus.com/bid/13978" source="BID">13978</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-498.html" source="REDHAT">RHSA-2005:498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="spamassassin">
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1267" published="2005-06-10" name="CVE-2005-1267" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159208" source="MISC" patch="1" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159208</ref>
      <ref url="http://www.trustix.org/errata/2005/0028/" source="TRUSTIX" patch="1" adv="1">2005-0028</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-June/msg00007.html" source="FEDORA" patch="1" adv="1">FEDORA-2005-406</ref>
      <ref url="http://secunia.com/advisories/15634/" source="SECUNIA" patch="1" adv="1">15634</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11148" source="OVAL">oval:org.mitre.oval:def:11148</ref>
      <ref url="http://www.securityfocus.com/bid/13906" source="BID">13906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded" source="FEDORA">FLSA:156139</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-505.html" source="REDHAT">RHSA-2005:505</ref>
      <ref url="http://www.debian.org/security/2005/dsa-854" source="DEBIAN">DSA-854</ref>
      <ref url="http://secunia.com/advisories/17118" source="SECUNIA">17118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.4" />
        <vers num="3.4a6" />
        <vers num="3.5" />
        <vers num="3.5.2" />
        <vers num="3.5_alpha" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.7" />
        <vers num="3.7.1" />
        <vers num="3.7.2" />
        <vers num="3.8.1" />
        <vers num="3.8.2" />
        <vers num="3.8.3" />
        <vers num="3.9" />
        <vers num="3.9.1" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="10.2" edition="" />
        <vers num="10.2" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0" />
        <vers num="core_4.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1268" published="2005-08-05" name="CVE-2005-1268" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:129" source="MANDRAKE" patch="1" adv="1">MDKSA-2005:129</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-582.html" source="REDHAT" patch="1">RHSA-2005:582</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163013" source="MISC" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163013</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0789" source="VUPEN">ADV-2006-0789</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded" source="HP">SSRT051251</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded" source="HP">SSRT051251</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9589" source="OVAL">oval:org.mitre.oval:def:9589</ref>
      <ref url="http://www.securityfocus.com/bid/14366" source="BID">14366</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_46_apache.html" source="SUSE">SUSE-SA:2005:046</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-805" source="DEBIAN">DSA-805</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1" source="SUNALERT">102198</ref>
      <ref url="http://securityreason.com/securityalert/604" source="SREASON">604</ref>
      <ref url="http://secunia.com/advisories/19185" source="SECUNIA">19185</ref>
      <ref url="http://secunia.com/advisories/19072" source="SECUNIA">19072</ref>
      <ref url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html" source="TRUSTIX">TSLSA-2005-0059</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1747" source="OVAL" sig="1">oval:org.mitre.oval:def:1747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1714" source="OVAL" sig="1">oval:org.mitre.oval:def:1714</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1346" source="OVAL" sig="1">oval:org.mitre.oval:def:1346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1269" published="2005-06-16" name="CVE-2005-1269" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-139-1" source="UBUNTU">USN-139-1</ref>
      <ref url="http://www.securityfocus.com/bid/13931" source="BID">13931</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-11.xml" source="GENTOO">GLSA-200506-11</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9544" source="OVAL">oval:org.mitre.oval:def:9544</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=18" source="CONFIRM">http://gaim.sourceforge.net/security/?id=18</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-518.html" source="REDHAT">RHSA-2005:518</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:099" source="MANDRAKE">MDKSA-2005:099</ref>
      <ref url="http://www.debian.org/security/2005/dsa-734" source="DEBIAN">DSA-734</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:744" source="OVAL" sig="1">oval:org.mitre.oval:def:744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.76" />
        <vers num="0.77" />
        <vers num="0.78" />
        <vers num="0.79" />
        <vers num="0.80" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.82.1" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1270" published="2005-04-26" name="CVE-2005-1270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13399" source="BID" patch="1">13399</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-25.xml" source="GENTOO" patch="1">GLSA-200504-25</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20279" source="XF">rootkit-hunter-checkupdate-symlink(20279)</ref>
      <ref url="http://www.osvdb.org/15861" source="OSVDB">15861</ref>
      <ref url="http://secunia.com/advisories/15127" source="SECUNIA">15127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="rootkit_hunter">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1271" reject="1" published="2005-05-12" name="CVE-2005-1271" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1343.  Reason: This candidate is a reservation duplicate of CVE-2005-1343.  Notes: All CVE users should reference CVE-2005-1343 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-1272" published="2005-08-05" name="CVE-2005-1272" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/279774" source="CERT-VN" patch="1" adv="1">VU#279774</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21656" source="XF" patch="1">brightstor-enterprise-backup-bo(21656)</ref>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33239" source="CONFIRM" patch="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33239</ref>
      <ref url="http://www.securityfocus.com/bid/14453" source="BID" patch="1">14453</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=287&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20050803 CA BrightStor ARCserve Backup Agent for MS SQL Server Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.0" edition="" />
        <vers num="11.0" edition=":windows" />
        <vers num="11.0" edition=":oracle" />
        <vers num="11.1" edition="" />
        <vers num="11.1" edition=":windows" />
        <vers num="11.1" edition=":oracle" />
        <vers num="9.0.1" edition="" />
        <vers num="9.0.1" edition=":windows" />
        <vers num="9.0_1" edition="" />
        <vers num="9.0_1" edition=":oracle" />
      </prod>
      <prod vendor="ca" name="brightstor_arcserve_backup_agent">
        <vers num="11" edition="" />
        <vers num="11" edition=":exchange" />
        <vers num="11.0" edition="" />
        <vers num="11.0" edition=":sql" />
        <vers num="11.0" edition=":sap" />
        <vers num="11.1" edition="" />
        <vers num="11.1" edition=":sql" />
        <vers num="11.1" edition=":exchange" />
        <vers num="11.1" edition=":sap" />
        <vers num="9.0.1" edition="" />
        <vers num="9.0.1" edition=":exchange" />
        <vers num="9.0.1" edition=":sap" />
        <vers num="9.0.1" edition=":sql" />
      </prod>
      <prod vendor="ca" name="brightstor_enterprise_backup">
        <vers num="10.0" />
        <vers num="10.5" />
      </prod>
      <prod vendor="ca" name="brightstor_enterprise_backup_agent">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sap" />
        <vers num="10.0" edition=":sql" />
        <vers num="10.0" edition=":oracle" />
        <vers num="10.5" edition="" />
        <vers num="10.5" edition=":oracle" />
        <vers num="10.5" edition=":sql" />
        <vers num="10.5" edition=":sap" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1274" published="2005-04-26" name="CVE-2005-1274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=236&amp;type=vulnerabilities" source="IDEFENSE">20050426 MySQL MaxDB Webtool Remote 'If' Stack Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers prev="1" num="7.5.00.23" />
        <vers num="7.5.00.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1275" published="2005-04-25" name="CVE-2005-1275" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.imagemagick.org/script/changelog.php" source="CONFIRM" patch="1">http://www.imagemagick.org/script/changelog.php</ref>
      <ref url="http://www.securityfocus.com/bid/13351" source="BID">13351</ref>
      <ref url="http://www.overflow.pl/adv/imheapoverflow.txt" source="MISC">http://www.overflow.pl/adv/imheapoverflow.txt</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Apr/0407.html" source="BUGTRAQ">20050424 [Overflow.pl] ImageMagick ReadPNMImage() Heap Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10003" source="OVAL">oval:org.mitre.oval:def:10003</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=90423" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=90423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-413.html" source="REDHAT">RHSA-2005:413</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:107" source="MANDRAKE">MDKSA-2005:107</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:711" source="OVAL" sig="1">oval:org.mitre.oval:def:711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="graphicsmagick" name="graphicsmagick">
        <vers num="1.0" />
        <vers num="1.0.6" />
        <vers num="1.1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
      </prod>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.2.5" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.1" />
        <vers num="6.1.1.6" />
        <vers num="6.1.2" />
        <vers num="6.1.3" />
        <vers num="6.1.4" />
        <vers num="6.1.5" />
        <vers num="6.1.6" />
        <vers num="6.1.7" />
        <vers num="6.1.8" />
        <vers num="6.2" />
        <vers num="6.2.0.4" />
        <vers num="6.2.0.7" />
        <vers num="6.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1277" reject="1" published="2005-06-28" name="CVE-2005-1277" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1766.  Reason: This candidate is a duplicate of CVE-2005-1766.  Notes: This duplicate occurred due to insufficient coordination across three separate parties.  All CVE users should reference CVE-2005-1766 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1278" published="2005-05-02" name="CVE-2005-1278" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/396932" source="BUGTRAQ">20050426 tcpdump[v3.8.x/v3.9.1]: ISIS, BGP, and LDP infinite loop DOS exploits.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-421.html" source="REDHAT">RHSA-2005:421</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-417.html" source="REDHAT">RHSA-2005:417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10159" source="OVAL">oval:org.mitre.oval:def:10159</ref>
      <ref url="http://www.securityfocus.com/bid/13392" source="BID">13392</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded" source="FEDORA">FLSA:156139</ref>
      <ref url="http://secunia.com/advisories/18146" source="SECUNIA">18146</ref>
      <ref url="http://secunia.com/advisories/15125" source="SECUNIA">15125</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.60/SCOSA-2005.60.txt" source="SCO">SCOSA-2005.60</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1279" published="2005-05-02" name="CVE-2005-1279" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/396932" source="BUGTRAQ" adv="1">20050426 tcpdump[v3.8.x/v3.9.1]: ISIS, BGP, and LDP infinite loop DOS exploits.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-421.html" source="REDHAT">RHSA-2005:421</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-417.html" source="REDHAT">RHSA-2005:417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9601" source="OVAL">oval:org.mitre.oval:def:9601</ref>
      <ref url="http://www.securityfocus.com/bid/13389" source="BID">13389</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded" source="FEDORA">FLSA:156139</ref>
      <ref url="http://www.debian.org/security/2005/dsa-850" source="DEBIAN">DSA-850</ref>
      <ref url="http://secunia.com/advisories/18146" source="SECUNIA">18146</ref>
      <ref url="http://secunia.com/advisories/17101" source="SECUNIA">17101</ref>
      <ref url="http://secunia.com/advisories/15125" source="SECUNIA">15125</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.60/SCOSA-2005.60.txt" source="SCO">SCOSA-2005.60</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1280" published="2005-05-02" name="CVE-2005-1280" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/396930" source="BUGTRAQ">20050426 tcpdump(/ethereal)[]: (RSVP) rsvp_print() infinite loop DOS.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-421.html" source="REDHAT">RHSA-2005:421</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-417.html" source="REDHAT">RHSA-2005:417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10732" source="OVAL">oval:org.mitre.oval:def:10732</ref>
      <ref url="http://www.securityfocus.com/bid/13390" source="BID">13390</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded" source="FEDORA">FLSA:156139</ref>
      <ref url="http://secunia.com/advisories/18146" source="SECUNIA">18146</ref>
      <ref url="http://secunia.com/advisories/15125" source="SECUNIA">15125</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.60/SCOSA-2005.60.txt" source="SCO">SCOSA-2005.60</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1281" published="2005-04-26" name="CVE-2005-1281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13391" source="BID">13391</ref>
      <ref url="http://www.securityfocus.com/archive/1/396930" source="BUGTRAQ">20050426 tcpdump(/ethereal)[]: (RSVP) rsvp_print() infinite loop DOS.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1282" published="2005-05-02" name="CVE-2005-1282" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the src parameter in an IMG tag, (2) User settings, or (3) Address book input boxes in the webmail interface.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20225" source="XF">argosoft-mail-server-html-tag-filter-xss(20225)</ref>
      <ref url="http://www.securityfocus.com/bid/13326" source="BID">13326</ref>
      <ref url="http://secunia.com/advisories/15100" source="SECUNIA">15100</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111419001527077&amp;w=2" source="BUGTRAQ">20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8.7.6" edition="" />
        <vers num="1.8.7.6" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1283" published="2005-04-22" name="CVE-2005-1283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote authenticated users to (1) read arbitrary files via the UIDL parameter to the msg script or (2) copy or move the user's .eml file to arbitrary locations via the delete script, a different vulnerability than CVE-2005-0367.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20229" source="XF">argosoft-mail-server-dir-traversal(20229)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20226" source="XF">argosoft-mail-server-eml-files-dir-traversal(20226)</ref>
      <ref url="http://www.osvdb.org/15823" source="OSVDB">15823</ref>
      <ref url="http://www.osvdb.org/15821" source="OSVDB">15821</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111419001527077&amp;w=2" source="BUGTRAQ">20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8.7.6" edition="" />
        <vers num="1.8.7.6" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1284" published="2005-05-02" name="CVE-2005-1284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if "Allow Creation of Accounts From the Web Interface" is disabled, via a direct HTTP POST request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20228" source="XF">argosoft-mail-server-add-new-mail-account(20228)</ref>
      <ref url="http://www.securityfocus.com/bid/13323" source="BID">13323</ref>
      <ref url="http://www.osvdb.org/15822" source="OSVDB">15822</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111419001527077&amp;w=2" source="BUGTRAQ">20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8.7.6" edition="" />
        <vers num="1.8.7.6" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1285" published="2005-04-22" name="CVE-2005-1285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013790" source="SECTRACK">1013790</ref>
      <ref url="http://secunia.com/advisories/15058" source="SECUNIA">15058</ref>
      <ref url="http://www.securityfocus.com/bid/13325" source="BID">13325</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111420516900814&amp;w=2" source="BUGTRAQ">20050422 [SePro Bugtraq] WBB - WoltLab Burning Board &lt;= 2.3.1 - XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers prev="1" num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1286" published="2005-05-02" name="CVE-2005-1286" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the full pathname when executing a process.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15818" source="OSVDB">15818</ref>
      <ref url="http://secunia.com/advisories/15076" source="SECUNIA">15076</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111420400316397&amp;w=2" source="BUGTRAQ">20050422 BitDefender 8 - Race condition vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softwin" name="bitdefender_antivirus">
        <vers num="professional_plus_8" />
        <vers num="standard_8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1287" published="2005-04-23" name="CVE-2005-1287" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.digitalparadox.org/advisories/bkdev.txt" source="MISC">http://www.digitalparadox.org/advisories/bkdev.txt</ref>
      <ref url="http://securitytracker.com/id?1013793" source="SECTRACK">1013793</ref>
      <ref url="http://secunia.com/advisories/15072" source="SECUNIA">15072</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431863/100/0/threaded" source="BUGTRAQ">20060423 BK Forum &lt;= 4.0 Remote SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431659/100/0/threaded" source="BUGTRAQ">20060421 BK Forum &lt;&lt;--V.4.0 SQL Injection</ref>
      <ref url="http://www.osvdb.org/15786" source="OSVDB">15786</ref>
      <ref url="http://www.osvdb.org/15785" source="OSVDB">15785</ref>
      <ref url="http://www.osvdb.org/15784" source="OSVDB">15784</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428133317901&amp;w=2" source="BUGTRAQ">20050423 Multiple Sql injection vulnerabilities in BK Forum v.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bk_dev" name="bk_forum">
        <vers prev="1" num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1288" published="2005-05-02" name="CVE-2005-1288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">inc_login_check.asp ACS Blog 0.8 through 1.1.3 allows remote attackers to gain administrator privileges via the "in" value in a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013795" source="SECTRACK">1013795</ref>
      <ref url="http://secunia.com/advisories/15105" source="SECUNIA">15105</ref>
      <ref url="http://www.osvdb.org/15787" source="OSVDB">15787</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428190921388&amp;w=2" source="BUGTRAQ">20050423 ACSblog bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp_press" name="acs_blog">
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1289" published="2005-05-02" name="CVE-2005-1289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013780" source="SECTRACK">1013780</ref>
      <ref url="http://secunia.com/advisories/15054" source="SECUNIA">15054</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428818425864&amp;w=2" source="BUGTRAQ">20050423 E-Cart v1.1 Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-cart" name="e-cart">
        <vers num="2004_1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1290" published="2005-05-02" name="CVE-2005-1290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc parameters to admin_forums.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://neosecurityteam.net/Advisories/Advisory-14.txt" source="MISC">http://neosecurityteam.net/Advisories/Advisory-14.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428283721756&amp;w=2" source="BUGTRAQ">20050423 -==phpBB 2.0.14 Multiple Vulnerabilities==-</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1291" published="2005-04-23" name="CVE-2005-1291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in CartWIZ ASP Cart allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) addToCart.asp or (2) productDetails.asp, the (3) priceFrom, (4) idCategory, or (5) priceTo parameter to searchResults.asp, or (6) the idParentCategory parameter to productCatalogSubCats.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20246" source="XF">cartwiz-multiple-sql-injection(20246)</ref>
      <ref url="http://securitytracker.com/id?1013792" source="SECTRACK">1013792</ref>
      <ref url="http://secunia.com/advisories/15055" source="SECUNIA">15055</ref>
      <ref url="http://www.osvdb.org/15774" source="OSVDB">15774</ref>
      <ref url="http://www.osvdb.org/15773" source="OSVDB">15773</ref>
      <ref url="http://www.osvdb.org/15772" source="OSVDB">15772</ref>
      <ref url="http://www.osvdb.org/15771" source="OSVDB">15771</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428393022389&amp;w=2" source="BUGTRAQ">20050423 Multiple Sql injection and XSS in CartWIZ ASP Cart</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cartwiz" name="asp_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1292" published="2005-05-02" name="CVE-2005-1292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20249" source="XF">cartwiz-multiple-script-xss(20249)</ref>
      <ref url="http://www.osvdb.org/15780" source="OSVDB">15780</ref>
      <ref url="http://www.osvdb.org/15778" source="OSVDB">15778</ref>
      <ref url="http://www.osvdb.org/15777" source="OSVDB">15777</ref>
      <ref url="http://www.osvdb.org/15776" source="OSVDB">15776</ref>
      <ref url="http://www.osvdb.org/15775" source="OSVDB">15775</ref>
      <ref url="http://securitytracker.com/id?1013792" source="SECTRACK">1013792</ref>
      <ref url="http://secunia.com/advisories/15055" source="SECUNIA">15055</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428393022389&amp;w=2" source="BUGTRAQ">20050423 Multiple Sql injection and XSS in CartWIZ ASP Cart</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elemental_software" name="cartwiz">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1293" published="2005-05-02" name="CVE-2005-1293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15071" source="SECUNIA">15071</ref>
      <ref url="http://digitalparadox.org/advisories/storeportal.txt" source="MISC">http://digitalparadox.org/advisories/storeportal.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445131808328&amp;w=2" source="BUGTRAQ">20050424 Multiple SQL Injections in StorePortal 2.63</ref>
    </refs>
    <vuln_soft>
      <prod vendor="storeportal" name="storeportal">
        <vers num="2.63" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1294" published="2005-04-24" name="CVE-2005-1294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://affix.sourceforge.net/patch_hci_3_2_0" source="CONFIRM" patch="1">http://affix.sourceforge.net/patch_hci_3_2_0</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0423a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2005-0423a%5D.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445064725591&amp;w=2" source="BUGTRAQ">20050424 DMA[2005-0423a] - 'Nokia Affix Bluetooth Integer Underflow'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="affix">
        <vers prev="1" num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1295" published="2005-04-25" name="CVE-2005-1295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445189816161&amp;w=2" source="BUGTRAQ">20050425 remote command execution in include.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="include.cgi" name="include.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1296" published="2005-04-25" name="CVE-2005-1296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445189816161&amp;w=2" source="BUGTRAQ">20050425 remote command execution in include.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="include.cgi" name="include.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1297" published="2005-04-25" name="CVE-2005-1297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445189816161&amp;w=2" source="BUGTRAQ">20050425 remote command execution in include.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="include.cgi" name="include.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1298" published="2005-04-25" name="CVE-2005-1298" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444807013846&amp;w=2" source="BUGTRAQ">20050425 remote command execution in inserter.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inserter.cgi" name="inserter.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1299" published="2005-04-25" name="CVE-2005-1299" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444807013846&amp;w=2" source="BUGTRAQ">20050425 remote command execution in inserter.cgi script</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1300" published="2005-04-25" name="CVE-2005-1300" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444807013846&amp;w=2" source="BUGTRAQ">20050425 remote command execution in inserter.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inserter.cgi" name="inserter.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1301" published="2005-04-13" name="CVE-2005-1301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/80_e.html" source="MISC" patch="1">http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/80_e.html</ref>
      <ref url="http://www.osvdb.org/15788" source="OSVDB">15788</ref>
      <ref url="http://secunia.com/advisories/15101" source="SECUNIA">15101</ref>
      <ref url="http://jvn.jp/jp/JVN%23AF02FB4B/index.html" source="MISC">http://jvn.jp/jp/JVN%23AF02FB4B/index.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444390329376&amp;w=2" source="BUGTRAQ">20050425 [SNS Advisory No.80] nProtect:Netizen Arbitrary File Download Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nprotect" name="netizen">
        <vers num="2005.3.17.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1302" published="2005-05-02" name="CVE-2005-1302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13355" source="BID">13355</ref>
      <ref url="http://www.osvdb.org/15815" source="OSVDB">15815</ref>
      <ref url="http://secunia.com/advisories/15121" source="SECUNIA">15121</ref>
      <ref url="http://securityreason.com/securityalert/694" source="SREASON">694</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444886429814&amp;w=2" source="BUGTRAQ">20050425 Sql Injection in Confixx 3.06 &amp; 3.08 &amp; 3.?? ?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="swsoft" name="confixx">
        <vers num="3.0.6" />
        <vers num="3.0.8" />
        <vers num="pro_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1303" published="2005-04-24" name="CVE-2005-1303" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445477910178&amp;w=2" source="BUGTRAQ">20050424 remote command execution in citat.pl script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citat.pl" name="citat.pl">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1304" published="2005-05-02" name="CVE-2005-1304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445477910178&amp;w=2" source="BUGTRAQ">20050424 remote command execution in citat.pl script</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1305" published="2005-05-02" name="CVE-2005-1305" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445410220152&amp;w=2" source="BUGTRAQ">20050424 hyper.cgi script file show bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hyper.cgi" name="hyper.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1306" published="2005-06-15" name="CVE-2005-1306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13962" source="BID" patch="1" adv="1">13962</ref>
      <ref url="http://www.adobe.com/support/techdocs/331710.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/331710.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" />
        <vers num="7.0.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0" />
        <vers num="7.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1307" published="2005-05-17" name="CVE-2005-1307" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/exploits/5EP0D20FQC.html" source="MISC">http://www.securiteam.com/exploits/5EP0D20FQC.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627622403544&amp;w=2" source="BUGTRAQ">20050516 Mac OS X - Adobe Version Cue local root exploit [c version exploit]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18445" source="XF">version-cue-gain-privileges(18445)</ref>
      <ref url="http://www.securityfocus.com/bid/11833" source="BID">11833</ref>
      <ref url="http://www.osvdb.org/12298" source="OSVDB">12298</ref>
      <ref url="http://www.osvdb.org/12297" source="OSVDB">12297</ref>
      <ref url="http://www.adobe.com/support/techdocs/331621.html" source="CONFIRM">http://www.adobe.com/support/techdocs/331621.html</ref>
      <ref url="http://securitytracker.com/id?1012446" source="SECTRACK">1012446</ref>
      <ref url="http://secunia.com/advisories/13399" source="SECUNIA">13399</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0040.html" source="BUGTRAQ">20041206 Local root exploit on Mac OS X with Adobe Version Cue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="version_cue">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":mac_os_x" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1308" published="2005-04-15" name="CVE-2005-1308" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13374" source="BID">13374</ref>
      <ref url="http://secunia.com/advisories/15119" source="SECUNIA">15119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inter7" name="sqwebmail">
        <vers num="3.4.1" />
        <vers num="3.5.0" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="4.0.4_2004-05-24" />
        <vers num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1309" published="2005-05-02" name="CVE-2005-1309" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15755" source="OSVDB">15755</ref>
      <ref url="http://www.osvdb.org/15754" source="OSVDB">15754</ref>
      <ref url="http://securitytracker.com/id?1013811" source="SECTRACK">1013811</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1188735&amp;group_id=81992&amp;atid=564683" source="MISC">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1188735&amp;group_id=81992&amp;atid=564683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eaden_mckee" name="bblog">
        <vers num="0.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1310" published="2005-04-23" name="CVE-2005-1310" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15756" source="OSVDB">15756</ref>
      <ref url="http://securitytracker.com/id?1013811" source="SECTRACK">1013811</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1188735&amp;group_id=81992&amp;atid=564683" source="MISC">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1188735&amp;group_id=81992&amp;atid=564683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eaden_mckee" name="bblog">
        <vers num="0.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1311" published="2005-05-02" name="CVE-2005-1311" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13372" source="BID" patch="1">13372</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=323206" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=323206</ref>
      <ref url="http://secunia.com/advisories/15107" source="SECUNIA" patch="1" adv="1">15107</ref>
      <ref url="http://www.osvdb.org/15828" source="OSVDB" adv="1">15828</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yappa-ng" name="yappa-ng">
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.1.0" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1312" published="2005-04-24" name="CVE-2005-1312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13371" source="BID" patch="1">13371</ref>
      <ref url="http://secunia.com/advisories/15107" source="SECUNIA" patch="1">15107</ref>
      <ref url="http://www.osvdb.org/15829" source="OSVDB">15829</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=323206" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=323206</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yappa-ng" name="yappa-ng">
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.1.0" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1313" published="2005-05-02" name="CVE-2005-1313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15075" source="SECUNIA" patch="1">15075</ref>
      <ref url="http://lists.horde.org/archives/sork/Week-of-Mon-20050418/002147.html" source="MLIST" patch="1">[sork] 20050422 Passwd 2.2.2 (final)</ref>
      <ref url="http://cvs.horde.org/diff.php/passwd/docs/CHANGES?r1=1.1.1.1.2.28&amp;r2=1.1.1.1.2.33&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/passwd/docs/CHANGES?r1=1.1.1.1.2.28&amp;r2=1.1.1.1.2.33&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="passwd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1314" published="2005-05-02" name="CVE-2005-1314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15080" source="SECUNIA" patch="1">15080</ref>
      <ref url="http://lists.horde.org/archives/kronolith/Week-of-Mon-20050418/005347.html" source="MLIST" patch="1">[kronolith] 20050422 Kronolith 1.1.4 (final)</ref>
      <ref url="http://cvs.horde.org/diff.php/kronolith/docs/CHANGES?r1=1.69.2.39&amp;r2=1.69.2.41&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/kronolith/docs/CHANGES?r1=1.69.2.39&amp;r2=1.69.2.41&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="kronolith">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1315" published="2005-05-02" name="CVE-2005-1315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15074" source="SECUNIA" patch="1">15074</ref>
      <ref url="http://lists.horde.org/archives/turba/Week-of-Mon-20050418/004182.html" source="MLIST" patch="1">[turba] 20050422 Turba 1.2.5 (final)</ref>
      <ref url="http://cvs.horde.org/diff.php/turba/docs/CHANGES?r1=1.61.2.74&amp;r2=1.61.2.77&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/turba/docs/CHANGES?r1=1.61.2.74&amp;r2=1.61.2.77&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="turba">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1_rc1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.3_rc1" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1316" published="2005-05-02" name="CVE-2005-1316" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15081" source="SECUNIA" patch="1">15081</ref>
      <ref url="http://cvs.horde.org/diff.php/accounts/docs/CHANGES?r1=1.1.1.1.2.15&amp;r2=1.1.1.1.2.18&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/accounts/docs/CHANGES?r1=1.1.1.1.2.15&amp;r2=1.1.1.1.2.18&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="accounts">
        <vers num="2.1" />
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1317" published="2005-04-25" name="CVE-2005-1317" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.horde.org/archives/chora/Week-of-Mon-20050418/004050.html" source="MLIST" patch="1">20050422 Chora 1.2.3 (final)</ref>
      <ref url="http://secunia.com/advisories/15083" source="SECUNIA">15083</ref>
      <ref url="http://cvs.horde.org/diff.php/chora/docs/CHANGES?r1=1.45.2.34&amp;r2=1.45.2.37&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/chora/docs/CHANGES?r1=1.45.2.34&amp;r2=1.45.2.37&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="chora">
        <vers prev="1" num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1318" published="2005-05-02" name="CVE-2005-1318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Forwards E-Mail Forwarding Manager before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15082" source="SECUNIA" patch="1">15082</ref>
      <ref url="http://lists.horde.org/archives/sork/Week-of-Mon-20050418/002145.html" source="MLIST" patch="1">[sork] 20050422 Forwards 2.2.2 (final)</ref>
      <ref url="http://cvs.horde.org/diff.php/forwards/docs/CHANGES?r1=1.1.1.1.2.20&amp;r2=1.1.1.1.2.23&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/forwards/docs/CHANGES?r1=1.1.1.1.2.20&amp;r2=1.1.1.1.2.23&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="forwards">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1319" published="2005-05-02" name="CVE-2005-1319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15080" source="SECUNIA" patch="1">15080</ref>
      <ref url="http://lists.horde.org/archives/imp/Week-of-Mon-20050418/041912.html" source="MLIST" patch="1">[imp] 20050422 IMP 3.2.8 (final)</ref>
      <ref url="http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.119&amp;r2=1.389.2.125&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.119&amp;r2=1.389.2.125&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="imp">
        <vers prev="1" num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.7_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1320" published="2005-05-02" name="CVE-2005-1320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15078" source="SECUNIA" patch="1">15078</ref>
      <ref url="http://lists.horde.org/archives/mnemo/Week-of-Mon-20050418/000166.html" source="MLIST">[mnemo] 20050422 Mnemo 1.1.4 (final)</ref>
      <ref url="http://cvs.horde.org/diff.php/mnemo/docs/CHANGES?r1=1.4.2.31&amp;r2=1.4.2.33&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/mnemo/docs/CHANGES?r1=1.4.2.31&amp;r2=1.4.2.33&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="mnemo">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1321" published="2005-05-02" name="CVE-2005-1321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15073" source="SECUNIA" patch="1" adv="1">15073</ref>
      <ref url="http://lists.horde.org/archives/sork/Week-of-Mon-20050418/002148.html" source="MLIST" patch="1">[sork] 20050422 Vacation 2.2.2 (final)</ref>
      <ref url="http://cvs.horde.org/diff.php/vacation/docs/CHANGES?r1=1.1.1.1.2.21&amp;r2=1.1.1.1.2.26&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/vacation/docs/CHANGES?r1=1.1.1.1.2.21&amp;r2=1.1.1.1.2.26&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="vaction">
        <vers num="1.0a" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1322" published="2005-05-02" name="CVE-2005-1322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.horde.org/archives/nag/Week-of-Mon-20050418/000756.html" source="MLIST" patch="1">[nag] 20050422 Nag 1.1.3 (final)</ref>
      <ref url="http://secunia.com/advisories/15079" source="SECUNIA" adv="1">15079</ref>
      <ref url="http://cvs.horde.org/diff.php/nag/docs/CHANGES?r1=1.54.2.33&amp;r2=1.54.2.35&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/nag/docs/CHANGES?r1=1.54.2.33&amp;r2=1.54.2.35&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="nag">
        <vers num="1.1.1" />
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1323" published="2005-05-02" name="CVE-2005-1323" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20285" source="XF">netterm-netftpd-user-bo(20285)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0407" source="VUPEN">ADV-2005-0407</ref>
      <ref url="http://www.securityfocus.com/bid/13396" source="BID">13396</ref>
      <ref url="http://www.securityfocus.com/archive/1/396959" source="BUGTRAQ">20050426 ADV: NetTerm's NetFtpd 4.2.2 Buffer Overflow + PoC Exploit</ref>
      <ref url="http://www.securenetterm.com/html/what_s_new.html" source="CONFIRM">http://www.securenetterm.com/html/what_s_new.html</ref>
      <ref url="http://www.osvdb.org/15865" source="OSVDB">15865</ref>
      <ref url="http://secunia.com/advisories/15140" source="SECUNIA">15140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intersoft" name="netterm">
        <vers num="4.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1324" published="2005-05-02" name="CVE-2005-1324" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php for phpMyVisites allow remote attackers to inject arbitrary web script or HTML via the (1) part, (2) per, or (3) site parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20255" source="XF">phpmyvisites-index-xss(20255)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0378" source="VUPEN">ADV-2005-0378</ref>
      <ref url="http://www.osvdb.org/15789" source="OSVDB">15789</ref>
      <ref url="http://secunia.com/advisories/15084" source="SECUNIA">15084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthieu_aubry" name="phpmyvisites">
        <vers num="0.1_beta" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2_beta" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1325" published="2005-05-02" name="CVE-2005-1325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13370" source="BID" patch="1">13370</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454298603060&amp;w=2" source="BUGTRAQ">20050426 [exploits] phpMyVisites 1.3 local file retrieval</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpmyvisites/phpmyvisites/include/set_lang.php?r1=1.5&amp;r2=1.6" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/phpmyvisites/phpmyvisites/include/set_lang.php?r1=1.5&amp;r2=1.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthieu_aubry" name="phpmyvisites">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1326" published="2005-05-02" name="CVE-2005-1326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in VooDoo cIRCle BOTNET before 1.0.33 allows remote authenticated attackers to cause a denial of service (client crash) via a crafted packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=323254" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=323254</ref>
      <ref url="http://www.osvdb.org/15830" source="OSVDB" adv="1">15830</ref>
      <ref url="http://secunia.com/advisories/15110" source="SECUNIA">15110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="voodoo_circle" name="voodoo_circle">
        <vers num="1.0.20" />
        <vers num="1.0.21" />
        <vers num="1.0.22" />
        <vers num="1.0.23" />
        <vers num="1.0.24" />
        <vers num="1.0.25" />
        <vers num="1.0.26" />
        <vers num="1.0.27" />
        <vers num="1.0.28" />
        <vers num="1.0.29" />
        <vers num="1.0.30" />
        <vers num="1.0.31" />
        <vers num="1.0.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1327" published="2005-05-02" name="CVE-2005-1327" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13353" source="BID">13353</ref>
      <ref url="http://www.securityfocus.com/archive/1/396858" source="BUGTRAQ" adv="1">20050424 WoltLab Burning Board &lt;= 2.3.1 PL2 - XSS Vulnerability (24.04.05)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers prev="1" num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1328" published="2005-05-02" name="CVE-2005-1328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OneWorldStore allows remote attackers to cause a denial of service (application crash) via a direct request to owConnections/chksettings.asp.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13322" source="BID" patch="1">13322</ref>
      <ref url="http://www.oneworldstore.com/support_security_issue_updates.asp#April_20_2005_Lostmon" source="CONFIRM" patch="1">http://www.oneworldstore.com/support_security_issue_updates.asp#April_20_2005_Lostmon</ref>
      <ref url="http://lostmon.blogspot.com/2005/04/oneworldstore-critical-failure.html" source="MISC" patch="1">http://lostmon.blogspot.com/2005/04/oneworldstore-critical-failure.html</ref>
      <ref url="http://www.osvdb.org/15724" source="OSVDB">15724</ref>
      <ref url="http://securitytracker.com/id?1013782" source="SECTRACK">1013782</ref>
      <ref url="http://secunia.com/advisories/15057" source="SECUNIA">15057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneworldstore" name="oneworldstore">
        <vers num="basic" />
        <vers num="business" />
        <vers num="enterprise" />
        <vers num="free" />
        <vers num="soho" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1329" published="2005-05-02" name="CVE-2005-1329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13361" source="BID" patch="1">13361</ref>
      <ref url="http://www.oneworldstore.com/support_security_issue_updates.asp#April_24_2005_Lostmon" source="CONFIRM" patch="1">http://www.oneworldstore.com/support_security_issue_updates.asp#April_24_2005_Lostmon</ref>
      <ref url="http://securitytracker.com/id?1013796" source="SECTRACK" patch="1">1013796</ref>
      <ref url="http://secunia.com/advisories/15104" source="SECUNIA" patch="1">15104</ref>
      <ref url="http://lostmon.blogspot.com/2005/04/oneworldstore-user-information.html" source="MISC" patch="1">http://lostmon.blogspot.com/2005/04/oneworldstore-user-information.html</ref>
      <ref url="http://www.osvdb.org/15781" source="OSVDB">15781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneworldstore" name="oneworldstore">
        <vers num="basic" />
        <vers num="business" />
        <vers num="enterprise" />
        <vers num="free" />
        <vers num="soho" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1330" published="2005-05-04" name="CVE-2005-1330" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" adv="1">APPLE-SA-2005-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1331" published="2005-05-04" name="CVE-2005-1331" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13480" source="BID" patch="1">13480</ref>
      <ref url="http://secunia.com/advisories/15227" source="SECUNIA" patch="1">15227</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0455" source="VUPEN">ADV-2005-0455</ref>
      <ref url="http://remahl.se/david/vuln/010/" source="MISC">http://remahl.se/david/vuln/010/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="applescript">
        <vers num="2.0.0" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1332" published="2005-05-04" name="CVE-2005-1332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/258390" source="CERT-VN">VU#258390</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" adv="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=301381" source="CONFIRM" adv="1">http://docs.info.apple.com/article.html?artnum=301381</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0502a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2005-0502a%5D.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1333" published="2005-05-04" name="CVE-2005-1333" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://www.securityfocus.com/bid/13491" source="BID">13491</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0502a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2005-0502a%5D.txt</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1334" reject="1" published="2005-06-03" name="CVE-2005-1334" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1579.  Reason: This candidate is a duplicate of CVE-2005-1579.  Notes: All CVE users should reference CVE-2005-1579 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-1335" published="2005-05-04" name="CVE-2005-1335" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/331694" source="CERT-VN">VU#331694</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE">APPLE-SA-2005-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1336" published="2005-05-04" name="CVE-2005-1336" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/582934" source="CERT-VN">VU#582934</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE">APPLE-SA-2005-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1337" published="2005-05-04" name="CVE-2005-1337" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://remahl.se/david/vuln/004/" source="MISC" adv="1">http://remahl.se/david/vuln/004/</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" adv="1">APPLE-SA-2005-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1338" published="2005-05-04" name="CVE-2005-1338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1339" published="2005-05-04" name="CVE-2005-1339" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" adv="1">APPLE-SA-2005-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1340" published="2005-05-04" name="CVE-2005-1340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1341" published="2005-05-04" name="CVE-2005-1341" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/994510" source="CERT-VN">VU#994510</ref>
      <ref url="http://www.securityfocus.com/bid/13480" source="BID" patch="1">13480</ref>
      <ref url="http://securitytracker.com/id?1013882" source="SECTRACK" patch="1">1013882</ref>
      <ref url="http://secunia.com/advisories/15227" source="SECUNIA" patch="1">15227</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0455" source="VUPEN">ADV-2005-0455</ref>
      <ref url="http://www.osvdb.org/16083" source="OSVDB" adv="1">16083</ref>
      <ref url="http://remahl.se/david/vuln/012/" source="MISC">http://remahl.se/david/vuln/012/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="terminal">
        <vers num="1.4.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1342" published="2005-05-04" name="CVE-2005-1342" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/356070" source="CERT-VN" adv="1">VU#356070</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.securityfocus.com/bid/13480" source="BID" patch="1">13480</ref>
      <ref url="http://secunia.com/advisories/15227" source="SECUNIA" patch="1" adv="1">15227</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0455" source="VUPEN">ADV-2005-0455</ref>
      <ref url="http://www.osvdb.org/16084" source="OSVDB" adv="1">16084</ref>
      <ref url="http://remahl.se/david/vuln/011/" source="MISC" adv="1">http://remahl.se/david/vuln/011/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="terminal">
        <vers num="1.4.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1343" published="2005-05-03" name="CVE-2005-1343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/706838" source="CERT-VN">VU#706838</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1344" published="2005-05-02" name="CVE-2005-1344" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument.  NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program.  Therefore this may not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/5EP061FEKC.html" source="MISC">http://www.securiteam.com/unixfocus/5EP061FEKC.html</ref>
      <ref url="http://www.osvdb.org/12848" source="OSVDB">12848</ref>
      <ref url="http://www.lucaercoli.it/advs/htdigest.txt" source="MISC">http://www.lucaercoli.it/advs/htdigest.txt</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE">APPLE-SA-2005-05-03</ref>
      <ref url="http://www.securityfocus.com/bid/13537" source="BID">13537</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1345" published="2005-05-02" name="CVE-2005-1345" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-acl_error" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-acl_error</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1255" source="CONFIRM">http://www.squid-cache.org/bugs/show_bug.cgi?id=1255</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-415.html" source="REDHAT">RHSA-2005:415</ref>
      <ref url="http://www.debian.org/security/2005/dsa-721" source="DEBIAN">DSA-721</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10513" source="OVAL">oval:org.mitre.oval:def:10513</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000948" source="CONECTIVA">CLA-2005:948</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.stable1" />
        <vers num="2.5.stable2" />
        <vers num="2.5.stable3" />
        <vers num="2.5.stable4" />
        <vers num="2.5.stable5" />
        <vers num="2.5.stable6" />
        <vers num="2.5.stable7" />
        <vers num="2.5.stable8" />
        <vers num="2.5.stable9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1346" published="2005-05-02" name="CVE-2005-1346" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a denial of service (component crash) and avoid detection via a crafted RAR file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2005.04.27.html" source="CONFIRM" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2005.04.27.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="4.3.7.27" />
      </prod>
      <prod vendor="symantec" name="mail_security">
        <vers num="4.0.5.66" edition="" />
        <vers num="4.0.5.66" edition=":smtp" />
        <vers num="4.5.4.743" edition="" />
        <vers num="4.5.4.743" edition=":exchange" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2005_11.0.0" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2005_contains_nav_11.0.0" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2005_contains_nav_11.0.0" />
      </prod>
      <prod vendor="symantec" name="symav_filter_domino_nt">
        <vers num="3.1.1.87" />
      </prod>
      <prod vendor="symantec" name="web_security">
        <vers num="3.0.1.72" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1347" published="2005-05-02" name="CVE-2005-1347" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">** UNVERIFIABLE **  NOTE: this issue describes a problem that can not be independently verified as of 20050421.  Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service ("Invalid-ID-Handle-Error" error) and modify memory beginning at a particular address, possibly allowing the execution of arbitrary code, via a crafted PDF file.  NOTE: the vendor has stated that the reporter refused to provide sufficient details to confirm the issue.  In addition, due to the lack of details in the original advisory, an independent verification is not possible.  Finally, the reliability of the original reporter is unknown.  This item has only been assigned a CVE identifier for tracking purposes, and to serve as a concrete example of the newly defined UNVERIFIABLE and PRERELEASE content decisions in CVE, which must be discussed by the Editorial Board. Without additional details or independent verification by reliable sources, it is highly likely that this item will be REJECTED.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20216" source="XF">acrobat-reader-invalid-id-handle-bo(20216)</ref>
      <ref url="http://www.osvdb.org/15850" source="OSVDB">15850</ref>
      <ref url="http://www.alphahackers.com/advisories/acrobat6.txt" source="MISC">http://www.alphahackers.com/advisories/acrobat6.txt</ref>
      <ref url="http://securitytracker.com/id?1013774" source="SECTRACK">1013774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="3.0" />
        <vers num="5.0.10" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1348" published="2005-05-02" name="CVE-2005-1348" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorization header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445834220015&amp;w=2" source="BUGTRAQ">20050424 MailEnable HTTPS Buffer Overflow [x0n3-h4ck]</ref>
      <ref url="http://www.x0n3-h4ck.org/upload/x0n3-h4ck_mailenable_https.pl" source="MISC">http://www.x0n3-h4ck.org/upload/x0n3-h4ck_mailenable_https.pl</ref>
      <ref url="http://www.osvdb.org/15737" source="OSVDB">15737</ref>
      <ref url="http://securitytracker.com/id?1013786" source="SECTRACK">1013786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_enterprise">
        <vers prev="1" num="1.04" />
      </prod>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers prev="1" num="1.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1349" published="2005-05-02" name="CVE-2005-1349" modified="2010-04-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15130" source="SECUNIA" patch="1">15130</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20275" source="XF" adv="1">convert-uulib-bo(20275)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-26.xml" source="GENTOO">GLSA-200504-26</ref>
      <ref url="http://www.securityfocus.com/bid/13401" source="BID">13401</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:022" source="MANDRIVA">MDKSA-2006:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perl" name="convert_uulib">
        <vers prev="1" num="1.050" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1350" published="2005-05-02" name="CVE-2005-1350" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ad.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446285915444&amp;w=2" source="BUGTRAQ">20050424 remote command execution in ad.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="ad.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1351" published="2005-05-02" name="CVE-2005-1351" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ad.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446285915444&amp;w=2" source="BUGTRAQ">20050424 remote command execution in ad.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="ad.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1352" published="2005-05-02" name="CVE-2005-1352" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the ad.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446285915444&amp;w=2" source="BUGTRAQ">20050424 remote command execution in ad.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="ad.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1353" published="2005-05-02" name="CVE-2005-1353" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The forum.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446056205059&amp;w=2" source="BUGTRAQ">20050424 remote command execution in forum.pl script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="forum.pl" name="forum.pl">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1354" published="2005-05-02" name="CVE-2005-1354" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The forum.pl script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446056205059&amp;w=2" source="BUGTRAQ">20050424 remote command execution in forum.pl script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="forum.pl" name="forum.pl">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1355" published="2005-05-02" name="CVE-2005-1355" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">includer.cgi in The Includer allows remote attackers to read arbitrary files via a full pathname in the argument, a similar vulnerability to CVE-2005-0801.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445548126797&amp;w=2" source="BUGTRAQ">20050424 remote command execution in includer.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="includer.cgi" name="includer.cgi">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1356" published="2005-05-02" name="CVE-2005-1356" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in includer.cgi script in The Includer allows remote attackers to inject arbitrary web script or HTML via the argument.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445548126797&amp;w=2" source="BUGTRAQ">20050424 remote command execution in includer.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="includer.cgi" name="includer.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1357" published="2005-05-02" name="CVE-2005-1357" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">text.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445867315415&amp;w=2" source="BUGTRAQ">20050425 remote command execution in text.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="text.cgi" name="text.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1358" published="2005-05-02" name="CVE-2005-1358" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">text.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445867315415&amp;w=2" source="BUGTRAQ">20050425 remote command execution in text.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="text.cgi" name="text.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1359" published="2005-05-02" name="CVE-2005-1359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445867315415&amp;w=2" source="BUGTRAQ">20050425 remote command execution in text.cgi script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="text.cgi" name="text.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1360" published="2005-05-02" name="CVE-2005-1360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP code by modifying the path_prefix parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20278" source="XF">graycms-pathprefix-error-include(20278)</ref>
      <ref url="http://www.securityfocus.com/bid/13381" source="BID" adv="1">13381</ref>
      <ref url="http://www.osvdb.org/15860" source="OSVDB" adv="1">15860</ref>
      <ref url="http://secunia.com/advisories/15133" source="SECUNIA">15133</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454354214982&amp;w=2" source="BUGTRAQ">20050426 GrayCMS php code injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="graycms" name="graycms">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1361" published="2005-05-02" name="CVE-2005-1361" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20283" source="XF">metacart-eshop-sql-injection(20283)</ref>
      <ref url="http://www.securityfocus.com/bid/13377" source="BID">13377</ref>
      <ref url="http://www.securityfocus.com/bid/13376" source="BID">13376</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111453994718211&amp;w=2" source="BUGTRAQ">20050426 Multiple SQL Injections in MetaCart e-Shop V-8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metalinks" name="metacart_e-shop">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1362" published="2005-05-02" name="CVE-2005-1362" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) chkText, (5) strText, (6) chkPrice, (7) intPrice, (8) chkCat, or (9) strCat parameters to searchAction.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454090503662&amp;w=2" source="BUGTRAQ">20050426 Multiple SQL Injections in MetaCart2 for SQL Server Special Edition U.K</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metalinks" name="metacart2">
        <vers num="paypal" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1363" published="2005-05-02" name="CVE-2005-1363" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCatalog_NAME parameter to productsByCategory.asp, (4) curCatalogID, (5) strSubCatalog_NAME, (6) intCatalogID, or (7) page parameter to productsByCategory.asp or (8) intProdID parameter to product.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454142832023&amp;w=2" source="BUGTRAQ">20050426 MetaCart2 for PayFlow Multiple Sql Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metalinks" name="metacart2">
        <vers num="payflow_link" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1364" published="2005-05-02" name="CVE-2005-1364" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) intAuctionID parameter to item.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20286" source="XF">metabid-item-login-sql-injection(20286)</ref>
      <ref url="http://www.securityfocus.com/bid/13395" source="BID">13395</ref>
      <ref url="http://www.osvdb.org/15869" source="OSVDB">15869</ref>
      <ref url="http://www.osvdb.org/15868" source="OSVDB">15868</ref>
      <ref url="http://secunia.com/advisories/15136" source="SECUNIA" adv="1">15136</ref>
      <ref url="http://digitalparadox.org/advisories/metabid.txt" source="MISC">http://digitalparadox.org/advisories/metabid.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454192928364&amp;w=2" source="BUGTRAQ">20050426 Multiple SQL Injections in MetaBid Auctions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metalinks" name="metabid_auctions">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1365" published="2005-05-16" name="CVE-2005-1365" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13642" source="BID">13642</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-010.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-010.txt</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=327708" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=327708</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111625635716712&amp;w=2" source="FULLDISC" adv="1">20050516 Advisory: Pico Server (pServ) Remote Command Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pico_server" name="pico_server">
        <vers num="3.0" />
        <vers num="3.0_beta_3" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1366" published="2005-05-16" name="CVE-2005-1366" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13638" source="BID">13638</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-011.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-011.txt</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=327708" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=327708</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111625623909003&amp;w=2" source="FULLDISC" adv="1">20050516 Pico Server (pServ) Information Disclosure Of CGI Sources</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pico_server" name="pico_server">
        <vers num="3.0" />
        <vers num="3.0_beta_3" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1367" published="2005-05-16" name="CVE-2005-1367" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-012.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-012.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111625623909003&amp;w=2" source="FULLDISC" adv="1">20050516 Pico Server (pServ) Local Information Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pico_server" name="pico_server">
        <vers num="3.0" />
        <vers num="3.0_beta_3" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1368" published="2005-05-02" name="CVE-2005-1368" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.8" source="CONFIRM" patch="1">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.8</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset%40423078fafVa6mAyny23YZ87hDipmTw" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset%40423078fafVa6mAyny23YZ87hDipmTw</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1369" published="2005-05-02" name="CVE-2005-1369" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) it87 and (2) via686a drivers in I2C for Linux 2.6.x before 2.6.11.8, and 2.6.12 before 2.6.12-rc2, create the sysfs "alarms" file with write permissions, which allows local users to cause a denial of service (CPU consumption) by attempting to write to the file, which does not have an associated store function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.8" source="CONFIRM" patch="1">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.8</ref>
      <ref url="http://lkml.org/lkml/2005/4/20/159" source="CONFIRM">http://lkml.org/lkml/2005/4/20/159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1370" published="2005-05-03" name="CVE-2005-1370" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013829" source="SECTRACK" patch="1">1013829</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0490.html" source="HP" patch="1">HPSBMA01138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20307" source="XF">hp-openview-radia-gain-access(20307)</ref>
      <ref url="http://www.securityfocus.com/bid/13414" source="BID">13414</ref>
      <ref url="http://www.osvdb.org/15960" source="OSVDB">15960</ref>
      <ref url="http://secunia.com/advisories/15089" source="SECUNIA">15089</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0490.html" source="HP">SSRT5958</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111471365231909&amp;w=2" source="BUGTRAQ">20050428 High risk flaw in HP OpenView Radia Management Agent</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_radia_management_portal">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1371" published="2005-05-03" name="CVE-2005-1371" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20301" source="XF">bpftp-gain-privilege(20301)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0419" source="VUPEN">ADV-2005-0419</ref>
      <ref url="http://www.securityfocus.com/bid/13410" source="BID">13410</ref>
      <ref url="http://www.osvdb.org/15898" source="OSVDB">15898</ref>
      <ref url="http://secunia.com/advisories/15152" source="SECUNIA">15152</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464474828477&amp;w=2" source="BUGTRAQ">20050427 Privilege escalation in BulletProof FTP Server v2.4.0.31</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bulletproof" name="bulletproof_ftp_server">
        <vers num="2.4.0.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1372" published="2005-05-03" name="CVE-2005-1372" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20302" source="XF">bakbone-netvault-gain-privileges(20302)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0420" source="VUPEN">ADV-2005-0420</ref>
      <ref url="http://www.securityfocus.com/bid/13408" source="BID">13408</ref>
      <ref url="http://www.osvdb.org/15900" source="OSVDB">15900</ref>
      <ref url="http://secunia.com/advisories/15158/" source="SECUNIA">15158</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464410324243&amp;w=2" source="BUGTRAQ">20050427 Privilege escalation in BakBone NetVault 7.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bakbone" name="netvault">
        <vers num="7.1.1" />
        <vers num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1373" published="2005-05-03" name="CVE-2005-1373" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in Dream4 Koobi CMS 4.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) q or (2) p parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20293" source="XF">koobi-parameter-search-sql-injection(20293)</ref>
      <ref url="http://www.securityfocus.com/bid/13413" source="BID">13413</ref>
      <ref url="http://www.securityfocus.com/bid/13412" source="BID">13412</ref>
      <ref url="http://www.osvdb.org/15997" source="OSVDB">15997</ref>
      <ref url="http://secunia.com/advisories/14696" source="SECUNIA">14696</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464009913703&amp;w=2" source="BUGTRAQ">20050427 SQL-injections in koobi-cms</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dream4" name="koobi_cms">
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1374" published="2005-05-03" name="CVE-2005-1374" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php, (4) learningPathList.php, (5) learningPathAdmin.php, (6) learningPath.php, (7) userLog.php, (8) tool parameter to toolaccess_details.php, (9) data parameter to user_access_details.php, or (10) coursePath parameter to myagenda.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20295" source="XF" patch="1" adv="1">claroline-multiple-scripts-xss(20295)</ref>
      <ref url="http://www.securityfocus.com/bid/13407" source="BID" patch="1" adv="1">13407</ref>
      <ref url="http://www.claroline.net/news.php#85" source="CONFIRM" patch="1" adv="1">http://www.claroline.net/news.php#85</ref>
      <ref url="http://securitytracker.com/id?1013822" source="SECTRACK" patch="1" adv="1">1013822</ref>
      <ref url="http://secunia.com/advisories/15161" source="SECUNIA" patch="1" adv="1">15161</ref>
      <ref url="http://secunia.com/advisories/15725" source="SECUNIA">15725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464607103407&amp;w=2" source="BUGTRAQ">20050427 ZRCSA-200501 - Multiple vulnerabilities in Claroline</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.5.3" />
        <vers num="1.6_beta" />
        <vers num="1.6_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1375" published="2005-05-03" name="CVE-2005-1375" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20298" source="XF" patch="1">claroline-multiple-sql-injection(20298)</ref>
      <ref url="http://www.securityfocus.com/bid/13407" source="BID" patch="1">13407</ref>
      <ref url="http://www.claroline.net/news.php#85" source="CONFIRM" patch="1">http://www.claroline.net/news.php#85</ref>
      <ref url="http://securitytracker.com/id?1013822" source="SECTRACK" patch="1">1013822</ref>
      <ref url="http://secunia.com/advisories/15161" source="SECUNIA" patch="1">15161</ref>
      <ref url="http://secunia.com/advisories/15725" source="SECUNIA">15725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464607103407&amp;w=2" source="BUGTRAQ">20050427 ZRCSA-200501 - Multiple vulnerabilities in Claroline</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.5.3" />
        <vers num="1.6_beta" />
        <vers num="1.6_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1376" published="2005-05-03" name="CVE-2005-1376" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20287" source="XF" patch="1">claroline-document-directory-traversal(20287)</ref>
      <ref url="http://www.securityfocus.com/bid/13407" source="BID" patch="1">13407</ref>
      <ref url="http://www.claroline.net/news.php#85" source="CONFIRM" patch="1">http://www.claroline.net/news.php#85</ref>
      <ref url="http://securitytracker.com/id?1013822" source="SECTRACK" patch="1">1013822</ref>
      <ref url="http://secunia.com/advisories/15161" source="SECUNIA" patch="1">15161</ref>
      <ref url="http://secunia.com/advisories/15725" source="SECUNIA">15725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464607103407&amp;w=2" source="BUGTRAQ">20050427 ZRCSA-200501 - Multiple vulnerabilities in Claroline</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.5.3" />
        <vers num="1.6_beta" />
        <vers num="1.6_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1377" published="2005-05-03" name="CVE-2005-1377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary PHP code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20300" source="XF" patch="1">claroline-file-include(20300)</ref>
      <ref url="http://www.securityfocus.com/bid/13407" source="BID" patch="1">13407</ref>
      <ref url="http://www.claroline.net/news.php#85" source="CONFIRM" patch="1">http://www.claroline.net/news.php#85</ref>
      <ref url="http://securitytracker.com/id?1013822" source="SECTRACK" patch="1">1013822</ref>
      <ref url="http://secunia.com/advisories/15161" source="SECUNIA" patch="1">15161</ref>
      <ref url="http://secunia.com/advisories/15725" source="SECUNIA">15725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464607103407&amp;w=2" source="BUGTRAQ">20050427 ZRCSA-200501 - Multiple vulnerabilities in Claroline</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.5.3" />
        <vers num="1.6_beta" />
        <vers num="1.6_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1378" published="2005-05-03" name="CVE-2005-1378" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13417" source="BID" patch="1">13417</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20303" source="XF">phpbb-notes-module-sql-injection(20303)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0416" source="VUPEN">ADV-2005-0416</ref>
      <ref url="http://www.osvdb.org/15899" source="OSVDB">15899</ref>
      <ref url="http://securitytracker.com/id?1013827" source="SECTRACK">1013827</ref>
      <ref url="http://secunia.com/advisories/15154/" source="SECUNIA">15154</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00070-04272005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00070-04272005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111471606518372&amp;w=2" source="BUGTRAQ">20050427 phpBB Notes Mod SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oxpus" name="phpbb_personal_notes_module">
        <vers prev="1" num="1.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1379" published="2005-05-03" name="CVE-2005-1379" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13431" source="BID" adv="1">13431</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472262231060&amp;w=2" source="BUGTRAQ">20050428 insecure user account lam-runtime-7.0.6-2mdk rpm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_lam-runtime">
        <vers num="7.0.6.2mdk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1380" published="2005-05-03" name="CVE-2005-1380" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20276" source="XF" adv="1">weblogic-jndiframesetaction-xss(20276)</ref>
      <ref url="http://www.securityfocus.com/bid/13400" source="BID" adv="1">13400</ref>
      <ref url="http://www.red-database-security.com/advisory/bea_css_in_admin_console.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/bea_css_in_admin_console.html</ref>
      <ref url="http://www.osvdb.org/15895" source="OSVDB">15895</ref>
      <ref url="http://securitytracker.com/alerts/2005/Apr/1013817.html" source="SECTRACK" adv="1">1013817</ref>
      <ref url="http://secunia.com/advisories/15128" source="SECUNIA" adv="1">15128</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472745503010&amp;w=2" source="BUGTRAQ">20050428 Cross Site Scripting in BEA Admin Console</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:win32" />
        <vers num="8.1" edition="sp4:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1381" published="2005-05-03" name="CVE-2005-1381" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20309" source="XF" adv="1">oracle9ias-application-cache-xss(20309)</ref>
      <ref url="http://www.securityfocus.com/bid/13422" source="BID" adv="1">13422</ref>
      <ref url="http://www.securityfocus.com/bid/13421" source="BID" adv="1">13421</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_webcache_CSS_vulnerabilities.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_webcache_CSS_vulnerabilities.html</ref>
      <ref url="http://www.osvdb.org/15910" source="OSVDB" adv="1">15910</ref>
      <ref url="http://secunia.com/advisories/15143" source="SECUNIA" adv="1">15143</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472423409560&amp;w=2" source="BUGTRAQ">20050428 Cross Site Scripting in Oracle Webcache 9i Adminstrator Application</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_web_cache">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1382" published="2005-05-03" name="CVE-2005-1382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20310" source="XF" adv="1">oracle9ias-application-cache-file-corruption(20310)</ref>
      <ref url="http://www.securityfocus.com/bid/13420" source="BID" adv="1">13420</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_webcache_append_file_vulnerabilitiy.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_webcache_append_file_vulnerabilitiy.html</ref>
      <ref url="http://www.osvdb.org/15909" source="OSVDB" adv="1">15909</ref>
      <ref url="http://secunia.com/advisories/15143" source="SECUNIA" adv="1">15143</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472615519295&amp;w=2" source="BUGTRAQ">20050428 File appending vulnerability in Oracle Webcache 9i</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_web_cache">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1383" published="2005-05-03" name="CVE-2005-1383" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20311" source="XF" patch="1">oracle9ias-application-cache-url-bypass(20311)</ref>
      <ref url="http://www.securityfocus.com/bid/13418" source="BID" patch="1">13418</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_webcache_bypass.html" source="MISC" patch="1">http://www.red-database-security.com/advisory/oracle_webcache_bypass.html</ref>
      <ref url="http://www.osvdb.org/15908" source="OSVDB" patch="1">15908</ref>
      <ref url="http://secunia.com/advisories/15143" source="SECUNIA">15143</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472266123952&amp;w=2" source="BUGTRAQ">20050428 Webcache Client Requests Bypass OHS mod_access Restrictions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.0.2" />
        <vers num="10.1.0.3" />
        <vers num="10.1.0.3.1" />
        <vers num="10.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1384" published="2005-05-03" name="CVE-2005-1384" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20308" source="XF">phpcoin-multiple-sql-injection(20308)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0423" source="VUPEN">ADV-2005-0423</ref>
      <ref url="http://www.securityfocus.com/bid/13433" source="BID">13433</ref>
      <ref url="http://securitytracker.com/id?1013834" source="SECTRACK">1013834</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111473522804665&amp;w=2" source="BUGTRAQ">20050428 Multiple Sql injections in phpCoin v1.2.2 and below</ref>
      <ref url="http://digitalparadox.org/viewadvisories.ah?view=36" source="MISC" adv="1">http://digitalparadox.org/viewadvisories.ah?view=36</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/phpcoin-poc.html" source="MISC">http://pridels0.blogspot.com/2006/03/phpcoin-poc.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coinsoft_technologies" name="phpcoin">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1385" published="2005-05-03" name="CVE-2005-1385" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16006" source="OSVDB">16006</ref>
      <ref url="http://securitytracker.com/id?1013835" source="SECTRACK">1013835</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111479346119272&amp;w=2" source="BUGTRAQ">20050429  Re: Safari HTTPS Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111479299730011&amp;w=2" source="BUGTRAQ">20050429 Re: Safari HTTPS Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111473570624498&amp;w=2" source="BUGTRAQ">20050428 Safari HTTPS Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1386" published="2005-05-03" name="CVE-2005-1386" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to Web_Links with the portuguese language (lang-portuguese.php), (7) a request to Web_Links with the indonesian language (lang-indonesian.php), (8) a request to the survey module with the indonesian language (lang-indonesian.php), (9) a request to the Reviews module with the portuguese language, or (10) a request to the Journal module with the portuguese language, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111478982629035&amp;w=2" source="BUGTRAQ">20050429 Multiples Full Path Disclosure in php-nuke 7.6 (and below)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1387" published="2005-05-03" name="CVE-2005-1387" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing processes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13449" source="BID">13449</ref>
      <ref url="http://www.osvdb.org/16046" source="OSVDB">16046</ref>
      <ref url="http://secunia.com/advisories/15201" source="SECUNIA">15201</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111480898530362&amp;w=2" source="BUGTRAQ">20050429 Mac OS X Cocktail 3.5.4 admin password disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kristofer_szymanski" name="cocktail">
        <vers num="3.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1388" published="2005-05-03" name="CVE-2005-1388" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SURVIVOR before 0.9.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13415" source="BID" patch="1">13415</ref>
      <ref url="http://www.columbia.edu/acis/dev/projects/survivor/doc/todo.html#changelog" source="CONFIRM" patch="1">http://www.columbia.edu/acis/dev/projects/survivor/doc/todo.html#changelog</ref>
      <ref url="http://www.osvdb.org/15905" source="OSVDB" adv="1">15905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="survivor" name="survivor">
        <vers num="0.9.5a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1389" reject="1" published="2005-05-03" name="CVE-2005-1389" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0175.  Reason: This candidate is a duplicate of CVE-2005-0175.  Notes: All CVE users should reference CVE-2005-0175 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" seq="2005-1390" reject="1" published="2005-05-03" name="CVE-2005-1390" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0174.  Reason: This candidate is a duplicate of CVE-2005-0174.  Notes: All CVE users should reference CVE-2005-0174 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-1391" published="2005-05-03" name="CVE-2005-1391" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13436" source="BID" patch="1">13436</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20316" source="XF">pound-addport-bo(20316)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0437" source="VUPEN">ADV-2005-0437</ref>
      <ref url="http://www.osvdb.org/15963" source="OSVDB" adv="1">15963</ref>
      <ref url="http://www.debian.org/security/2005/dsa-934" source="DEBIAN">DSA-934</ref>
      <ref url="http://www.apsis.ch/pound/pound_list/archive/2005/2005-04/1114516112000" source="MLIST">[pound_list] 20050426 remote buffer overflow in pound 1.8.2 + question abotu Host header</ref>
      <ref url="http://securitytracker.com/id?1013824" source="SECTRACK">1013824</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-29.xml" source="GENTOO">GLSA-200504-29</ref>
      <ref url="http://secunia.com/advisories/18381" source="SECUNIA">18381</ref>
      <ref url="http://secunia.com/advisories/15679" source="SECUNIA">15679</ref>
      <ref url="http://secunia.com/advisories/15202" source="SECUNIA">15202</ref>
      <ref url="http://secunia.com/advisories/15142" source="SECUNIA">15142</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=307852" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=307852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apsis" name="pound">
        <vers num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1392" published="2005-05-03" name="CVE-2005-1392" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0436" source="VUPEN">ADV-2005-0436</ref>
      <ref url="http://www.osvdb.org/16053" source="OSVDB">16053</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-30.xml" source="GENTOO" adv="1">GLSA-200504-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1393" published="2005-05-03" name="CVE-2005-1393" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt" source="MISC" patch="1">http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt</ref>
      <ref url="http://securitytracker.com/id?1013852" source="SECTRACK">1013852</ref>
      <ref url="http://secunia.com/advisories/15196" source="SECUNIA">15196</ref>
      <ref url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=14&amp;MetaID=1015" source="CONFIRM">http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=14&amp;MetaID=1015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111489411524630&amp;w=2" source="FULLDISC">20050430 DMA[2005-0425a] - 'ESRI ArcGIS 9.x multiple local vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esri" name="arcinfo_workstation">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1394" published="2005-05-03" name="CVE-2005-1394" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt" source="MISC" patch="1">http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt</ref>
      <ref url="http://securitytracker.com/id?1013852" source="SECTRACK" patch="1" adv="1">1013852</ref>
      <ref url="http://secunia.com/advisories/15196" source="SECUNIA" adv="1">15196</ref>
      <ref url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=14&amp;MetaID=1015" source="CONFIRM">http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=14&amp;MetaID=1015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111489411524630&amp;w=2" source="FULLDISC">20050430 DMA[2005-0425a] - 'ESRI ArcGIS 9.x multiple local vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esri" name="arcgis">
        <vers num="9.0" />
      </prod>
      <prod vendor="esri" name="arcinfo_workstation">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1395" published="2005-05-03" name="CVE-2005-1395" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XAPPLRESLANGPATH or (2) XAPPLRESDIR environment variable, or (3) command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15197" source="SECUNIA" patch="1">15197</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033705.html" source="FULLDISC" patch="1">20050501 DMA[2005-0501a] - 'ARPUS/Ce setuid buffer overflow and file overwrite'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0501a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0501a].txt</ref>
      <ref url="http://securitytracker.com/id?1013855" source="SECTRACK">1013855</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1396" published="2005-05-03" name="CVE-2005-1396" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to version 2.6</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16050" source="OSVDB" adv="1">16050</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0501a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0501a].txt</ref>
      <ref url="http://securitytracker.com/id?1013855" source="SECTRACK">1013855</ref>
      <ref url="http://secunia.com/advisories/15197" source="SECUNIA" adv="1">15197</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033705.html" source="FULLDISC">20050501 DMA[2005-0501a] - 'ARPUS/Ce setuid buffer overflow and file overwrite'</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1397" published="2005-05-03" name="CVE-2005-1397" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20297" source="XF" patch="1">php-calendar-searchphp-sql-injection(20297)</ref>
      <ref url="http://www.securityfocus.com/bid/13405" source="BID" patch="1">13405</ref>
      <ref url="http://secunia.com/advisories/15116" source="SECUNIA" patch="1">15116</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0418" source="VUPEN">ADV-2005-0418</ref>
      <ref url="http://www.osvdb.org/15866" source="OSVDB">15866</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=323483" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=323483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-calendar" name="php-calendar">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1398" published="2005-05-03" name="CVE-2005-1398" modified="2009-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters.  NOTE: it was later reported that 3.4 through 4.6.4 are also affected.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/44766" source="XF">phpcart-phpcart-data-manipulation(44766)</ref>
      <ref url="http://www.securityfocus.com/bid/30887" source="BID">30887</ref>
      <ref url="http://www.securityfocus.com/bid/13406" source="BID">13406</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/495806/100/0/threaded" source="BUGTRAQ">20080828 XSS and Data Manipulation attacks found in CMS PHPCart.</ref>
      <ref url="http://www.osvdb.org/15859" source="OSVDB">15859</ref>
      <ref url="http://secunia.com/advisories/15147" source="SECUNIA" adv="1">15147</ref>
      <ref url="http://lostmon.blogspot.com/2005/04/phpcart-price-manipulation.html" source="MISC">http://lostmon.blogspot.com/2005/04/phpcart-price-manipulation.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcart" name="phpcart">
        <vers num="3.2" />
        <vers num="3.4" />
        <vers num="4.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1399" published="2005-05-06" name="CVE-2005-1399" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:06.iir.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-05:06</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.10" />
        <vers num="4.11" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1400" published="2005-05-06" name="CVE-2005-1400" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:07.ldt.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-05:07</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.10" />
        <vers num="4.11" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1401" published="2005-05-03" name="CVE-2005-1401" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.security-focus.com/archive/1/397304" source="BUGTRAQ">20050501 Clients format string and server crash in Mtp-Target 1.2.2</ref>
      <ref url="http://aluigi.altervista.org/adv/mtpbugs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/mtpbugs-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mtp-target" name="mtp-target">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1402" published="2005-05-03" name="CVE-2005-1402" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.security-focus.com/archive/1/397304" source="BUGTRAQ">20050501 Clients format string and server crash in Mtp-Target 1.2.2</ref>
      <ref url="http://aluigi.altervista.org/adv/mtpbugs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/mtpbugs-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mtp-target" name="mtp-target">
        <vers prev="1" num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1403" published="2005-05-03" name="CVE-2005-1403" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13427" source="BID">13427</ref>
      <ref url="http://www.osvdb.org/15894" source="OSVDB" adv="1">15894</ref>
      <ref url="http://securitytracker.com/id?1013836" source="SECTRACK">1013836</ref>
      <ref url="http://secunia.com/advisories/15155" source="SECUNIA" adv="1">15155</ref>
      <ref url="http://lostmon.blogspot.com/2005/04/amazon-webstore-script-injection-and.html" source="MISC">http://lostmon.blogspot.com/2005/04/amazon-webstore-script-injection-and.html</ref>
      <ref url="http://www.osvdb.org/15892" source="OSVDB">15892</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1404" published="2005-05-03" name="CVE-2005-1404" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.org/archive/1/397025" source="BUGTRAQ" patch="1" adv="1">20050426 myPHP Forum v3 (possible v1 &amp; 2 also) Identification 'spoof'</ref>
      <ref url="http://www.osvdb.org/15902" source="OSVDB" patch="1" adv="1">15902</ref>
      <ref url="http://www.securityfocus.com/bid/13430" source="BID">13430</ref>
      <ref url="http://www.osvdb.org/15903" source="OSVDB" adv="1">15903</ref>
      <ref url="http://secunia.com/advisories/15166" source="SECUNIA" adv="1">15166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphp_forum" name="myphp_forum">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1405" published="2005-05-03" name="CVE-2005-1405" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013839" source="SECTRACK" patch="1">1013839</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20045" source="XF">lotus-sethttpheader-injection(20045)</ref>
      <ref url="http://www.osvdb.org/15365" source="OSVDB">15365</ref>
      <ref url="http://secunia.com/advisories/14879" source="SECUNIA" adv="1">14879</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202437" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1406" published="2005-05-06" name="CVE-2005-1406" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:08.kmem.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-05:08</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2256" source="VUPEN">ADV-2005-2256</ref>
      <ref url="http://www.securityfocus.com/bid/15252" source="BID">15252</ref>
      <ref url="http://www.securityfocus.com/bid/13526" source="BID">13526</ref>
      <ref url="http://secunia.com/advisories/17368" source="SECUNIA">17368</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Oct/msg00000.html" source="APPLE">APPLE-SA-2005-10-31</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.1" />
        <vers num="4.10" />
        <vers num="4.11" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1407" published="2005-05-03" name="CVE-2005-1407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.skype.com/security/ssa-2005-01.html" source="CONFIRM" patch="1" adv="1">http://www.skype.com/security/ssa-2005-01.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skype_technologies" name="skype">
        <vers num="1.2.0.0" />
        <vers num="1.2.0.37" />
        <vers num="1.2.0.41" />
        <vers num="1.2.0.46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1408" published="2005-05-26" name="CVE-2005-1408" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI handler in a crafted Keynote presentation.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://remahl.se/david/vuln/016/" source="MISC" patch="1">http://remahl.se/david/vuln/016/</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00005.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-05-25</ref>
      <ref url="http://securitytracker.com/id?1014053" source="SECTRACK">1014053</ref>
      <ref url="http://secunia.com/advisories/15508" source="SECUNIA">15508</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="keynote">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1409" published="2005-05-03" name="CVE-2005-1409" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.postgresql.org/about/news.315" source="CONFIRM" patch="1">http://www.postgresql.org/about/news.315</ref>
      <ref url="http://archives.postgresql.org/pgsql-announce/2005-05/msg00001.php" source="MLIST" patch="1">[pgsql-announce] 20050502 IMPORTANT: two new PostgreSQL security problems found</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0453" source="VUPEN">ADV-2005-0453</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10050" source="OVAL">oval:org.mitre.oval:def:10050</ref>
      <ref url="http://www.securityfocus.com/bid/13476" source="BID">13476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426302/30/6680/threaded" source="FEDORA">FLSA-2006:157366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-433.html" source="REDHAT">RHSA-2005:433</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:676" source="OVAL" sig="1">oval:org.mitre.oval:def:676</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2.1" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.2.5" />
        <vers num="7.2.6" />
        <vers num="7.2.7" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.2" />
        <vers num="7.3.3" />
        <vers num="7.3.4" />
        <vers num="7.3.5" />
        <vers num="7.3.6" />
        <vers num="7.3.7" />
        <vers num="7.3.8" />
        <vers num="7.3.9" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1410" published="2005-05-03" name="CVE-2005-1410" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13475" source="BID" patch="1">13475</ref>
      <ref url="http://www.postgresql.org/about/news.315" source="CONFIRM" patch="1">http://www.postgresql.org/about/news.315</ref>
      <ref url="http://archives.postgresql.org/pgsql-announce/2005-05/msg00001.php" source="MLIST" patch="1">[pgsql-announce] 20050502 IMPORTANT: two new PostgreSQL security problems found</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0453" source="VUPEN">ADV-2005-0453</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9343" source="OVAL">oval:org.mitre.oval:def:9343</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426302/30/6680/threaded" source="FEDORA">FLSA-2006:157366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-433.html" source="REDHAT">RHSA-2005:433</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1086" source="OVAL" sig="1">oval:org.mitre.oval:def:1086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.4" />
        <vers num="7.4.3" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1411" published="2005-05-03" name="CVE-2005-1411" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20321" source="XF" adv="1">icuii-password-disclosure(20321)</ref>
      <ref url="http://www.securityfocus.com/bid/13441" source="BID">13441</ref>
      <ref url="http://www.osvdb.org/14688" source="OSVDB" adv="1">14688</ref>
      <ref url="http://securitytracker.com/id?1013828" source="SECTRACK">1013828</ref>
      <ref url="http://secunia.com/advisories/15171" source="SECUNIA">15171</ref>
      <ref url="http://osvdb.org/ref/14/14688-icuii.txt" source="MISC">http://osvdb.org/ref/14/14688-icuii.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybration" name="icuii">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1412" published="2005-05-03" name="CVE-2005-1412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15967" source="OSVDB" adv="1">15967</ref>
      <ref url="http://secunia.com/advisories/15190" source="SECUNIA" adv="1">15190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecomm" name="professional_guestbook">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1413" published="2005-05-03" name="CVE-2005-1413" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username or (2) password parameters to admin_login.asp, or the (3) searchstring and possibly (4) ID parameters to default.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20313" source="XF">envivo-username-password-sql-injection(20313)</ref>
      <ref url="http://www.securityfocus.com/bid/13440" source="BID">13440</ref>
      <ref url="http://www.securityfocus.com/bid/13439" source="BID">13439</ref>
      <ref url="http://www.securityfocus.com/bid/13437" source="BID">13437</ref>
      <ref url="http://www.osvdb.org/15966" source="OSVDB">15966</ref>
      <ref url="http://www.osvdb.org/15965" source="OSVDB">15965</ref>
      <ref url="http://securitytracker.com/id?1013843" source="SECTRACK">1013843</ref>
      <ref url="http://secunia.com/advisories/15173" source="SECUNIA">15173</ref>
      <ref url="http://digitalparadox.org/viewadvisories.ah?view=37" source="MISC">http://digitalparadox.org/viewadvisories.ah?view=37</ref>
      <ref url="http://www.securityfocus.com/bid/24860" source="BID">24860</ref>
      <ref url="http://www.osvdb.org/15964" source="OSVDB">15964</ref>
      <ref url="http://securityvulns.ru/Rdocument425.html" source="MISC">http://securityvulns.ru/Rdocument425.html</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=118414271202945&amp;w=2" source="FULLDISC">20070711 durito: enVivo!CMS SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="envivosoft" name="envivo_cms">
        <vers num="3.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1414" published="2005-05-03" name="CVE-2005-1414" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13445" source="BID">13445</ref>
      <ref url="http://www.osvdb.org/14685" source="OSVDB" adv="1">14685</ref>
      <ref url="http://securitytracker.com/id?1013823" source="SECTRACK">1013823</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26187" source="XF">filepocket-registry-plaintext-password(26187)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1415" published="2005-05-03" name="CVE-2005-1415" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13454" source="BID" patch="1">13454</ref>
      <ref url="http://www.cuteftp.com/gsftps/history.asp" source="CONFIRM" patch="1">http://www.cuteftp.com/gsftps/history.asp</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-04/0674.html" source="FULLDISC">20050501 Remote buffer overflow in GlobalScape Secure FTP server 3.0.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globalscape" name="secure_ftp_server">
        <vers num="3.0" />
        <vers num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1416" published="2005-05-03" name="CVE-2005-1416" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0448" source="VUPEN">ADV-2005-0448</ref>
      <ref url="http://www.soft3304.net/04WebServer/Security.html" source="CONFIRM">http://www.soft3304.net/04WebServer/Security.html</ref>
      <ref url="http://www.osvdb.org/16067" source="OSVDB">16067</ref>
      <ref url="http://secunia.com/advisories/15230" source="SECUNIA">15230</ref>
      <ref url="http://osvdb.org/ref/16/16067-04webserver.txt" source="MISC">http://osvdb.org/ref/16/16067-04webserver.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="soft3304" name="04webserver">
        <vers num="1.81" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1417" published="2005-05-03" name="CVE-2005-1417" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7) links_rate.asp, (8) pic_rates.asp, (9) article_toprated.asp, (10) dl_toprated.asp, (11) links_toprated.asp, (12) arguments to pic_toprated.asp, or (13) the TOPIC_ID or Forum_ID parameters to custom_link.asp.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vulnerabilities have been partially fixed in versions 1.3.5 and 2.0. The remaining vulnerabilities will reportedly be fixed in the upcoming 2.1 version.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.maxwebportal.info/downloads/mwp_security_fixes.zip" source="CONFIRM" patch="1">http://www.maxwebportal.info/downloads/mwp_security_fixes.zip</ref>
      <ref url="http://www.securityfocus.com/bid/13466" source="BID">13466</ref>
      <ref url="http://securitytracker.com/id?1013845" source="SECTRACK">1013845</ref>
      <ref url="http://secunia.com/advisories/15214" source="SECUNIA">15214</ref>
      <ref url="http://www.maxwebportal.info/topic.asp?TOPIC_ID=2482&amp;FORUM_ID=1&amp;CAT_ID=1&amp;Forum_Title=General+Chat&amp;Topic_Title=Security+Update" source="CONFIRM">http://www.maxwebportal.info/topic.asp?TOPIC_ID=2482&amp;FORUM_ID=1&amp;CAT_ID=1&amp;Forum_Title=General+Chat&amp;Topic_Title=Security+Update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.5" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1418" published="2005-05-03" name="CVE-2005-1418" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20319" source="XF">notjustbrowsing-password-disclosure(20319)</ref>
      <ref url="http://www.securityfocus.com/bid/13442" source="BID">13442</ref>
      <ref url="http://www.osvdb.org/14687" source="OSVDB">14687</ref>
      <ref url="http://securitytracker.com/id?1013826" source="SECTRACK">1013826</ref>
      <ref url="http://secunia.com/advisories/15184" source="SECUNIA">15184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netleaf_limited" name="notjustbrowsing">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1419" published="2005-05-03" name="CVE-2005-1419" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15959" source="OSVDB">15959</ref>
      <ref url="http://securitytracker.com/id?1013833" source="SECTRACK">1013833</ref>
      <ref url="http://secunia.com/advisories/15178" source="SECUNIA" adv="1">15178</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0491.html" source="BUGTRAQ">20050428 [HSC Security Group] Ocean12 Mailing List Manager Pro SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocean12_technologies" name="mailing_list_manager">
        <vers num="1.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1420" published="2005-05-03" name="CVE-2005-1420" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1013860" source="SECTRACK">1013860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raysoft" name="video_cam_server">
        <vers num="1.0.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1421" published="2005-05-03" name="CVE-2005-1421" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1013860" source="SECTRACK">1013860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raysoft" name="video_cam_server">
        <vers num="1.0.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1422" published="2005-05-03" name="CVE-2005-1422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to conduct administrator operations and cause a denial of service (server or camera shutdown) via a direct request to admin.html.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1013860" source="SECTRACK">1013860</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1423" published="2005-05-03" name="CVE-2005-1423" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16069" source="OSVDB">16069</ref>
      <ref url="http://secunia.com/advisories/15231" source="SECUNIA">15231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602lan_suite">
        <vers num="2004.0.05.0413" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1424" published="2005-05-03" name="CVE-2005-1424" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20315" source="XF">gotext-user-information-disclosure(20315)</ref>
      <ref url="http://www.securityfocus.com/bid/13443" source="BID">13443</ref>
      <ref url="http://www.osvdb.org/14686" source="OSVDB" adv="1">14686</ref>
      <ref url="http://securitytracker.com/id?1013825" source="SECTRACK">1013825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stumbleinside" name="gotext">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1425" published="2005-05-03" name="CVE-2005-1425" modified="2010-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20314" source="XF">uapplication-information-disclosure(20314)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456240/100/0/threaded" source="BUGTRAQ">20070107 Uguestbook Remote Password Disclosure Vulnerability</ref>
      <ref url="http://www.osvdb.org/15995" source="OSVDB">15995</ref>
      <ref url="http://securitytracker.com/id?1013830" source="SECTRACK">1013830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uapplication" name="uguestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1426" published="2005-05-03" name="CVE-2005-1426" modified="2010-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20314" source="XF">uapplication-information-disclosure(20314)</ref>
      <ref url="http://www.osvdb.org/15996" source="OSVDB">15996</ref>
      <ref url="http://securitytracker.com/id?1013830" source="SECTRACK">1013830</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1427" published="2005-05-03" name="CVE-2005-1427" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20314" source="XF">uapplication-information-disclosure(20314)</ref>
      <ref url="http://www.osvdb.org/15994" source="OSVDB">15994</ref>
      <ref url="http://securitytracker.com/id?1013830" source="SECTRACK">1013830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uapplication" name="uphotogallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1428" published="2005-05-03" name="CVE-2005-1428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20314" source="XF">uapplication-information-disclosure(20314)</ref>
      <ref url="http://securitytracker.com/id?1013830" source="SECTRACK">1013830</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1429" published="2005-05-03" name="CVE-2005-1429" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13404" source="BID">13404</ref>
      <ref url="http://securitytracker.com/id?1013837" source="SECTRACK">1013837</ref>
      <ref url="http://www.osvdb.org/15968" source="OSVDB">15968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abczone.it" name="wwwguestbook">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1430" published="2005-05-03" name="CVE-2005-1430" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.security-focus.com/archive/1/397306" source="BUGTRAQ">20050501 Insecure pty permissions in OS X &lt; 10.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1431" published="2005-05-03" name="CVE-2005-1431" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20328" source="XF">gnutls-record-parsing-dos(20328)</ref>
      <ref url="http://www.securityfocus.com/bid/13477" source="BID">13477</ref>
      <ref url="http://www.osvdb.org/16054" source="OSVDB">16054</ref>
      <ref url="http://securitytracker.com/id?1013861" source="SECTRACK">1013861</ref>
      <ref url="http://secunia.com/advisories/15193" source="SECUNIA">15193</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9238" source="OVAL">oval:org.mitre.oval:def:9238</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnutls-dev/2005-April/000858.html" source="MLIST">[gnutls-dev] 20050428 GnuTLS 1.2.3 and 1.0.25 </ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-430.html" source="REDHAT">RHSA-2005:430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnutls">
        <vers num="1.0.18" />
        <vers num="1.0.19" />
        <vers num="1.0.20" />
        <vers num="1.0.21" />
        <vers num="1.0.22" />
        <vers num="1.0.23" />
        <vers num="1.0.24" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1433" published="2005-05-03" name="CVE-2005-1433" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15226" source="SECUNIA" patch="1">15226</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMA01141" source="HP">HPSBMA01141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_event_correlation_services">
        <vers num="3.2" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1434" published="2005-05-03" name="CVE-2005-1434" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in OpenView Network Node Manager (OV NNM) 6.2, 6.4, 7.01, and 7.50 allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15223" source="SECUNIA" patch="1">15223</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMA01140" source="HP">HPSBMA01140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="7.01" />
        <vers num="7.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1435" published="2005-05-03" name="CVE-2005-1435" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/forum/message.php?msg_id=3128678" source="CONFIRM" patch="1">http://sourceforge.net/forum/message.php?msg_id=3128678</ref>
      <ref url="http://securitytracker.com/id?1013859" source="SECTRACK" patch="1">1013859</ref>
      <ref url="http://secunia.com/advisories/15225" source="SECUNIA" adv="1">15225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_webmail" name="open_webmail">
        <vers prev="1" num="2.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1436" published="2005-05-03" name="CVE-2005-1436" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php, (4) the e parameter to user_login.php, (5) the err parameter to open_submit.php, or (6) the name and subject fields when adding a ticket.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00071-05022005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00071-05022005</ref>
      <ref url="http://secunia.com/advisories/15216" source="SECUNIA">15216</ref>
      <ref url="http://www.osvdb.org/16274" source="OSVDB">16274</ref>
      <ref url="http://www.osvdb.org/16273" source="OSVDB">16273</ref>
      <ref url="http://www.osvdb.org/16272" source="OSVDB">16272</ref>
      <ref url="http://www.osvdb.org/16271" source="OSVDB">16271</ref>
      <ref url="http://www.osvdb.org/16270" source="OSVDB">16270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket">
        <vers num="1.2.7" />
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1437" published="2005-05-03" name="CVE-2005-1437" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or (2) cat parameter to view.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00071-05022005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00071-05022005</ref>
      <ref url="http://secunia.com/advisories/15216" source="SECUNIA">15216</ref>
      <ref url="http://www.osvdb.org/16277" source="OSVDB">16277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket">
        <vers num="1.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1438" published="2005-05-03" name="CVE-2005-1438" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16278" source="OSVDB">16278</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00071-05022005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00071-05022005</ref>
      <ref url="http://secunia.com/advisories/15216" source="SECUNIA">15216</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1439" published="2005-05-03" name="CVE-2005-1439" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00071-05022005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00071-05022005</ref>
      <ref url="http://secunia.com/advisories/15216" source="SECUNIA">15216</ref>
      <ref url="http://www.osvdb.org/16279" source="OSVDB">16279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1440" published="2005-05-03" name="CVE-2005-1440" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13462" source="BID">13462</ref>
      <ref url="http://www.osvdb.org/15958" source="OSVDB">15958</ref>
      <ref url="http://www.osvdb.org/15957" source="OSVDB">15957</ref>
      <ref url="http://www.osvdb.org/15956" source="OSVDB">15956</ref>
      <ref url="http://www.osvdb.org/15955" source="OSVDB">15955</ref>
      <ref url="http://www.osvdb.org/15954" source="OSVDB">15954</ref>
      <ref url="http://www.osvdb.org/15953" source="OSVDB">15953</ref>
      <ref url="http://www.osvdb.org/15952" source="OSVDB">15952</ref>
      <ref url="http://www.osvdb.org/15951" source="OSVDB" adv="1">15951</ref>
      <ref url="http://securitytracker.com/id?1013853" source="SECTRACK">1013853</ref>
      <ref url="http://secunia.com/advisories/15181" source="SECUNIA">15181</ref>
      <ref url="http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html" source="MISC">http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codetosell" name="viart_shop_enterprise">
        <vers num="2.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1441" published="2005-05-03" name="CVE-2005-1441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202525" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20043" source="XF">lotus-nrpc-format-string(20043)</ref>
      <ref url="http://www.securityfocus.com/bid/13446" source="BID">13446</ref>
      <ref url="http://www.osvdb.org/15366" source="OSVDB">15366</ref>
      <ref url="http://securitytracker.com/id?1013842" source="SECTRACK">1013842</ref>
      <ref url="http://secunia.com/advisories/14879" source="SECUNIA">14879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.2_cf2" />
        <vers num="6.0.3" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1442" published="2005-05-03" name="CVE-2005-1442" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202526" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20044" source="XF">lotus-notesini-bo(20044)</ref>
      <ref url="http://www.securityfocus.com/bid/13447" source="BID">13447</ref>
      <ref url="http://www.osvdb.org/15367" source="OSVDB" adv="1">15367</ref>
      <ref url="http://secunia.com/advisories/1013841" source="SECUNIA">1013841</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1443" published="2005-05-03" name="CVE-2005-1443" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013863" source="SECTRACK">1013863</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1444" published="2005-05-03" name="CVE-2005-1444" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name parameters to main.php, (2) the inadmin, newsev, or postid parameters to 5.php, or (3) the id parameter to 0.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00072-05032005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00072-05032005</ref>
      <ref url="http://secunia.com/advisories/15213" source="SECUNIA" patch="1" adv="1">15213</ref>
      <ref url="http://forum.sitepanel2.com/index.php?showtopic=271" source="MISC">http://forum.sitepanel2.com/index.php?showtopic=271</ref>
      <ref url="http://www.osvdb.org/16264" source="OSVDB">16264</ref>
      <ref url="http://www.osvdb.org/16263" source="OSVDB">16263</ref>
      <ref url="http://www.osvdb.org/16262" source="OSVDB">16262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitepanel" name="sitepanel">
        <vers prev="1" num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1445" published="2005-05-03" name="CVE-2005-1445" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to (1) delete arbitrary files via the id parameter in a rmattach action to 5.php, or (2) read arbitrary files via the lang parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00072-05032005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00072-05032005</ref>
      <ref url="http://secunia.com/advisories/15213" source="SECUNIA" patch="1" adv="1">15213</ref>
      <ref url="http://forum.sitepanel2.com/index.php?showtopic=271" source="MISC">http://forum.sitepanel2.com/index.php?showtopic=271</ref>
      <ref url="http://www.osvdb.org/16266" source="OSVDB">16266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitepanel" name="sitepanel">
        <vers prev="1" num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1446" published="2005-05-03" name="CVE-2005-1446" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to upload and execute arbitrary files such as PHP scripts via an attachment to a trouble ticket.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00072-05032005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00072-05032005</ref>
      <ref url="http://secunia.com/advisories/15213" source="SECUNIA" patch="1" adv="1">15213</ref>
      <ref url="http://forum.sitepanel2.com/index.php?showtopic=271" source="MISC">http://forum.sitepanel2.com/index.php?showtopic=271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitepanel" name="sitepanel">
        <vers prev="1" num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1447" published="2005-05-03" name="CVE-2005-1447" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in main.php in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to execute arbitrary PHP code via the p parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00072-05032005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00072-05032005</ref>
      <ref url="http://secunia.com/advisories/15213" source="SECUNIA" patch="1" adv="1">15213</ref>
      <ref url="http://www.osvdb.org/16268" source="OSVDB">16268</ref>
      <ref url="http://forum.sitepanel2.com/index.php?showtopic=271" source="MISC">http://forum.sitepanel2.com/index.php?showtopic=271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitepanel" name="sitepanel">
        <vers prev="1" num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1448" published="2005-05-03" name="CVE-2005-1448" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13411" source="BID" patch="1">13411</ref>
      <ref url="http://www.s9y.org/63.html#A9" source="CONFIRM" patch="1">http://www.s9y.org/63.html#A9</ref>
      <ref url="http://www.osvdb.org/15876" source="OSVDB" patch="1">15876</ref>
      <ref url="http://secunia.com/advisories/15145" source="SECUNIA" patch="1" adv="1">15145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7_beta1" />
        <vers num="0.7_beta2" />
        <vers num="0.7_beta3" />
        <vers num="0.7_beta4" />
        <vers num="0.7_rc1" />
        <vers num="0.8_beta5" />
        <vers num="0.8_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1449" published="2005-05-03" name="CVE-2005-1449" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.s9y.org/63.html#A9" source="CONFIRM" patch="1">http://www.s9y.org/63.html#A9</ref>
      <ref url="http://secunia.com/advisories/15145" source="SECUNIA" patch="1">15145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5_pl1" />
        <vers num="0.6_pl3" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7_beta1" />
        <vers num="0.7_beta2" />
        <vers num="0.7_beta3" />
        <vers num="0.7_beta4" />
        <vers num="0.7_rc1" />
        <vers num="0.8_beta5" />
        <vers num="0.8_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1450" published="2005-05-03" name="CVE-2005-1450" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.s9y.org/63.html#A9" source="CONFIRM" patch="1">http://www.s9y.org/63.html#A9</ref>
      <ref url="http://secunia.com/advisories/15145" source="SECUNIA" patch="1">15145</ref>
      <ref url="http://www.osvdb.org/15877" source="OSVDB" adv="1">15877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5_pl1" />
        <vers num="0.6_pl3" />
        <vers num="0.7" />
        <vers num="0.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1451" published="2005-05-03" name="CVE-2005-1451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.s9y.org/63.html#A9" source="CONFIRM" patch="1">http://www.s9y.org/63.html#A9</ref>
      <ref url="http://secunia.com/advisories/15145" source="SECUNIA" patch="1">15145</ref>
      <ref url="http://www.osvdb.org/15878" source="OSVDB">15878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5_pl1" />
        <vers num="0.6_pl3" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7_beta1" />
        <vers num="0.7_beta2" />
        <vers num="0.7_beta3" />
        <vers num="0.7_beta4" />
        <vers num="0.7_rc1" />
        <vers num="0.8_beta_5" />
        <vers num="0.8_beta_6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1452" published="2005-05-03" name="CVE-2005-1452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.s9y.org/63.html#A9" source="CONFIRM" patch="1">http://www.s9y.org/63.html#A9</ref>
      <ref url="http://secunia.com/advisories/15145" source="SECUNIA">15145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5_pl1" />
        <vers num="0.6_pl3" />
        <vers num="0.7" />
        <vers num="0.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1453" published="2005-05-05" name="CVE-2005-1453" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://leafnode.sourceforge.net/leafnode-SA-2005-01.txt" source="CONFIRM" patch="1">http://leafnode.sourceforge.net/leafnode-SA-2005-01.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0468" source="VUPEN">ADV-2005-0468</ref>
      <ref url="http://secunia.com/advisories/15252" source="SECUNIA" adv="1">15252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leafnode" name="leafnode">
        <vers num="1.10.0" />
        <vers num="1.11.1" />
        <vers num="1.9.48" />
        <vers num="1.9.52" />
        <vers num="1.9.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1454" published="2005-05-19" name="CVE-2005-1454" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13540" source="BID" patch="1">13540</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200505-13.xml" source="GENTOO" patch="1">GLSA-200505-13</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20449" source="XF">freeradius-xlat-sql-injection(20449)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/May/1013909.html" source="SECTRACK">1013909</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_14_sr.html" source="SUSE">SUSE-SR:2005:014</ref>
      <ref url="http://www.freeradius.org/security.html" source="CONFIRM">http://www.freeradius.org/security.html</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-05/0492.html" source="FULLDISC">20050520 ERRATA: [ GLSA 200505-13 ] FreeRADIUS: SQL injection and Denial of Service vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9610" source="OVAL">oval:org.mitre.oval:def:9610</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-524.html" source="REDHAT">RHSA-2005:524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1455" published="2005-05-19" name="CVE-2005-1455" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13541" source="BID" patch="1">13541</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200505-13.xml" source="GENTOO" patch="1">GLSA-200505-13</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20450" source="XF">freeradius-sqlescapefunc-bo(20450)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/May/1013909.html" source="SECTRACK">1013909</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_14_sr.html" source="SUSE">SUSE-SR:2005:014</ref>
      <ref url="http://www.freeradius.org/security.html" source="CONFIRM">http://www.freeradius.org/security.html</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-05/0492.html" source="FULLDISC">20050520 ERRATA: [ GLSA 200505-13 ] FreeRADIUS: SQL injection and Denial of Service vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9579" source="OVAL">oval:org.mitre.oval:def:9579</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-524.html" source="REDHAT">RHSA-2005:524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1456" published="2005-05-05" name="CVE-2005-1456" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9700" source="OVAL">oval:org.mitre.oval:def:9700</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1457" published="2005-05-05" name="CVE-2005-1457" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9825" source="OVAL">oval:org.mitre.oval:def:9825</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1458" published="2005-05-05" name="CVE-2005-1458" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown "other problems" in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11348" source="OVAL">oval:org.mitre.oval:def:11348</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1459" published="2005-05-05" name="CVE-2005-1459" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11494" source="OVAL">oval:org.mitre.oval:def:11494</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1460" published="2005-05-05" name="CVE-2005-1460" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9970" source="OVAL">oval:org.mitre.oval:def:9970</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1461" published="2005-05-05" name="CVE-2005-1461" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9853" source="OVAL">oval:org.mitre.oval:def:9853</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1462" published="2005-05-05" name="CVE-2005-1462" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9713" source="OVAL">oval:org.mitre.oval:def:9713</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1463" published="2005-05-05" name="CVE-2005-1463" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the (1) DHCP and (2) ANSI A dissectors in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10713" source="OVAL">oval:org.mitre.oval:def:10713</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1464" published="2005-05-05" name="CVE-2005-1464" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9534" source="OVAL">oval:org.mitre.oval:def:9534</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1465" published="2005-05-05" name="CVE-2005-1465" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the NCP dissector in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (long loop).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10224" source="OVAL">oval:org.mitre.oval:def:10224</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1466" published="2005-05-05" name="CVE-2005-1466" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DICOM dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (large memory allocation) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11024" source="OVAL">oval:org.mitre.oval:def:11024</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1467" published="2005-05-05" name="CVE-2005-1467" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9654" source="OVAL">oval:org.mitre.oval:def:9654</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1468" published="2005-05-05" name="CVE-2005-1468" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the (1) WSP, (2) Q.931, (3) H.245, (4) KINK, (5) MGCP, (6) RPC, (7) SMBMailslot, and (8) SMB NETLOGON dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) via unknown vectors that lead to a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID" patch="1">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT" patch="1" adv="1">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA" patch="1" adv="1">FLSA-2006:152922</ref>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10049" source="OVAL">oval:org.mitre.oval:def:10049</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1469" published="2005-05-05" name="CVE-2005-1469" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9598" source="OVAL">oval:org.mitre.oval:def:9598</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1470" published="2005-05-05" name="CVE-2005-1470" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/news/item_20050504_01.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/news/item_20050504_01.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00019.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11804" source="OVAL">oval:org.mitre.oval:def:11804</ref>
      <ref url="http://www.securityfocus.com/bid/13504" source="BID">13504</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-427.html" source="REDHAT">RHSA-2005:427</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963" source="CONECTIVA">CLSA-2005:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1471" published="2005-05-06" name="CVE-2005-1471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15222" source="SECUNIA">15222</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111537013104724&amp;w=2" source="FULLDISC">20050506 [SEC-1 LTD] RSA SecurID Web Agent Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="securid_web_agent">
        <vers num="5" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1472" published="2005-05-19" name="CVE-2005-1472" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00004.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-05-19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1473" published="2005-06-13" name="CVE-2005-1473" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00004.html" source="APPLE" patch="1">APPLE-SA-2005-05-19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1474" published="2005-06-13" name="CVE-2005-1474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13694" source="BID" patch="1">13694</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00004.html" source="APPLE" patch="1">APPLE-SA-2005-05-19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1475" published="2005-06-16" name="CVE-2005-1475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2005-4/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-4/advisory/</ref>
      <ref url="http://secunia.com/advisories/15008" source="SECUNIA" patch="1" adv="1">15008</ref>
      <ref url="http://www.securityfocus.com/bid/13970" source="BID">13970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="8.0_final_build_1095" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1476" published="2005-05-09" name="CVE-2005-1476" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/534710" source="CERT-VN">VU#534710</ref>
      <ref url="http://secunia.com/advisories/15292" source="SECUNIA" patch="1" adv="1">15292</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=293302" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=293302</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=292691" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=292691</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20443" source="XF">mozilla-javascript-code-execution(20443)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0493" source="VUPEN">ADV-2005-0493</ref>
      <ref url="http://www.securityfocus.com/bid/13544" source="BID">13544</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-42.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-42.html</ref>
      <ref url="http://securitytracker.com/id?1013913" source="SECTRACK">1013913</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10045" source="OVAL">oval:org.mitre.oval:def:10045</ref>
      <ref url="http://greyhatsecurity.org/vulntests/ffrc.htm" source="MISC">http://greyhatsecurity.org/vulntests/ffrc.htm</ref>
      <ref url="http://greyhatsecurity.org/firefox.htm" source="MISC">http://greyhatsecurity.org/firefox.htm</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-435.html" source="REDHAT">RHSA-2005:435</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-434.html" source="REDHAT">RHSA-2005:434</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111556301530553&amp;w=2" source="FULLDISC">20050508 Firefox Remote Compromise Technical Details</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111553138007647&amp;w=2" source="FULLDISC">20050508 Firefox Remote Compromise Leaked</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100002" source="OVAL" sig="1">oval:org.mitre.oval:def:100002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1477" published="2005-05-09" name="CVE-2005-1477" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/648758" source="CERT-VN">VU#648758</ref>
      <ref url="http://secunia.com/advisories/15292" source="SECUNIA" patch="1">15292</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=293302" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=293302</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=292691" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=292691</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20443" source="XF">mozilla-javascript-code-execution(20443)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0493" source="VUPEN">ADV-2005-0493</ref>
      <ref url="http://www.securityfocus.com/bid/13544" source="BID">13544</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-42.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-42.html</ref>
      <ref url="http://securitytracker.com/id?1013913" source="SECTRACK">1013913</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9231" source="OVAL">oval:org.mitre.oval:def:9231</ref>
      <ref url="http://greyhatsecurity.org/vulntests/ffrc.htm" source="MISC">http://greyhatsecurity.org/vulntests/ffrc.htm</ref>
      <ref url="http://greyhatsecurity.org/firefox.htm" source="MISC">http://greyhatsecurity.org/firefox.htm</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-435.html" source="REDHAT">RHSA-2005:435</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-434.html" source="REDHAT">RHSA-2005:434</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111556301530553&amp;w=2" source="FULLDISC">20050508 Firefox Remote Compromise Technical Details</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111553138007647&amp;w=2" source="FULLDISC">20050508 Firefox Remote Compromise Leaked</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100001" source="OVAL" sig="1">oval:org.mitre.oval:def:100001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1478" published="2005-05-11" name="CVE-2005-1478" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20414" source="XF">dmail-dsmtpexe-format-string(20414)</ref>
      <ref url="http://www.securityfocus.com/bid/13505" source="BID">13505</ref>
      <ref url="http://www.security.org.sg/vuln/dmail31a.html" source="MISC">http://www.security.org.sg/vuln/dmail31a.html</ref>
      <ref url="http://securitytracker.com/id?1013885" source="SECTRACK">1013885</ref>
      <ref url="http://secunia.com/advisories/15242" source="SECUNIA" adv="1">15242</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531804617905&amp;w=2" source="BUGTRAQ">20050505 dSMTP - SMTP Mail Server 3.1b Linux Remote Root Format String Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="dmail">
        <vers num="3.1a" />
        <vers num="3.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1479" published="2005-05-11" name="CVE-2005-1479" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15219" source="SECUNIA" patch="1">15219</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20371" source="XF">jgsportal-sql-injection(20371)</ref>
      <ref url="http://www.securityfocus.com/bid/13451" source="BID">13451</ref>
      <ref url="http://securitytracker.com/id?1013866" source="SECTRACK">1013866</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627681218415&amp;w=2" source="BUGTRAQ">20050516 [SePro Bugtraq] WBB Portal - JGS-Portal &lt;= 3.0.2 - Multiple Vulnerabilities (09.05.05)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111506870504598&amp;w=2" source="BUGTRAQ">20050430 JGS-Portal 3.0.1 SQL-Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgs-xa" name="jgs-portal">
        <vers prev="1" num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1480" published="2005-05-11" name="CVE-2005-1480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in the urlget site command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15037" source="SECUNIA" patch="1">15037</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20368" source="XF" adv="1">raidenftpd-directory-traversal(20368)</ref>
      <ref url="http://www.securityfocus.com/bid/13292" source="BID">13292</ref>
      <ref url="http://www.osvdb.org/15713" source="OSVDB">15713</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111507556127582&amp;w=2" source="BUGTRAQ">20050502 Directory Traversal Vuln - RaidenFTPD 2.4 &lt; Build 2241</ref>
      <ref url="http://forum.raidenftpd.com/showflat.php?Board=UBB13&amp;Number=45685" source="CONFIRM">http://forum.raidenftpd.com/showflat.php?Board=UBB13&amp;Number=45685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raiden_professional_servers" name="raidenftpd">
        <vers prev="1" num="2.4.2240" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1481" published="2005-05-11" name="CVE-2005-1481" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Aaron Outpost ASP Inline Corporate Calendar allow remote attackers to execute arbitrary SQL commands via the Event_ID parameter to (1) defer.asp or (2) details.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20416" source="XF">asp-inline-corporate-calendar-sql-injection(20416)</ref>
      <ref url="http://securitytracker.com/id?1013884" source="SECTRACK">1013884</ref>
      <ref url="http://secunia.com/advisories/15239" source="SECUNIA">15239</ref>
      <ref url="http://www.osvdb.org/16193" source="OSVDB">16193</ref>
      <ref url="http://www.osvdb.org/16192" source="OSVDB">16192</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530675909673&amp;w=2" source="BUGTRAQ">20050503 [HSC Security Group] ASP Inline Corporate Calendar SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aaronoutpost" name="asp_inline_corporate_calendar">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1482" published="2005-05-11" name="CVE-2005-1482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20431" source="XF">articlelive-bypass-security(20431)</ref>
      <ref url="http://www.securityfocus.com/bid/13493" source="BID" adv="1">13493</ref>
      <ref url="http://www.digitalparadox.org/advisories/inal.txt" source="MISC">http://www.digitalparadox.org/advisories/inal.txt</ref>
      <ref url="http://securitytracker.com/id?1013895" source="SECTRACK" adv="1">1013895</ref>
      <ref url="http://secunia.com/advisories/15250" source="SECUNIA">15250</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530871724865&amp;w=2" source="BUGTRAQ">20050503 Authentication bypass, sql injections and xss in ArticleLive 2005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interspire" name="articlelive">
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1483" published="2005-05-11" name="CVE-2005-1483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5) BlogId parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20430" source="XF">articlelive-multiple-xss(20430)</ref>
      <ref url="http://www.securityfocus.com/bid/13493" source="BID">13493</ref>
      <ref url="http://securitytracker.com/id?1013895" source="SECTRACK">1013895</ref>
      <ref url="http://secunia.com/advisories/15250" source="SECUNIA">15250</ref>
      <ref url="http://www.osvdb.org/16183" source="OSVDB">16183</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530871724865&amp;w=2" source="BUGTRAQ">20050503 Authentication bypass, sql injections and xss in ArticleLive 2005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interspire" name="articlelive">
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1484" published="2005-05-11" name="CVE-2005-1484" modified="2009-06-08" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Golden FTP server pro 2.52 allows remote attackers to read arbitrary files via a "\.." (backward slash dot dot) with a leading '"' (double quote) in the GET command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20668" source="XF">goldenftp-dotdot-directory-traversal(20668)</ref>
      <ref url="http://www.securityfocus.com/bid/13479" source="BID">13479</ref>
      <ref url="http://secunia.com/advisories/15175" source="SECUNIA">15175</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530871716145&amp;w=2" source="BUGTRAQ">20050504 Golden Ftp Server Pro - Directory Traversal Vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kmint21_software" name="golden_ftp_server">
        <vers num="1.00b" />
        <vers num="1.20b" />
        <vers num="1.30b" />
        <vers num="1.31b" />
        <vers num="1.92" />
        <vers num="2.0.2b" />
        <vers num="2.0.5b" />
        <vers num="2.10" />
        <vers num="2.16" />
        <vers num="2.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1485" published="2005-05-11" name="CVE-2005-1485" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Golden FTP Server Pro allows 2.52 allows remote attackers to obtain sensitive information via a GET request for a file that does not exist, which reveals the absolute path of the FTP server in the resulting FTP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20674" source="XF">goldenftp-information-disclosure(20674)</ref>
      <ref url="http://secunia.com/advisories/15175/" source="SECUNIA">15175</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530871716145&amp;w=2" source="BUGTRAQ">20050504 Golden Ftp Server Pro - Directory Traversal Vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kmint21_software" name="golden_ftp_server">
        <vers num="2.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1486" published="2005-05-11" name="CVE-2005-1486" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php.  NOTE: the vendor was not able to reproduce some of the reported vectors but believes that they have been addressed.  The original researcher is known to be unreliable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20384" source="XF">fishcart-multiple-xss(20384)</ref>
      <ref url="http://www.securityfocus.com/bid/13499" source="BID">13499</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457754/100/200/threaded" source="BUGTRAQ">20070123 Re: Multiple SQL injections and XSS in FishCart 3.1</ref>
      <ref url="http://www.osvdb.org/16281" source="OSVDB">16281</ref>
      <ref url="http://www.osvdb.org/16280" source="OSVDB">16280</ref>
      <ref url="http://www.fishcart.org/archives/200505/msg00028.html" source="MLIST">[fishcart] 20050521 Re: Concerned about security</ref>
      <ref url="http://www.digitalparadox.org/advisories/fishc.txt" source="MISC">http://www.digitalparadox.org/advisories/fishc.txt</ref>
      <ref url="http://secunia.com/advisories/15232/" source="SECUNIA" adv="1">15232</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530799109755&amp;w=2" source="BUGTRAQ">20050504 Multiple SQL injections and XSS in FishCart 3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fishnet" name="fishcart">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1487" published="2005-05-11" name="CVE-2005-1487" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php.  NOTE: the vendor disputes this report, saying that they are forced SQL errors.  The original researcher is known to be unreliable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20386" source="XF">fishcart-multiple-sql-injection(20386)</ref>
      <ref url="http://www.securityfocus.com/bid/13499" source="BID">13499</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457754/100/200/threaded" source="BUGTRAQ">20070123 Re: Multiple SQL injections and XSS in FishCart 3.1</ref>
      <ref url="http://www.osvdb.org/16283" source="OSVDB">16283</ref>
      <ref url="http://www.osvdb.org/16282" source="OSVDB">16282</ref>
      <ref url="http://www.digitalparadox.org/advisories/fishc.txt" source="MISC" adv="1">http://www.digitalparadox.org/advisories/fishc.txt</ref>
      <ref url="http://secunia.com/advisories/15232/" source="SECUNIA">15232</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530799109755&amp;w=2" source="BUGTRAQ">20050504 Multiple SQL injections and XSS in FishCart 3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fishnet" name="fishcart">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1488" published="2005-05-11" name="CVE-2005-1488" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.html, (2) addressaction.html, (3) the Signature field to settings.html, or (4) the Shared calendars to calendarsettings.html.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20467" source="XF">merak-icewarp-script-xss(20467)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530933016434&amp;w=2" source="BUGTRAQ">20050504 Multiple vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.4.2" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="8.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1489" published="2005-05-11" name="CVE-2005-1489" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15249" source="SECUNIA" patch="1">15249</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20469" source="XF">merak-icewarp-script-path-disclosure(20469)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530933016434&amp;w=2" source="BUGTRAQ">20050504 Multiple vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.4.2" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="8.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1490" published="2005-05-11" name="CVE-2005-1490" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20472" source="XF">merak-icewarp-file-existence(20472)</ref>
      <ref url="http://secunia.com/advisories/15249" source="SECUNIA">15249</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530933016434&amp;w=2" source="BUGTRAQ">20050504 Multiple vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.4.2" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="8.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1491" published="2005-05-11" name="CVE-2005-1491" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20471" source="XF">merak-icewarp-directory-relocation(20471)</ref>
      <ref url="http://secunia.com/advisories/15249" source="SECUNIA">15249</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530933016434&amp;w=2" source="BUGTRAQ">20050504 Multiple vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.4.2" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="8.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1492" published="2005-05-11" name="CVE-2005-1492" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013891" source="SECTRACK" patch="1">1013891</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20415" source="XF">links-usercgi-addcgi-xss(20415)</ref>
      <ref url="http://www.securityfocus.com/bid/13484" source="BID">13484</ref>
      <ref url="http://www.osvdb.org/16189" source="OSVDB">16189</ref>
      <ref url="http://www.gossamer-threads.com/forum/Gossamer_Links_3.0.1_Released_P280986/" source="CONFIRM" adv="1">http://www.gossamer-threads.com/forum/Gossamer_Links_3.0.1_Released_P280986/</ref>
      <ref url="http://secunia.com/advisories/15253" source="SECUNIA">15253</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531023916998&amp;w=2" source="BUGTRAQ">20050504 Gossamer Threads Links SQL login XSS Vulnerability</ref>
      <ref url="http://gossamer-threads.com/perl/gforum/gforum.cgi?post=281029;" source="CONFIRM" adv="1">http://gossamer-threads.com/perl/gforum/gforum.cgi?post=281029;</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gossamer_threads" name="gossamer_threads_links">
        <vers num="2.0" />
        <vers num="2.2.0" />
      </prod>
      <prod vendor="gossamer_threads" name="gossamer_threads_links-sql">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1493" published="2005-05-11" name="CVE-2005-1493" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/alerts/2005/May/1013888.html" source="SECTRACK" patch="1">1013888</ref>
      <ref url="http://www.securityfocus.com/bid/13495" source="BID" patch="1">13495</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/SimpleCam1.2-adv.txt" source="MISC" patch="1">http://www.autistici.org/fdonato/advisory/SimpleCam1.2-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20411" source="XF">simplecam-dotdot-directory-traversal(20411)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531466319161&amp;w=2" source="BUGTRAQ">20050504 directory traversal in SimpleCam 1.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dead_pirate_software" name="simplecam">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1494" published="2005-05-11" name="CVE-2005-1494" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20669" source="XF">megabook-admincgi-xss(20669)</ref>
      <ref url="http://www.securityfocus.com/bid/13522" source="BID">13522</ref>
      <ref url="http://www.securityfocus.com/archive/1/397809" source="BUGTRAQ">20050508 Re: MegaBook V2.0 - Cross Site Scripting Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531609618182&amp;w=2" source="BUGTRAQ">20050505 MegaBook V2.0 - Cross Site Scripting Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="megabook" name="megabook">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1495" published="2005-05-11" name="CVE-2005-1495" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.</descript>
    </desc>
    <sols>
      <sol source="nvd">Applying patchset 10.1.0.4 is fixing this issue for Oracle 10g. Oracle 9i is still vulnerable.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/777773" source="CERT-VN" adv="1">VU#777773</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20407" source="XF" adv="1">oracle-audit-data-manipulation(20407)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle-fine-grained-auditing-issue.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle-fine-grained-auditing-issue.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531683824209&amp;w=2" source="BUGTRAQ">20050505 Oracle 9i / 10g Fine Grained Auditing Issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.0.2" />
        <vers num="10.1.0.3" />
        <vers num="10.1.0.3.1" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_10.1.0.3" />
        <vers num="enterprise_10.1.0.3.1" />
        <vers num="personal_10.1.0.2" />
        <vers num="personal_10.1.0.3" />
        <vers num="personal_10.1.0.3.1" />
        <vers num="standard_10.1.0.2" />
        <vers num="standard_10.1.0.3" />
        <vers num="standard_10.1.0.3.1" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.0.1.2" />
        <vers num="9.0.1.3" />
        <vers num="9.0.1.4" />
        <vers num="9.0.2" />
        <vers num="9.2.0.1" />
        <vers num="9.2.0.2" />
        <vers num="release_2_9.2.1" />
        <vers num="release_2_9.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1496" published="2005-05-11" name="CVE-2005-1496" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.</descript>
    </desc>
    <sols>
      <sol source="nvd">Applying patchset 10.1.0.4 is fixing this issue.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.red-database-security.com/exploits/oracle_exploit_dbms_scheduler_select_user.html" source="MISC" patch="1">http://www.red-database-security.com/exploits/oracle_exploit_dbms_scheduler_select_user.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20410" source="XF">oracle10g-gain-privileges(20410)</ref>
      <ref url="http://www.securityfocus.com/bid/13509" source="BID" adv="1">13509</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531740305049&amp;w=2" source="BUGTRAQ">20050505 Oracle 10g DBMS_SCHEDULER SESSION_USER issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.0.2" />
        <vers num="10.1.0.3" />
        <vers num="10.1.0.3.1" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_10.1.0.3" />
        <vers num="enterprise_10.1.0.3.1" />
        <vers num="personal_10.1.0.2" />
        <vers num="personal_10.1.0.3" />
        <vers num="personal_10.1.0.3.1" />
        <vers num="standard_10.1.0.2" />
        <vers num="standard_10.1.0.3" />
        <vers num="standard_10.1.0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1497" published="2005-05-11" name="CVE-2005-1497" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20433" source="XF" adv="1">mybloggie-postid-path-disclosure(20433)</ref>
      <ref url="http://mywebland.com/forums/viewtopic.php?t=180" source="MISC">http://mywebland.com/forums/viewtopic.php?t=180</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531904608224&amp;w=2" source="BUGTRAQ">20050505 Multiple vulnerabilities in myBloggie 2.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1498" published="2005-05-11" name="CVE-2005-1498" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which are not properly sanitized before they are displayed in an error message.  NOTE: issues 2, 3, and 4 may be due to a problem in associated products rather than myBloggie itself.</descript>
    </desc>
    <sols>
      <sol source="nvd">Download newest myBloggie from http://mywebland.com/</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20436" source="XF">mybloggie-script-injection(20436)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20434" source="XF">mybloggie-viewmodephp-xss(20434)</ref>
      <ref url="http://www.securityfocus.com/bid/13507" source="BID">13507</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531904608224&amp;w=2" source="BUGTRAQ">20050505 Multiple vulnerabilities in myBloggie 2.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1499" published="2005-05-11" name="CVE-2005-1499" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">delcomment.php in myBloggie 2.1.1 allows remote attackers to delete arbitrary comments by modifying the comment_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20437" source="XF" adv="1">mybloggie-delcomment-bypass-security(20437)</ref>
      <ref url="http://www.securityfocus.com/bid/13507" source="BID" adv="1">13507</ref>
      <ref url="http://secunia.com/advisories/14980" source="SECUNIA">14980</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531904608224&amp;w=2" source="BUGTRAQ">20050505 Multiple vulnerabilities in myBloggie 2.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1500" published="2005-05-11" name="CVE-2005-1500" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the cat_id parameter in viewcat mode, the (4) month_no or (5) year parameter in viewmonth mode, or (6) post_id parameter in viewid mode to index.php.  NOTE: item (1) was discovered to affect 2.1.3 as well.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20439" source="XF">mybloggie-sql-injection(20439)</ref>
      <ref url="http://www.securityfocus.com/bid/15017" source="BID">15017</ref>
      <ref url="http://www.securityfocus.com/bid/13507" source="BID">13507</ref>
      <ref url="http://secunia.com/advisories/14980" source="SECUNIA" adv="1">14980</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722848308367&amp;w=2" source="BUGTRAQ">20050527 SQL Injection Exploit for myBloggie 2.1.1 - 2.1.2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531904608224&amp;w=2" source="BUGTRAQ">20050505 Multiple vulnerabilities in myBloggie 2.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.1" />
        <vers num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1501" published="2005-05-11" name="CVE-2005-1501" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MidiCart PHP Shopping Cart allows remote attackers to obtain sensitive information via a direct request to (1) search_list.php, (2) item_list.php, or (3) item_show.php, which reveal the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20425" source="XF">midicart-path-disclosure(20425)</ref>
      <ref url="http://www.osvdb.org/16172" source="OSVDB">16172</ref>
      <ref url="http://www.hackgen.org/advisories/hackgen-2005-004.txt" source="MISC">http://www.hackgen.org/advisories/hackgen-2005-004.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111533057918993&amp;w=2" source="BUGTRAQ">20050505 [hackgen-2005-#004] - Multiple bugs in MidiCart PHP Shopping Cart</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midicart_software" name="midicart_php_shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1502" published="2005-05-11" name="CVE-2005-1502" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) searchstring parameter to search_list.php or the (2) secondgroup or (3) maingroup parameters to item_list.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20427" source="XF">midicart-xss(20427)</ref>
      <ref url="http://www.securityfocus.com/bid/13518" source="BID">13518</ref>
      <ref url="http://www.securityfocus.com/bid/13517" source="BID">13517</ref>
      <ref url="http://www.securityfocus.com/bid/13516" source="BID">13516</ref>
      <ref url="http://www.osvdb.org/16174" source="OSVDB">16174</ref>
      <ref url="http://www.osvdb.org/16173" source="OSVDB">16173</ref>
      <ref url="http://www.hackgen.org/advisories/hackgen-2005-004.txt" source="MISC">http://www.hackgen.org/advisories/hackgen-2005-004.txt</ref>
      <ref url="http://secunia.com/advisories/15269" source="SECUNIA">15269</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111533057918993&amp;w=2" source="BUGTRAQ">20050505 [hackgen-2005-#004] - Multiple bugs in MidiCart PHP Shopping Cart</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midicart_software" name="midicart_php_shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1503" published="2005-05-11" name="CVE-2005-1503" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring parameter to search_list.php, the (2) maingroup or (3) secondgroup parameters to item_list.php, or (4) code_no parameter to item_show.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20428" source="XF">midicart-sql-injection(20428)</ref>
      <ref url="http://www.securityfocus.com/bid/13515" source="BID">13515</ref>
      <ref url="http://www.securityfocus.com/bid/13514" source="BID">13514</ref>
      <ref url="http://www.securityfocus.com/bid/13513" source="BID">13513</ref>
      <ref url="http://www.securityfocus.com/bid/13512" source="BID">13512</ref>
      <ref url="http://www.osvdb.org/16177" source="OSVDB">16177</ref>
      <ref url="http://www.osvdb.org/16176" source="OSVDB">16176</ref>
      <ref url="http://www.osvdb.org/16175" source="OSVDB">16175</ref>
      <ref url="http://www.hackgen.org/advisories/hackgen-2005-004.txt" source="MISC" adv="1">http://www.hackgen.org/advisories/hackgen-2005-004.txt</ref>
      <ref url="http://secunia.com/advisories/15269" source="SECUNIA">15269</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111533057918993&amp;w=2" source="BUGTRAQ">20050505 [hackgen-2005-#004] - Multiple bugs in MidiCart PHP Shopping Cart</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1504" published="2005-05-11" name="CVE-2005-1504" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20422" source="XF">gamespy-sdk-cdkey-gain-access(20422)</ref>
      <ref url="http://secunia.com/advisories/15254/" source="SECUNIA">15254</ref>
      <ref url="http://aluigi.altervista.org/adv/gskeyinuse-adv.txt" source="MISC">http://aluigi.altervista.org/adv/gskeyinuse-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539740212818&amp;w=2" source="BUGTRAQ">20050504 Gamespy cd-key validation system: Cd-key never in use</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamespy" name="cd-key_validation_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1505" published="2005-05-11" name="CVE-2005-1505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The new account wizard in Mail.app 2.0 in Mac OS 10.4, when configuring an IMAP mail account and checking the credentials, does not prompt the user to use SSL until after the password has already been sent, which causes the password to be sent in plaintext.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20670" source="XF">mailapp-account-wizard-plaintext-password(20670)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539448630095&amp;w=2" source="BUGTRAQ">20050504 Mac OS 10.4: new-account-wizzard in Mail 2.0 sends clear-text passwords</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1506" published="2005-05-11" name="CVE-2005-1506" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in out.php in CJ Ultra (CJUltra) Plus 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via the perm parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15281" source="SECUNIA">15281</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539589013911&amp;w=2" source="BUGTRAQ">20050505 Sql Injection in CJ Ultra Plus v1.0.3-1.0.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cj" name="ultra_plus">
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1507" published="2005-05-11" name="CVE-2005-1507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20478" source="XF">4d-webstar-plugin-bo(20478)</ref>
      <ref url="http://www.securityfocus.com/bid/13538" source="BID">13538</ref>
      <ref url="http://www.osvdb.org/16154" source="OSVDB">16154</ref>
      <ref url="http://secunia.com/advisories/15278" source="SECUNIA">15278</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111541709402784&amp;w=2" source="BUGTRAQ">20050506 4d WebSTAR 5.x Web Server Mac OS X Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="5.3.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1508" published="2005-05-11" name="CVE-2005-1508" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) month or (2) annee parameters to the news module, (3) nbractif or (4) annee parameters to the stats module, (5) id parameter to profil.php, (6) mb_lettre or (7) lettre parameter to memberlist.php, or (8) chaine_search, or (9) auteur_search parameter to the recherche module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20500" source="XF">pwsphp-mulitple-scripts-xss(20500)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0503" source="VUPEN">ADV-2005-0503</ref>
      <ref url="http://www.osvdb.org/16232" source="OSVDB">16232</ref>
      <ref url="http://www.osvdb.org/16231" source="OSVDB">16231</ref>
      <ref url="http://www.osvdb.org/16230" source="OSVDB">16230</ref>
      <ref url="http://www.osvdb.org/16229" source="OSVDB">16229</ref>
      <ref url="http://www.osvdb.org/16228" source="OSVDB">16228</ref>
      <ref url="http://secunia.com/advisories/15315" source="SECUNIA" adv="1">15315</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2" source="BUGTRAQ">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwsphp" name="pwsphp">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1509" published="2005-05-11" name="CVE-2005-1509" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profil.php in PwsPHP 1.2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20501" source="XF">pwsphp-id-sql-injection(20501)</ref>
      <ref url="http://www.securityfocus.com/bid/13563" source="BID">13563</ref>
      <ref url="http://www.osvdb.org/16233" source="OSVDB">16233</ref>
      <ref url="http://secunia.com/advisories/15315" source="SECUNIA">15315</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2" source="BUGTRAQ">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwsphp" name="pwsphp">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1510" published="2005-05-11" name="CVE-2005-1510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16234" source="OSVDB">16234</ref>
      <ref url="http://secunia.com/advisories/15315" source="SECUNIA">15315</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2" source="BUGTRAQ">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwsphp" name="pwsphp">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1511" published="2005-05-11" name="CVE-2005-1511" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PwsPHP 1.2.2 allows remote attackers to bypass authentication and post arbitrary comments via the Pseudo cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20503" source="XF">pwsphp-cookie-spoof-identity(20503)</ref>
      <ref url="http://www.osvdb.org/16235" source="OSVDB">16235</ref>
      <ref url="http://secunia.com/advisories/15315" source="SECUNIA">15315</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2" source="BUGTRAQ">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwsphp" name="pwsphp">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1512" published="2005-05-11" name="CVE-2005-1512" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly execute arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20508" source="XF">pwsphp-admin-panel-file-upload(20508)</ref>
      <ref url="http://www.osvdb.org/16236" source="OSVDB">16236</ref>
      <ref url="http://secunia.com/advisories/15315" source="SECUNIA" adv="1">15315</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2" source="BUGTRAQ">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwsphp" name="pwsphp">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1513" published="2005-05-11" name="CVE-2005-1513" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html" source="MISC">http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html</ref>
      <ref url="http://securitytracker.com/id?1013911" source="SECTRACK">1013911</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0101.html" source="FULLDISC">20050506 64 bit qmail fun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dan_bernstein" name="qmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1514" published="2005-05-11" name="CVE-2005-1514" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">commands.c in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SMTP command without a space character, which causes an array to be referenced with a negative index.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html" source="MISC">http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html</ref>
      <ref url="http://securitytracker.com/id?1013911" source="SECTRACK">1013911</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0101.html" source="FULLDISC">20050506 64 bit qmail fun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dan_bernstein" name="qmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1515" published="2005-05-11" name="CVE-2005-1515" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer signedness error in the qmail_put and substdio_put functions in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of SMTP RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html" source="MISC">http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html</ref>
      <ref url="http://securitytracker.com/id?1013911" source="SECTRACK">1013911</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0101.html" source="FULLDISC">20050506 64 bit qmail fun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dan_bernstein" name="qmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1516" published="2005-05-11" name="CVE-2005-1516" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20412" source="XF" adv="1">dmail-dlist-bypass-authentication(20412)</ref>
      <ref url="http://www.securityfocus.com/bid/13497" source="BID" adv="1">13497</ref>
      <ref url="http://www.security.org.sg/vuln/dmail31a.html" source="MISC">http://www.security.org.sg/vuln/dmail31a.html</ref>
      <ref url="http://secunia.com/advisories/15242" source="SECUNIA" adv="1">15242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="dmail">
        <vers num="3.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1517" published="2005-05-11" name="CVE-2005-1517" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0527" source="VUPEN">ADV-2005-0527</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050511-url.shtml" source="CISCO">20050511 FWSM URL Filtering Solution TCP ACL Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers prev="1" num="2.3(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1518" published="2005-05-11" name="CVE-2005-1518" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57786-1" source="SUNALERT" patch="1" adv="1">57786</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0517" source="VUPEN">ADV-2005-0517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1519" published="2005-05-11" name="CVE-2005-1519" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-dns_query" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-dns_query</ref>
      <ref url="http://secunia.com/advisories/15294" source="SECUNIA" patch="1">15294</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0521" source="VUPEN">ADV-2005-0521</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html" source="FEDORA">FEDORA-2005-373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9976" source="OVAL">oval:org.mitre.oval:def:9976</ref>
      <ref url="http://www.securityfocus.com/bid/13592" source="BID">13592</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-489.html" source="REDHAT">RHSA-2005:489</ref>
      <ref url="http://www.debian.org/security/2005/dsa-751" source="DEBIAN">DSA-751</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers prev="1" num="2.5_stable9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1520" published="2005-05-26" name="CVE-2005-1520" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-mail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13766" source="BID" patch="1">13766</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=249&amp;type=vulnerabilities" source="IDEFENSE" patch="1">20050525 GNU Mailutils 0.6 mail header_get_field_name() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.debian.org/security/2005/dsa-732" source="DEBIAN">DSA-732</ref>
      <ref url="http://securitytracker.com/id?1014052" source="SECTRACK">1014052</ref>
      <ref url="http://secunia.com/advisories/15442" source="SECUNIA" adv="1">15442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailutils">
        <vers num="0.5" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1521" published="2005-05-26" name="CVE-2005-1521" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the fetch_io function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a partial message request with a large value in the END parameter, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13763" source="BID" patch="1">13763</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=248&amp;type=vulnerabilities" source="IDEFENSE" patch="1">20050525 GNU Mailutils 0.6 imap4d fetch_io Heap overflow Vulnerability</ref>
      <ref url="http://www.debian.org/security/2005/dsa-732" source="DEBIAN">DSA-732</ref>
      <ref url="http://securitytracker.com/id?1014052" source="SECTRACK">1014052</ref>
      <ref url="http://secunia.com/advisories/15442" source="SECUNIA" adv="1">15442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailutils">
        <vers num="0.5" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1522" published="2005-05-26" name="CVE-2005-1522" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13765" source="BID" patch="1">13765</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=247&amp;type=vulnerabilities" source="IDEFENSE" patch="1">20050525 GNU Mailutils 0.6 imap4d FETCH Commad Resource Consumption DoS Vulnerability</ref>
      <ref url="http://www.debian.org/security/2005/dsa-732" source="DEBIAN">DSA-732</ref>
      <ref url="http://securitytracker.com/id?1014052" source="SECTRACK">1014052</ref>
      <ref url="http://secunia.com/advisories/15442" source="SECUNIA" adv="1">15442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailutils">
        <vers num="0.5" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1523" published="2005-05-26" name="CVE-2005-1523" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13764" source="BID" patch="1">13764</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=246&amp;type=vulnerabilities" source="IDEFENSE" patch="1">20050525 GNU Mailutils 0.6 imap4d Format String Vulnerability</ref>
      <ref url="http://www.debian.org/security/2005/dsa-732" source="DEBIAN">DSA-732</ref>
      <ref url="http://securitytracker.com/id?1014052" source="SECTRACK">1014052</ref>
      <ref url="http://secunia.com/advisories/15442" source="SECUNIA" adv="1">15442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailutils">
        <vers num="0.5" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1524" published="2005-06-22" name="CVE-2005-1524" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library_path] parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=265&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" patch="1" adv="1">20050622 Multiple Vendor Cacti Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-20</ref>
      <ref url="http://www.cacti.net/release_notes_0_8_6e.php" source="CONFIRM" patch="1" adv="1">http://www.cacti.net/release_notes_0_8_6e.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21118" source="XF">cacti-topgraphheader-file-include(21118)</ref>
      <ref url="http://www.osvdb.org/17426" source="OSVDB">17426</ref>
      <ref url="http://www.debian.org/security/2005/dsa-764" source="DEBIAN">DSA-764</ref>
      <ref url="http://securitytracker.com/id?1014252" source="SECTRACK">1014252</ref>
      <ref url="http://secunia.com/advisories/16136" source="SECUNIA">16136</ref>
      <ref url="http://secunia.com/advisories/15931" source="SECUNIA">15931</ref>
      <ref url="http://secunia.com/advisories/15490" source="SECUNIA">15490</ref>
      <ref url="http://distro.conectiva.com/atualizacoes/index.php?id=a&amp;anuncio=000978" source="CONECTIVA">CLSA-2005:978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.8a" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5a" />
        <vers prev="1" num="0.8.6d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1525" published="2005-06-22" name="CVE-2005-1525" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=267&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" patch="1" adv="1">20050622 Multiple Vendor Cacti Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-20</ref>
      <ref url="http://www.cacti.net/release_notes_0_8_6e.php" source="CONFIRM" patch="1" adv="1">http://www.cacti.net/release_notes_0_8_6e.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21120" source="XF">cacti-configsettings-sql-injection(21120)</ref>
      <ref url="http://www.securityfocus.com/bid/14027" source="BID">14027</ref>
      <ref url="http://www.osvdb.org/17424" source="OSVDB">17424</ref>
      <ref url="http://www.debian.org/security/2005/dsa-764" source="DEBIAN">DSA-764</ref>
      <ref url="http://securitytracker.com/id?1014252" source="SECTRACK">1014252</ref>
      <ref url="http://secunia.com/advisories/15931" source="SECUNIA">15931</ref>
      <ref url="http://secunia.com/advisories/15490" source="SECUNIA">15490</ref>
      <ref url="http://distro.conectiva.com/atualizacoes/index.php?id=a&amp;anuncio=000978" source="CONECTIVA">CLSA-2005:978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.8a" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5a" />
        <vers prev="1" num="0.8.6d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1526" published="2005-06-22" name="CVE-2005-1526" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=266&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050622 Multiple Vendor Cacti config_settings.php Remote Code Execution Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-20</ref>
      <ref url="http://www.cacti.net/release_notes_0_8_6e.php" source="CONFIRM" patch="1" adv="1">http://www.cacti.net/release_notes_0_8_6e.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21119" source="XF">cacti-configsettings-file-include(21119)</ref>
      <ref url="http://www.securityfocus.com/bid/14028" source="BID">14028</ref>
      <ref url="http://www.osvdb.org/17425" source="OSVDB">17425</ref>
      <ref url="http://www.debian.org/security/2005/dsa-764" source="DEBIAN">DSA-764</ref>
      <ref url="http://securitytracker.com/id?1014252" source="SECTRACK">1014252</ref>
      <ref url="http://secunia.com/advisories/15931" source="SECUNIA">15931</ref>
      <ref url="http://secunia.com/advisories/15490" source="SECUNIA">15490</ref>
      <ref url="http://distro.conectiva.com/atualizacoes/index.php?id=a&amp;anuncio=000978" source="CONECTIVA">CLSA-2005:978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.8a" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5a" />
        <vers prev="1" num="0.8.6d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1527" published="2005-08-15" name="CVE-2005-1527" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21769" source="XF" patch="1">awstats-eval-execute-commands(21769)</ref>
      <ref url="http://www.osvdb.org/18696" source="OSVDB" patch="1">18696</ref>
      <ref url="http://securitytracker.com/id?1014636" source="SECTRACK" patch="1">1014636</ref>
      <ref url="http://secunia.com/advisories/16412" source="SECUNIA" patch="1" adv="1">16412</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-167-1" source="UBUNTU" adv="1">USN-167-1</ref>
      <ref url="http://www.securityfocus.com/bid/14525" source="BID">14525</ref>
      <ref url="http://www.securiteam.com/unixfocus/5DP0J00GKE.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/5DP0J00GKE.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=290&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20050809 AWStats ShowInfoURL Remote Command Execution Vulnerability</ref>
      <ref url="http://www.debian.org/security/2005/dsa-892" source="DEBIAN">DSA-892</ref>
      <ref url="http://secunia.com/advisories/17463" source="SECUNIA">17463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.7" />
        <vers num="5.8" />
        <vers num="5.9" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="5.04" edition="" />
        <vers num="5.04" edition=":i386" />
        <vers num="5.04" edition=":amd64" />
        <vers num="5.04" edition=":powerpc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1528" published="2005-12-31" name="CVE-2005-1528" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0474" source="VUPEN">ADV-2006-0474</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=379" source="IDEFENSE" adv="1">20060207 QNX Neutrino RTOS crttrap Arbitrary Library Loading Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18750" source="SECUNIA" adv="1">18750</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24560" source="XF">qnx-crttrap-privilege-elevation(24560)</ref>
      <ref url="http://www.securityfocus.com/bid/16539" source="BID">16539</ref>
      <ref url="http://securitytracker.com/id?1015599" source="SECTRACK">1015599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtos">
        <vers num="6.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1530" published="2005-07-19" name="CVE-2005-1530" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21373" source="XF" patch="1">sophos-bzip2-dos(21373)</ref>
      <ref url="http://www.securityfocus.com/bid/14270" source="BID" patch="1">14270</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=283&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" patch="1" adv="1">20050714 Sophos Anti-Virus Zip File Handling DoS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014488" source="SECTRACK">1014488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
        <vers num="3.78d" />
        <vers num="3.79" />
        <vers num="3.80" />
        <vers num="3.81" />
        <vers num="3.82" />
        <vers num="3.83" />
        <vers num="3.84" />
        <vers num="3.85" />
        <vers num="3.86" />
        <vers num="3.90" />
        <vers num="3.91" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="sophos" name="sophos_mailmonitor">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="sophos" name="sophos_mailmonitor_for_notes_domino">
        <vers num="" />
      </prod>
      <prod vendor="sophos" name="sophos_puremessage_anti-virus">
        <vers num="4.6" />
      </prod>
      <prod vendor="sophos" name="sophos_small_business_suite">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1531" published="2005-05-12" name="CVE-2005-1531" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-43.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/mfsa2005-43.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0530" source="VUPEN">ADV-2005-0530</ref>
      <ref url="http://securitytracker.com/id?1013963" source="SECTRACK">1013963</ref>
      <ref url="http://securitytracker.com/id?1013962" source="SECTRACK">1013962</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10351" source="OVAL">oval:org.mitre.oval:def:10351</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.securityfocus.com/bid/13641" source="BID">13641</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-435.html" source="REDHAT">RHSA-2005:435</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-434.html" source="REDHAT">RHSA-2005:434</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100015" source="OVAL" sig="1">oval:org.mitre.oval:def:100015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers prev="1" num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1532" published="2005-05-12" name="CVE-2005-1532" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0530" source="VUPEN">ADV-2005-0530</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.securityfocus.com/bid/13645" source="BID">13645</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-435.html" source="REDHAT">RHSA-2005:435</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-434.html" source="REDHAT">RHSA-2005:434</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-44.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-44.html</ref>
      <ref url="http://securitytracker.com/id?1013965" source="SECTRACK">1013965</ref>
      <ref url="http://securitytracker.com/id?1013964" source="SECTRACK">1013964</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10791" source="OVAL">oval:org.mitre.oval:def:10791</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100014" source="OVAL" sig="1">oval:org.mitre.oval:def:100014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1543" published="2005-05-25" name="CVE-2005-1543" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attackers to execute arbitrary code via (1) unspecified vectors, (2) type 1 authentication requests, and (3) type 2 authentication requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20645" source="XF">novell-zenwork-remote-management-2-bo(20645)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20644" source="XF">novell-zenwork-remote-management-1-bo(20644)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20639" source="XF">novell-zenwork-remote-management-bo(20639)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0571" source="VUPEN">ADV-2005-0571</ref>
      <ref url="http://www.securityfocus.com/bid/13678" source="BID">13678</ref>
      <ref url="http://www.rem0te.com/public/images/zen.pdf" source="MISC" adv="1">http://www.rem0te.com/public/images/zen.pdf</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097644.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097644.htm</ref>
      <ref url="http://securitytracker.com/id?1014005" source="SECTRACK">1014005</ref>
      <ref url="http://secunia.com/advisories/15433" source="SECUNIA">15433</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111645317713662&amp;w=2" source="BUGTRAQ" adv="1">20050518 NOVELL ZENWORKS MULTIPLE =?utf-8?Q?REM=C3=98TE?= STACK &amp; HEAP OVERFLOWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks">
        <vers num="6.5" />
      </prod>
      <prod vendor="novell" name="zenworks_desktops">
        <vers num="3.2" edition="sp2" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
      <prod vendor="novell" name="zenworks_remote_management">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="zenworks_server_management">
        <vers num="6.5" />
      </prod>
      <prod vendor="novell" name="zenworks_servers">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1544" published="2005-05-14" name="CVE-2005-1544" modified="2010-03-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20533" source="XF" patch="1">libtiff-bitspersample-bo(20533)</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=91584" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=91584</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200505-07.xml" source="GENTOO">GLSA-200505-07</ref>
      <ref url="http://secunia.com/advisories/15320" source="SECUNIA">15320</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=843" source="MISC">http://bugzilla.remotesensing.org/show_bug.cgi?id=843</ref>
      <ref url="http://www.ubuntu.com/usn/usn-130-1" source="UBUNTU">USN-130-1</ref>
      <ref url="http://www.securityfocus.com/bid/13585" source="BID">13585</ref>
      <ref url="http://www.osvdb.org/16350" source="OSVDB">16350</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:042" source="MANDRIVA">MDKSA-2006:042</ref>
      <ref url="http://www.debian.org/security/2005/dsa-755" source="DEBIAN">DSA-755</ref>
      <ref url="http://securitytracker.com/id?1013944" source="SECTRACK">1013944</ref>
      <ref url="http://secunia.com/advisories/18943" source="SECUNIA">18943</ref>
      <ref url="http://secunia.com/advisories/18289" source="SECUNIA">18289</ref>
      <ref url="http://secunia.com/advisories/16872" source="SECUNIA">16872</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.34/SCOSA-2005.34.txt" source="SCO">SCOSA-2005.34</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.3/SCOSA-2006.3.txt" source="SCO">SCOSA-2006.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.7.0" />
        <vers num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1545" published="2005-05-14" name="CVE-2005-1545" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200505-08.xml" source="GENTOO">GLSA-200505-08</ref>
      <ref url="http://www.debian.org/security/2005/dsa-743" source="DEBIAN">DSA-743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ht_editor" name="ht_editor">
        <vers num="0.3.991" />
        <vers num="0.3.992" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.4b" />
        <vers num="0.4.4c" />
        <vers num="0.4.4d" />
        <vers num="0.4.5" />
        <vers num="0.5.0" />
        <vers num="0.6.0" />
        <vers num="0.6.0b" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.8.0" />
        <vers num="2000-01-14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1546" published="2005-05-14" name="CVE-2005-1546" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200505-08.xml" source="GENTOO">GLSA-200505-08</ref>
      <ref url="http://www.debian.org/security/2005/dsa-743" source="DEBIAN">DSA-743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ht_editor" name="ht_editor">
        <vers num="0.3.991" />
        <vers num="0.3.992" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.4b" />
        <vers num="0.4.4c" />
        <vers num="0.4.4d" />
        <vers num="0.4.5" />
        <vers num="0.5.0" />
        <vers num="0.6.0" />
        <vers num="0.6.0b" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.8.0" />
        <vers num="2000-01-14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1547" published="2005-05-14" name="CVE-2005-1547" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers to execute arbitrary commands via a large packet to port 20031.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111600439331242&amp;w=2" source="BUGTRAQ">20050512 Netvault Remote Heap Overflow (another one)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bakbone" name="netvault">
        <vers num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1548" published="2005-05-14" name="CVE-2005-1548" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13548" source="BID">13548</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566565621193&amp;w=2" source="BUGTRAQ">20050508 Advanced Guestbook 2.3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_guestbook" name="advanced_guestbook">
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1549" published="2005-05-14" name="CVE-2005-1549" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in easymsgb.pl in Easy Message Board allows remote attackers to read arbitrary files via a .. (dot dot) in the print parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soulblack.com.ar/repo/papers/easymsgb_advisory.txt" source="MISC">http://www.soulblack.com.ar/repo/papers/easymsgb_advisory.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13551" source="BID">13551</ref>
      <ref url="http://www.osvdb.org/16162" source="OSVDB">16162</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566691005844&amp;w=2" source="BUGTRAQ">20050508 Easy Message Board Directory Traversal and Remote Command</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colored_scripts" name="easy_message_board">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1550" published="2005-05-14" name="CVE-2005-1550" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soulblack.com.ar/repo/papers/easymsgb_advisory.txt" source="MISC">http://www.soulblack.com.ar/repo/papers/easymsgb_advisory.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13555" source="BID">13555</ref>
      <ref url="http://www.osvdb.org/16163" source="OSVDB">16163</ref>
      <ref url="http://secunia.com/advisories/15295" source="SECUNIA">15295</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566691005844&amp;w=2" source="BUGTRAQ">20050508 Easy Message Board Directory Traversal and Remote Command</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colored_scripts" name="easy_message_board">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1551" published="2005-05-14" name="CVE-2005-1551" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Sophos Anti-Virus 3.93 does not check downloaded files for viruses when they have only been written, which creates a race condition and may allow remote attackers to bypass virus protection if the file is executed before the antivirus starts on system reboot.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20519" source="XF">sophos-download-virus-undetected(20519)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566827411376&amp;w=2" source="BUGTRAQ">20050509 Viruses can evade Sophos Anti-Virus</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.93" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1552" published="2005-05-14" name="CVE-2005-1552" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20537" source="XF">geovision-authentication(20537)</ref>
      <ref url="http://www.securityfocus.com/bid/13571" source="BID">13571</ref>
      <ref url="http://www.osvdb.org/16340" source="OSVDB">16340</ref>
      <ref url="http://www.esqo.com/research/advisories/2005/100505-1.txt" source="MISC" adv="1">http://www.esqo.com/research/advisories/2005/100505-1.txt</ref>
      <ref url="http://secunia.com/advisories/15330" source="SECUNIA">15330</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111574131105737&amp;w=2" source="BUGTRAQ" adv="1">20050510 Esqo advisory: GeoVision Digital Video Surveillance System - Multiple authentication issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geovision" name="digital_surveillance_system">
        <vers num="6.0.4" />
        <vers num="6.1" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1553" published="2005-05-14" name="CVE-2005-1553" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0 uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via sniffing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.esqo.com/research/advisories/2005/100505-1.txt" source="MISC" patch="1">http://www.esqo.com/research/advisories/2005/100505-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111574131105737&amp;w=2" source="BUGTRAQ" patch="1">20050510 Esqo advisory: GeoVision Digital Video Surveillance System - Multiple authentication issues</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20538" source="XF">geovision-authentication-plaintext(20538)</ref>
      <ref url="http://www.osvdb.org/16341" source="OSVDB">16341</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geovision" name="digital_surveillance_system">
        <vers num="6.0.4" />
        <vers num="6.1" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1554" published="2005-05-14" name="CVE-2005-1554" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20565" source="XF">wowbb-viewuser-sql-injection(20565)</ref>
      <ref url="http://www.securityfocus.com/bid/13569" source="BID" adv="1">13569</ref>
      <ref url="http://www.osvdb.org/16543" source="OSVDB">16543</ref>
      <ref url="http://secunia.com/advisories/12843" source="SECUNIA">12843</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111575905112831&amp;w=2" source="BUGTRAQ" adv="1">20050510 WowBB view_user.php SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wowbb" name="wowbb_web_forum">
        <vers num="1.6" />
        <vers num="1.61" />
        <vers num="1.62" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1555" published="2005-05-10" name="CVE-2005-1555" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20550" source="XF" patch="1" adv="1">coldfusion-mx7-default-page-xss(20550)</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb05-03.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb05-03.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111575500403231&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050510 New Macromedia Security Zone Bulletin Posted</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1556" published="2005-05-14" name="CVE-2005-1556" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20417" source="XF" adv="1">gamespy-sdk-cdkey-mult-games-dos(20417)</ref>
      <ref url="http://secunia.com/advisories/15254" source="SECUNIA" adv="1">15254</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0065.html" source="FULLDISC" adv="1">20050504 Gamespy cd-key validation system: "Cd-key in use" DoS versus many games</ref>
      <ref url="http://aluigi.altervista.org/adv/gskeyinuse-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/gskeyinuse-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111575820116969&amp;w=2" source="BUGTRAQ">20050510 Gamespy cd-key validation system: "Cd-key in use" DoS versus many games</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamespy" name="gamespy_sdk_cd-key_validation_toolkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1557" published="2005-05-11" name="CVE-2005-1557" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20544" source="XF" adv="1">webapp-php-guestbook-pro-xss(20544)</ref>
      <ref url="http://www.soulblack.com.ar/repo/papers/guesbookpro_advisory.txt" source="MISC" adv="1">http://www.soulblack.com.ar/repo/papers/guesbookpro_advisory.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13593" source="BID" adv="1">13593</ref>
      <ref url="http://www.osvdb.org/16349" source="OSVDB" adv="1">16349</ref>
      <ref url="http://securitytracker.com/id?1013940" source="SECTRACK">1013940</ref>
      <ref url="http://secunia.com/advisories/15290/" source="SECUNIA" adv="1">15290</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111585232810150&amp;w=2" source="BUGTRAQ" adv="1">20050511 Guesbook Pro XSS &amp; HTML Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixysoft" name="guestbook_pro">
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1558" published="2005-05-11" name="CVE-2005-1558" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15150" source="SECUNIA" patch="1" adv="1">15150</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20554" source="XF" adv="1">nexusway-configuration-modification(20554)</ref>
      <ref url="http://www.osvdb.org/16446" source="OSVDB" adv="1">16446</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111585017832066&amp;w=2" source="BUGTRAQ" adv="1">20050511 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0225.html" source="FULLDISC" adv="1">20050510 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neteyes" name="nexusway">
        <vers num="805" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1559" published="2005-05-11" name="CVE-2005-1559" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15150" source="SECUNIA" patch="1" adv="1">15150</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20557" source="XF" adv="1">nexusway-web-command-execution(20557)</ref>
      <ref url="http://www.osvdb.org/16449" source="OSVDB" adv="1">16449</ref>
      <ref url="http://www.osvdb.org/16448" source="OSVDB" adv="1">16448</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111585017832066&amp;w=2" source="BUGTRAQ" adv="1">20050511 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033945.html" source="FULLDISC" adv="1">20050510 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1560" published="2005-05-11" name="CVE-2005-1560" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15150" source="SECUNIA" patch="1" adv="1">15150</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20555" source="XF" adv="1">nexusway-ssh-command-execution(20555)</ref>
      <ref url="http://www.osvdb.org/16447" source="OSVDB" adv="1">16447</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111585017832066&amp;w=2" source="BUGTRAQ" adv="1">20050511 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033945.html" source="FULLDISC" adv="1">20050510 [Full-disclosure] [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neteyes" name="nexusway">
        <vers num="805" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1561" published="2005-05-11" name="CVE-2005-1561" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20560" source="XF" patch="1" adv="1">maxwebportal-postasp-xss(20560)</ref>
      <ref url="http://secunia.com/advisories/15329" source="SECUNIA" patch="1" adv="1">15329</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111584883727605&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050511 [HSC Security Group] MaxWebPortal - Multiple SQL injection/XSS</ref>
      <ref url="http://www.securityfocus.com/bid/13601" source="BID" adv="1">13601</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=2542" source="MISC" adv="1">http://www.hackerscenter.com/archive/view.asp?id=2542</ref>
      <ref url="http://www.osvdb.org/16501" source="OSVDB">16501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1562" published="2005-05-11" name="CVE-2005-1562" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to pop_profile.asp, or (7) Remove or (8) Delete parameter to pm_delete2.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20562" source="XF" patch="1" adv="1">maxwebportal-postasp-sql-injection(20562)</ref>
      <ref url="http://secunia.com/advisories/15329" source="SECUNIA" patch="1" adv="1">15329</ref>
      <ref url="http://www.securityfocus.com/bid/13601" source="BID" adv="1">13601</ref>
      <ref url="http://www.osvdb.org/16510" source="OSVDB">16510</ref>
      <ref url="http://www.osvdb.org/16506" source="OSVDB">16506</ref>
      <ref url="http://www.osvdb.org/16504" source="OSVDB">16504</ref>
      <ref url="http://www.osvdb.org/16503" source="OSVDB">16503</ref>
      <ref url="http://www.osvdb.org/16502" source="OSVDB">16502</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=2542" source="MISC" adv="1">http://www.hackerscenter.com/archive/view.asp?id=2542</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111584883727605&amp;w=2" source="BUGTRAQ" adv="1">20050511 [HSC Security Group] MaxWebPortal - Multiple SQL injection/XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.5" />
        <vers num="1.30" />
        <vers num="1.31" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1563" published="2005-05-14" name="CVE-2005-1563" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=287109" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=287109</ref>
      <ref url="http://www.osvdb.org/16425" source="OSVDB" patch="1" adv="1">16425</ref>
      <ref url="http://www.bugzilla.org/security/2.16.8/" source="CONFIRM" patch="1" adv="1">http://www.bugzilla.org/security/2.16.8/</ref>
      <ref url="http://secunia.com/advisories/15338" source="SECUNIA" patch="1" adv="1">15338</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592031902962&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050512 Security Advisory for Bugzilla 2.18, 2.19.2, and 2.16.8</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0533" source="VUPEN">ADV-2005-0533</ref>
      <ref url="http://www.securityfocus.com/bid/13606" source="BID">13606</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=001040" source="CONECTIVA">CLSA-2005:1040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.10" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.16.6" />
        <vers num="2.16.7" />
        <vers num="2.16.8" />
        <vers num="2.16.9" />
        <vers num="2.18" />
        <vers num="2.18.1" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1564" published="2005-05-12" name="CVE-2005-1564" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=287109" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=287109</ref>
      <ref url="http://www.osvdb.org/16426" source="OSVDB" patch="1" adv="1">16426</ref>
      <ref url="http://www.bugzilla.org/security/2.16.8/" source="CONFIRM" patch="1" adv="1">http://www.bugzilla.org/security/2.16.8/</ref>
      <ref url="http://secunia.com/advisories/15338" source="SECUNIA" patch="1" adv="1">15338</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592031902962&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050512 Security Advisory for Bugzilla 2.18, 2.19.2, and 2.16.8</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42797" source="XF">bugzilla-postbug-weak-security(42797)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1565" published="2005-05-12" name="CVE-2005-1565" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=287436" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=287436</ref>
      <ref url="http://www.osvdb.org/16427" source="OSVDB" patch="1" adv="1">16427</ref>
      <ref url="http://secunia.com/advisories/15338" source="SECUNIA" patch="1" adv="1">15338</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0533" source="VUPEN">ADV-2005-0533</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592031902962&amp;w=2" source="BUGTRAQ" adv="1">20050512 Security Advisory for Bugzilla 2.18, 2.19.2, and 2.16.8</ref>
      <ref url="http://www.securityfocus.com/bid/13605" source="BID">13605</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=001040" source="CONECTIVA">CLSA-2005:1040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1566" published="2005-05-14" name="CVE-2005-1566" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16445" source="OSVDB" adv="1">16445</ref>
      <ref url="http://secunia.com/advisories/15343" source="SECUNIA" adv="1">15343</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592452331677&amp;w=2" source="BUGTRAQ" adv="1">20050512 Acrowave AAP-3100AR authetication bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arcowave_systems" name="wlan_ap_+_adsl_router">
        <vers num="aap_3100ar" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1567" published="2005-05-12" name="CVE-2005-1567" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592417803514&amp;w=2" source="BUGTRAQ" adv="1">20050512 Directtopics Multiple Vulnerabilities (Security Advisory)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="directtopics" name="directtopics">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="beta" />
        <vers num="final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1568" published="2005-05-12" name="CVE-2005-1568" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to obtain sensitive information via an invalid topic parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592417803514&amp;w=2" source="BUGTRAQ" adv="1">20050512 Directtopics Multiple Vulnerabilities (Security Advisory)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="directtopics" name="directtopics">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="beta" />
        <vers num="final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1569" published="2005-05-14" name="CVE-2005-1569" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in DirectTopics 2.1 and 2.2 allows remote attackers to inject arbitrary web script via a javascript: URL in (1) a thread or (2) an IMG tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592417803514&amp;w=2" source="BUGTRAQ" adv="1">20050512 Directtopics Multiple Vulnerabilities (Security Advisory)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="directtopics" name="directtopics">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1570" published="2005-05-14" name="CVE-2005-1570" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013934" source="SECTRACK" adv="1">1013934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="battleaxe_software" name="bttlxeforum">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1571" published="2005-05-14" name="CVE-2005-1571" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in ShowOff! 1.5.4 allow remote attackers to read arbitrary files via ".." sequences in arguments to the (1) ShowAlbum, (2) ShowVideo, or (3) ShowGraphic scripts.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16332" source="OSVDB">16332</ref>
      <ref url="http://secunia.com/advisories/15300" source="SECUNIA" adv="1">15300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wenig_and_spitzer-williams" name="showoff_digital_media_software">
        <vers num="1.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1572" published="2005-05-11" name="CVE-2005-1572" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16333" source="OSVDB" adv="1">16333</ref>
      <ref url="http://secunia.com/advisories/15300" source="SECUNIA" adv="1">15300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wenig_and_spitzer-williams" name="showoff_digital_media_software">
        <vers num="1.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1573" published="2005-05-11" name="CVE-2005-1573" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.under9round.com/avn13.txt" source="MISC" adv="1">http://www.under9round.com/avn13.txt</ref>
      <ref url="http://securitytracker.com/id?1013933" source="SECTRACK" adv="1">1013933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darrel_oneil" name="asp_virtual_news_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1574" published="2005-05-14" name="CVE-2005-1574" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Windows Media Player 9 and 10, in certain cases, allows content protected by Windows Media Digital Rights Management (WMDRM) to redirect the user to a web site to obtain a license, even when the "Acquire licenses automatically for protected content" setting is not enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;892313" source="MSKB">892313</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="10" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1575" published="2005-05-14" name="CVE-2005-1575" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16431" source="OSVDB" adv="1">16431</ref>
      <ref url="http://secunia.com/secunia_research/2004-11/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2004-11/advisory/</ref>
      <ref url="http://secunia.com/advisories/12979" source="SECUNIA" adv="1">12979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10.1" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1576" published="2005-05-12" name="CVE-2005-1576" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2004-11/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2004-11/advisory/</ref>
      <ref url="http://secunia.com/advisories/12979" source="SECUNIA" patch="1" adv="1">12979</ref>
      <ref url="http://www.osvdb.org/16432" source="OSVDB" adv="1">16432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10.1" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1577" published="2005-05-14" name="CVE-2005-1577" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13604" source="BID" adv="1">13604</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5SP0D0AFPQ.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5SP0D0AFPQ.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apg_technology" name="classmaster">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1578" published="2005-05-13" name="CVE-2005-1578" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15340" source="SECUNIA" adv="1">15340</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guidance_software" name="encase">
        <vers num="4.18a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1579" published="2005-05-12" name="CVE-2005-1579" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13603" source="BID" patch="1" adv="1">13603</ref>
      <ref url="http://secunia.com/advisories/15307" source="SECUNIA" patch="1" adv="1">15307</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0531" source="VUPEN">ADV-2005-0531</ref>
      <ref url="http://www.osvdb.org/16376" source="OSVDB" adv="1">16376</ref>
      <ref url="http://securitytracker.com/id?1013961" source="SECTRACK" adv="1">1013961</ref>
      <ref url="http://remahl.se/david/vuln/018" source="MISC" adv="1">http://remahl.se/david/vuln/018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00006.html" source="APPLE">APPLE-SA-2005-05-31</ref>
      <ref url="http://lists.apple.com/archives/quartzcomposer-dev/2005/May/msg00263.html" source="MLIST" adv="1">[quartzcomposer-dev] 20050511 Re: Quartz Quicktime embedded in remote webpages...</ref>
      <ref url="http://lists.apple.com/archives/quartzcomposer-dev/2005/May/msg00250.html" source="MLIST" adv="1">[quartzcomposer-dev] 20050510 Quartz Quicktime embedded in remote webpages...</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0265.html" source="FULLDISC" adv="1">20050511 [DR018] Quartz Composer / QuickTime 7 information leakage</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=301714" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=301714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1580" published="2005-05-11" name="CVE-2005-1580" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13600" source="BID" adv="1">13600</ref>
      <ref url="http://www.osvdb.org/16334" source="OSVDB" adv="1">16334</ref>
      <ref url="http://www.kernelpanik.org/docs/kernelpanik/bmachines.txt" source="MISC" adv="1">http://www.kernelpanik.org/docs/kernelpanik/bmachines.txt</ref>
      <ref url="http://secunia.com/advisories/15312" source="SECUNIA" adv="1">15312</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boastmachine" name="boastmachine">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":platinum" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1581" published="2005-05-14" name="CVE-2005-1581" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013957" source="SECTRACK" adv="1">1013957</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_fichot" name="bug_report">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1582" published="2005-05-14" name="CVE-2005-1582" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013960" source="SECTRACK" patch="1" adv="1">1013960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="1two" name="1two_news">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1583" published="2005-05-14" name="CVE-2005-1583" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013960" source="SECTRACK" patch="1" adv="1">1013960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="1two" name="1two_news">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1584" published="2005-05-14" name="CVE-2005-1584" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13602" source="BID" adv="1">13602</ref>
      <ref url="http://www.osvdb.org/16327" source="OSVDB" adv="1">16327</ref>
      <ref url="http://secunia.com/advisories/15200" source="SECUNIA" adv="1">15200</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_solution" name="quick.forum">
        <vers num="2.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1585" published="2005-05-11" name="CVE-2005-1585" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16326" source="OSVDB" adv="1">16326</ref>
      <ref url="http://secunia.com/advisories/15200" source="SECUNIA" adv="1">15200</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_solution" name="quick.forum">
        <vers num="2.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1586" published="2005-05-14" name="CVE-2005-1586" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16329" source="OSVDB" adv="1">16329</ref>
      <ref url="http://www.osvdb.org/16328" source="OSVDB" adv="1">16328</ref>
      <ref url="http://secunia.com/advisories/15200" source="SECUNIA" adv="1">15200</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_solution" name="quick.forum">
        <vers num="2.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1587" published="2005-05-14" name="CVE-2005-1587" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13599" source="BID" adv="1">13599</ref>
      <ref url="http://www.osvdb.org/16330" source="OSVDB" adv="1">16330</ref>
      <ref url="http://secunia.com/advisories/15297" source="SECUNIA" adv="1">15297</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/quickcart-sword-variable-xss-and.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/quickcart-sword-variable-xss-and.html</ref>
      <ref url="http://opensolution.org/forum/?p=readTopic&amp;nr=948" source="CONFIRM">http://opensolution.org/forum/?p=readTopic&amp;nr=948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_solution" name="quick.cart">
        <vers num="0.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1588" published="2005-05-11" name="CVE-2005-1588" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter.  NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16331" source="OSVDB" adv="1">16331</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/quickcart-sword-variable-xss-and.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/quickcart-sword-variable-xss-and.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_solution" name="quick.cart">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1589" published="2005-05-17" name="CVE-2005-1589" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=111630531515901&amp;w=2" source="MLIST" patch="1" adv="1">[linux-kernel] 20050517 [PATCH] Fix root hole in pktcdvd</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0045.html" source="VULNWATCH" patch="1" adv="1">20050516 Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0557" source="VUPEN">ADV-2005-0557</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0047.html" source="VULNWATCH">20050517 Linux kernel pktcdvd ioctl break user space limit vulnerability [corrected]</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0046.html" source="VULNWATCH">20050517 Re: Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/13651" source="BID">13651</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.12" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1590" published="2005-05-16" name="CVE-2005-1590" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2004-2070.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/15897" source="OSVDB" adv="1">15897</ref>
      <ref url="http://secunia.com/advisories/15159" source="SECUNIA" adv="1">15159</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-04/0614.html" source="FULLDISC" adv="1">20050427 Privilege escalation and password protection bypass in Altiris Client Service for Windows (Version 6.0.88)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="altiris" name="client_service">
        <vers num="6.0.88" />
      </prod>
      <prod vendor="altiris" name="deployment_solution">
        <vers num="5.6" edition="sp1" />
        <vers num="5.6.181" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1591" published="2005-05-16" name="CVE-2005-1591" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57780-1" source="SUNALERT" patch="1" adv="1">57780</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0492" source="VUPEN">ADV-2005-0492</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1592" published="2005-05-16" name="CVE-2005-1592" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=324788" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=324788</ref>
      <ref url="http://secunia.com/advisories/15206" source="SECUNIA" adv="1">15206</ref>
    </refs>
    <vuln_soft>
      <prod vendor="birdblog" name="birdblog">
        <vers prev="1" num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1593" published="2005-05-16" name="CVE-2005-1593" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13560" source="BID" adv="1">13560</ref>
      <ref url="http://www.osvdb.org/16155" source="OSVDB">16155</ref>
      <ref url="http://securitytracker.com/id?1013924" source="SECTRACK" adv="1">1013924</ref>
      <ref url="http://secunia.com/advisories/15251" source="SECUNIA" adv="1">15251</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codethat" name="shoppingcart">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1594" published="2005-05-16" name="CVE-2005-1594" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15251" source="SECUNIA" patch="1" adv="1">15251</ref>
      <ref url="http://www.securityfocus.com/bid/13560" source="BID" adv="1">13560</ref>
      <ref url="http://www.osvdb.org/16156" source="OSVDB" adv="1">16156</ref>
      <ref url="http://securitytracker.com/id?1013924" source="SECTRACK" adv="1">1013924</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codethat" name="shoppingcart">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1595" published="2005-05-16" name="CVE-2005-1595" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15251" source="SECUNIA" patch="1" adv="1">15251</ref>
      <ref url="http://www.securityfocus.com/bid/13560" source="BID" adv="1">13560</ref>
      <ref url="http://www.osvdb.org/16157" source="OSVDB" adv="1">16157</ref>
      <ref url="http://securitytracker.com/id?1013924" source="SECTRACK" adv="1">1013924</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codethat" name="shoppingcart">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1596" published="2005-05-16" name="CVE-2005-1596" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15257" source="SECUNIA" patch="1" adv="1">15257</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20531" source="XF" adv="1">fusion-islogged-authentication-bypass(20531)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0508" source="VUPEN">ADV-2005-0508</ref>
      <ref url="http://www.securiteam.com/exploits/5OP042KFPU.html" source="MISC" adv="1">http://www.securiteam.com/exploits/5OP042KFPU.html</ref>
      <ref url="http://www.osvdb.org/16217" source="OSVDB" adv="1">16217</ref>
      <ref url="http://www.osvdb.org/16216" source="OSVDB" adv="1">16216</ref>
      <ref url="http://www.exploits.co.in/Article1134.html" source="MISC" adv="1">http://www.exploits.co.in/Article1134.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fusion" name="sbx">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1597" published="2005-05-16" name="CVE-2005-1597" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00073-05052005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00073-05052005</ref>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=168016" source="CONFIRM" patch="1">http://forums.invisionpower.com/index.php?showtopic=168016</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0487" source="VUPEN">ADV-2005-0487</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20445" source="XF">invision-powerboard-highlite-xss(20445)</ref>
      <ref url="http://www.securityfocus.com/bid/13534" source="BID">13534</ref>
      <ref url="http://www.osvdb.org/16298" source="OSVDB">16298</ref>
      <ref url="http://securitytracker.com/id?1013907" source="SECTRACK">1013907</ref>
      <ref url="http://secunia.com/advisories/15265" source="SECUNIA">15265</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539908705851&amp;w=2" source="BUGTRAQ">20050506 Multiple Vulnerabilities In Invision Power Board</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="2.0_alpha_3" />
        <vers num="2.0_pdr3" />
      </prod>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1598" published="2005-05-16" name="CVE-2005-1598" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00073-05052005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00073-05052005</ref>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=168016" source="CONFIRM" patch="1">http://forums.invisionpower.com/index.php?showtopic=168016</ref>
      <ref url="http://www.securityfocus.com/bid/13529" source="BID">13529</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20446" source="XF">invision-powerboard-login-sql-injection(20446)</ref>
      <ref url="http://www.securiteam.com/exploits/5GP0E2KFQQ.html" source="MISC">http://www.securiteam.com/exploits/5GP0E2KFQQ.html</ref>
      <ref url="http://www.osvdb.org/16297" source="OSVDB">16297</ref>
      <ref url="http://securitytracker.com/id?1014499" source="SECTRACK">1014499</ref>
      <ref url="http://securitytracker.com/id?1013907" source="SECTRACK">1013907</ref>
      <ref url="http://secunia.com/advisories/15265" source="SECUNIA">15265</ref>
      <ref url="http://milw0rm.com/exploits/1013" source="MILW0RM">1013</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111712587206834&amp;w=2" source="BUGTRAQ">20050526 Invision Power Board 1.* and 2.* Exploit (BID 13529)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539908705851&amp;w=2" source="BUGTRAQ">20050506 Multiple Vulnerabilities In Invision Power Board</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="2.0_alpha_3" />
        <vers num="2.0_pdr3" />
      </prod>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1599" published="2005-05-16" name="CVE-2005-1599" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Kryloff Technologies Subject Search Server (SSServer) 1.1 allows remote attackers to inject arbitrary web script or HTML via the "Search For" field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20558" source="XF">ssserver-searchfor-xss(20558)</ref>
      <ref url="http://www.securityfocus.com/bid/13574" source="BID">13574</ref>
      <ref url="http://securitytracker.com/id?1013938" source="SECTRACK">1013938</ref>
      <ref url="http://secunia.com/advisories/15288" source="SECUNIA">15288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kryloff_technologies" name="subject_search_server">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1600" published="2005-05-16" name="CVE-2005-1600" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20455" source="XF">libtomcrypt-signature-security-bypass(20455)</ref>
      <ref url="http://www.securityfocus.org/archive/1/397649" source="BUGTRAQ">20050503 Secure Science Corporation Advisory CSA-056</ref>
      <ref url="http://www.securityfocus.com/bid/13473" source="BID">13473</ref>
      <ref url="http://www.securiteam.com/unixfocus/5JP092AFPG.html" source="MISC">http://www.securiteam.com/unixfocus/5JP092AFPG.html</ref>
      <ref url="http://www.osvdb.org/16188" source="OSVDB">16188</ref>
      <ref url="http://secunia.com/advisories/15233" source="SECUNIA">15233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtomcrypt" name="libtomcrypt">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1601" published="2005-05-16" name="CVE-2005-1601" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MRO Maximo Self Service 4 and 5 stores certain information under the web document root using file extensions that are not processed by Tomcat, which allows remote attackers to obtain sensitive information via a direct request for the file, such as MXServer.properties.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20452" source="XF">maximo-information-disclosure(20452)</ref>
      <ref url="http://www.securityfocus.com/bid/13508" source="BID">13508</ref>
      <ref url="http://www.securityfocus.com/archive/1/397522" source="BUGTRAQ">20050505 MRO Maximo v4 &amp; v5</ref>
      <ref url="http://www.osvdb.org/16161" source="OSVDB">16161</ref>
      <ref url="http://secunia.com/advisories/15176" source="SECUNIA">15176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mro_software" name="maximo_self_service">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1602" published="2005-05-16" name="CVE-2005-1602" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20504" source="XF">browser-based-file-mgr-sql-injection(20504)</ref>
      <ref url="http://www.securityfocus.com/bid/13547" source="BID">13547</ref>
      <ref url="http://www.osvdb.org/16544" source="OSVDB">16544</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0134.html" source="FULLDISC">20050508 Browser Based File Manager Administration Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net56" name="file_manager">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1603" published="2005-05-16" name="CVE-2005-1603" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0501" source="VUPEN">ADV-2005-0501</ref>
      <ref url="http://www.securityfocus.com/bid/13550" source="BID">13550</ref>
      <ref url="http://www.osvdb.org/16158" source="OSVDB">16158</ref>
      <ref url="http://secunia.com/advisories/15299" source="SECUNIA">15299</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0129.html" source="FULLDISC">20050508 Server Remote File Manager DOS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="niteenterprises" name="remote_file_manager">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1604" published="2005-05-16" name="CVE-2005-1604" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13542" source="BID">13542</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/415172" source="BUGTRAQ">20051029 uplod phpshell in PHP Advanced Transfer Manager</ref>
      <ref url="http://www.securityfocus.com/archive/1/415300/30/0/threaded" source="BUGTRAQ">20051030 Re: uplod phpshell in PHP Advanced Transfer Manager</ref>
      <ref url="http://www.osvdb.org/16160" source="OSVDB">16160</ref>
      <ref url="http://secunia.com/advisories/15279" source="SECUNIA">15279</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/May/0075.html" source="BUGTRAQ">20050506 PHP Advanced Transfer Manager v1.21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bugada_andrea" name="php_advanced_transfer_manager">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1605" published="2005-05-16" name="CVE-2005-1605" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site Studio with H-Sphere.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20496" source="XF" patch="1">sitestudio-guestbook-xss(20496)</ref>
      <ref url="http://www.psoft.net/SS/ss_16_security_update_guestbook.html" source="CONFIRM" patch="1">http://www.psoft.net/SS/ss_16_security_update_guestbook.html</ref>
      <ref url="http://www.psoft.net/misc/hsphere_winbox_security_update_guestbook.html" source="CONFIRM" patch="1">http://www.psoft.net/misc/hsphere_winbox_security_update_guestbook.html</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-05/0154.html" source="FULLDISC" patch="1">20050509 SiteStudio</ref>
      <ref url="http://secunia.com/advisories/15286" source="SECUNIA" patch="1">15286</ref>
      <ref url="http://exploitlabs.com/files/advisories/EXPL-A-2005-008-sitestudio.txt" source="MISC" patch="1">http://exploitlabs.com/files/advisories/EXPL-A-2005-008-sitestudio.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13554" source="BID">13554</ref>
      <ref url="http://www.osvdb.org/16240" source="OSVDB">16240</ref>
    </refs>
    <vuln_soft>
      <prod vendor="positive_software" name="sitestudio">
        <vers num="1.6_final" />
        <vers num="1.6_patch_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1606" published="2005-05-16" name="CVE-2005-1606" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20522" source="XF" patch="1">hsphere-information-disclosure(20522)</ref>
      <ref url="http://www.securityfocus.com/bid/13559" source="BID" patch="1">13559</ref>
      <ref url="http://www.psoft.net/misc/hsphere_winbox_security_update_passwd.html" source="CONFIRM" patch="1">http://www.psoft.net/misc/hsphere_winbox_security_update_passwd.html</ref>
      <ref url="http://secunia.com/advisories/15287" source="SECUNIA" patch="1">15287</ref>
      <ref url="http://exploitlabs.com/files/advisories/EXPL-A-2005-007-hsphere.txt" source="MISC" patch="1">http://exploitlabs.com/files/advisories/EXPL-A-2005-007-hsphere.txt</ref>
      <ref url="http://www.osvdb.org/16239" source="OSVDB">16239</ref>
    </refs>
    <vuln_soft>
      <prod vendor="positive_software" name="h-sphere_winbox">
        <vers num="2.4.2_patch_4" />
        <vers num="2.4.3_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1607" published="2005-05-16" name="CVE-2005-1607" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart allows remote attackers to inject arbitrary web script or HTML via the (1) merchant or (2) demo parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16454" source="OSVDB" adv="1">16454</ref>
      <ref url="http://www.governmentsecurity.org/forum/lofiversion/index.php/t14715.html" source="MISC" adv="1">http://www.governmentsecurity.org/forum/lofiversion/index.php/t14715.html</ref>
      <ref url="http://securitytracker.com/id?1013903" source="SECTRACK" adv="1">1013903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="remote_cart" name="remote_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1608" published="2005-05-16" name="CVE-2005-1608" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the Blocks module in Spidean AutoTheme 1.7 and AT-Lite for PostNuke have unknown impact.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20490" source="XF" patch="1" adv="1">autotheme-pnadminphp-gain-access(20490)</ref>
      <ref url="http://www.securityfocus.com/bid/13539" source="BID" patch="1" adv="1">13539</ref>
      <ref url="http://securitytracker.com/id?1013908" source="SECTRACK" patch="1" adv="1">1013908</ref>
      <ref url="http://secunia.com/advisories/15289" source="SECUNIA" patch="1" adv="1">15289</ref>
      <ref url="http://news.postnuke.com/Article2687.html" source="CONFIRM" patch="1">http://news.postnuke.com/Article2687.html</ref>
      <ref url="http://www.osvdb.org/16346" source="OSVDB" adv="1">16346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidean" name="at-lite">
        <vers num="0.8" />
      </prod>
      <prod vendor="spidean" name="autotheme">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1609" published="2005-05-16" name="CVE-2005-1609" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun StorEdge 6130 Arrays (SE6130) with serial numbers between 0451AWF00G and 0513AWF00J allows local users and remote attackers to delete data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/812438" source="CERT-VN" adv="1">VU#812438</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20542" source="XF" adv="1">storedge-6130-array-bypass-security(20542)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0491" source="VUPEN">ADV-2005-0491</ref>
      <ref url="http://www.securityfocus.com/bid/13566" source="BID" adv="1">13566</ref>
      <ref url="http://www.osvdb.org/16325" source="OSVDB" adv="1">16325</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57771-1" source="SUNALERT" adv="1">57771</ref>
      <ref url="http://securitytracker.com/id?1013921" source="SECTRACK" adv="1">1013921</ref>
      <ref url="http://secunia.com/advisories/15306" source="SECUNIA" adv="1">15306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="storedge_6130_arrays">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1610" published="2005-05-16" name="CVE-2005-1610" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via a base64 encoded Codigo parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13570" source="BID" patch="1" adv="1">13570</ref>
      <ref url="http://www.osvdb.org/16214" source="OSVDB" patch="1" adv="1">16214</ref>
      <ref url="http://securitytracker.com/id?1013936" source="SECTRACK" patch="1" adv="1">1013936</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/nukeet-codigo-variable-cross-site.html" source="MISC" patch="1" adv="1">http://lostmon.blogspot.com/2005/05/nukeet-codigo-variable-cross-site.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20540" source="XF" adv="1">nukeet-securityphp-xss(20540)</ref>
      <ref url="http://secunia.com/advisories/15332" source="SECUNIA" adv="1">15332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tru-zone" name="nukeet">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1611" published="2005-05-16" name="CVE-2005-1611" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebX in Web Crossing 5.x allows remote attackers to inject arbitrary web script or HTML via a URL with an "@" followed by the desired script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20381" source="XF" adv="1">web-crossing-webx-xss(20381)</ref>
      <ref url="http://www.securityfocus.com/bid/13482" source="BID" adv="1">13482</ref>
      <ref url="http://www.osvdb.org/16070" source="OSVDB" adv="1">16070</ref>
      <ref url="http://secunia.com/advisories/15218" source="SECUNIA" adv="1">15218</ref>
      <ref url="http://osvdb.org/ref/16/16070-webcrossing.txt" source="MISC" adv="1">http://osvdb.org/ref/16/16070-webcrossing.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_crossing_inc" name="web_crossing">
        <vers num="5.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1612" published="2005-05-16" name="CVE-2005-1612" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13624" source="BID" adv="1">13624</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111601780332632&amp;w=2" source="BUGTRAQ" adv="1">20050513 OpenBB SQL Injection &amp; Cross-site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbb" name="openbb">
        <vers num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1613" published="2005-05-16" name="CVE-2005-1613" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web script or HTML via the reverse parameter in a list action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13625" source="BID" adv="1">13625</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111601780332632&amp;w=2" source="BUGTRAQ" adv="1">20050513 OpenBB SQL Injection &amp; Cross-site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbb" name="openbb">
        <vers num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1614" published="2005-05-16" name="CVE-2005-1614" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13621" source="BID" adv="1">13621</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111600262424876&amp;w=2" source="BUGTRAQ" adv="1">20050513 Ultimate PHP Board (UPB) Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_php_board" name="ultimate_php_board">
        <vers num="1.8" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1615" published="2005-05-16" name="CVE-2005-1615" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13622" source="BID">13622</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111600262424876&amp;w=2" source="BUGTRAQ" adv="1">20050513 Ultimate PHP Board (UPB) Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_php_board" name="ultimate_php_board">
        <vers num="1.8" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1616" published="2005-05-16" name="CVE-2005-1616" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to obtain sensitive information via an invalid (1) id or possibly (2) postorder parameter, which reveals the path in an error message when a file can not be opened.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111600262424876&amp;w=2" source="BUGTRAQ" adv="1">20050513 Ultimate PHP Board (UPB) Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_php_board" name="ultimate_php_board">
        <vers num="1.8" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1617" published="2005-05-16" name="CVE-2005-1617" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Willings WebCam and WebCam Lite 2.8 and earlier stores the password in memory in plaintext, which allows local users to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111601481221137&amp;w=2" source="BUGTRAQ" adv="1">20050513 Willings WebCam - Password Disclosure Issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="willings" name="webcam">
        <vers prev="1" num="2.8" />
      </prod>
      <prod vendor="willings" name="webcam_lite">
        <vers prev="1" num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1618" published="2005-05-16" name="CVE-2005-1618" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an &amp; (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111601904204055&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050513 Yahoo! Messenger URL Handler Remote DoS Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/13626" source="BID">13626</ref>
      <ref url="http://www.osvdb.org/16816" source="OSVDB">16816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1619" published="2005-05-16" name="CVE-2005-1619" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter.  NOTE: it was later reported that 0.14.5 is also affected.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13628" source="BID">13628</ref>
      <ref url="http://www.securityfocus.com/bid/13627" source="BID">13627</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/484575/100/0/threaded" source="BUGTRAQ">20071204 RFI and Multiple XSS in PhpMyChat</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111602076500031&amp;w=2" source="BUGTRAQ">20050513 PHPHeaven PHPMyChat Cross-site Scripting Vulnerablitiy</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpheaven" name="phpmychat">
        <vers num="0.14.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1620" published="2005-05-16" name="CVE-2005-1620" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111609838307070&amp;w=2" source="BUGTRAQ">20050514 Skull-Splitter's Guestbook Multiple XXS/HTML injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="soren_boysen" name="skull-splitter_guestbook">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1621" published="2005-05-16" name="CVE-2005-1621" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a .. (dot dot) in the func parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627124301526&amp;w=2" source="BUGTRAQ" patch="1">20050516 Postnuke 0.750 - 0.760rc4 local file inclusion</ref>
      <ref url="http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/includes/pnMod.php.diff?r1=1.47&amp;r2=1.48" source="CONFIRM" patch="1">http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/includes/pnMod.php.diff?r1=1.47&amp;r2=1.48</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0553" source="VUPEN">ADV-2005-0553</ref>
      <ref url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691" source="CONFIRM">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691</ref>
      <ref url="http://news.postnuke.com/Article2690.html" source="CONFIRM">http://news.postnuke.com/Article2690.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
        <vers num="0.760_rc2" />
        <vers num="0.760_rc3" />
        <vers num="0.760_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1622" published="2005-05-16" name="CVE-2005-1622" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627073203176&amp;w=2" source="BUGTRAQ" patch="1">20050516 Multiple Vulnerabilities in MetaCart e-Shop</ref>
      <ref url="http://echo.or.id/adv/adv13-theday-2005.txt" source="MISC" patch="1">http://echo.or.id/adv/adv13-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metalinks" name="metacart_e-shop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1625" published="2005-07-05" name="CVE-2005-1625" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=279&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050705 iDEFENSE Security Advisory 07.05.05: Adobe Acrobat Reader UnixAppOpenFilePerform() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.adobe.com/support/techdocs/329083.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/329083.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-575.html" source="REDHAT">RHSA-2005:575</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_42_acroread.html" source="SUSE">SUSE-SA:2005:042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.0.10" />
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1626" published="2005-05-17" name="CVE-2005-1626" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13648" source="BID" patch="1">13648</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=327708" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=327708</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1627" published="2005-05-17" name="CVE-2005-1627" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Viewglob before 2.0.1, related to "a potential security issue with the Viewglob display and ssh X forwarding," has unknown impact.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=325574" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=325574</ref>
      <ref url="http://securitytracker.com/id?1013937" source="SECTRACK" patch="1">1013937</ref>
      <ref url="http://secunia.com/advisories/15293" source="SECUNIA" patch="1">15293</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20559" source="XF" adv="1">viewglob-connection-information-disclosure(20559)</ref>
      <ref url="http://www.osvdb.org/16170" source="OSVDB">16170</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viewglob" name="viewglob">
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1628" published="2005-05-17" name="CVE-2005-1628" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0554" source="VUPEN" adv="1">ADV-2005-0554</ref>
      <ref url="http://www.soulblack.com.ar/repo/tools/sbwebapp.txt" source="MISC">http://www.soulblack.com.ar/repo/tools/sbwebapp.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13637" source="BID">13637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449573/100/200/threaded" source="BUGTRAQ">20061024 Re: Application orders Linux in WebAPP v0.9.9.2.1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449517/100/200/threaded" source="BUGTRAQ">20061023 Application orders Linux in WebAPP v0.9.9.2.1</ref>
      <ref url="http://www.defacers.com.mx/advisories/3.txt" source="MISC">http://www.defacers.com.mx/advisories/3.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1629" published="2005-05-17" name="CVE-2005-1629" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/May/0311.html" source="FULLDISC" patch="1">20050513 PhotoPost Arbitrary Data Exploit</ref>
      <ref url="http://www.securityfocus.com/bid/13620" source="BID">13620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.6" />
        <vers num="4.8.1" />
        <vers num="5.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1630" published="2005-05-17" name="CVE-2005-1630" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=326408" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=326408</ref>
      <ref url="http://secunia.com/advisories/15327" source="SECUNIA" patch="1">15327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opentools" name="attachment_mod">
        <vers num="2.3.10" />
        <vers num="2.3.11" />
        <vers num="2.3.12" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1631" published="2005-05-17" name="CVE-2005-1631" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">booby.php in Booby 1.0.0 and earlier allows remote attackers to view private bookmarks by guessing item IDs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13623" source="BID" patch="1">13623</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=326826" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=326826</ref>
      <ref url="http://secunia.com/advisories/15305" source="SECUNIA" patch="1">15305</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20605" source="XF" adv="1">booby-bookmarks-information-disclosure(20605)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="booby" name="booby">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.3" />
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1632" published="2005-05-17" name="CVE-2005-1632" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=7070332&amp;forum_id=1542" source="CONFIRM" patch="1">http://sourceforge.net/mailarchive/forum.php?thread_id=7070332&amp;forum_id=1542</ref>
      <ref url="http://www.osvdb.org/16622" source="OSVDB">16622</ref>
      <ref url="http://secunia.com/advisories/15386" source="SECUNIA" adv="1">15386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tavis_rudd" name="cheetah">
        <vers num="0.9.15" />
        <vers num="0.9.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1633" published="2005-05-17" name="CVE-2005-1633" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627681218415&amp;w=2" source="BUGTRAQ">20050516 [SePro Bugtraq] WBB Portal - JGS-Portal &lt;= 3.0.2 - Multiple Vulnerabilities (09.05.05)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgs-xa" name="jgs-portal">
        <vers prev="1" num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1634" published="2005-05-17" name="CVE-2005-1634" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.php, (3) year parameter to jgs_portal_beitraggraf.php, (4) tag parameter to jgs_portal_viewsgraf.php, (5) year parameter to jgs_portal_themengraf.php, (6) year parameter to jgs_portal_mitgraf.php, (7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.  NOTE: this issue may stem from the same core problem as CVE-2005-1633.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627681218415&amp;w=2" source="BUGTRAQ">20050516 [SePro Bugtraq] WBB Portal - JGS-Portal &lt;= 3.0.2 - Multiple Vulnerabilities (09.05.05)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgs-xa" name="jgs-portal">
        <vers prev="1" num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1635" published="2005-05-17" name="CVE-2005-1635" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">JGS-XA JGS-Portal 3.0.2 and earlier allows remote attackers to obtain the full server path via direct requests to (1) jgs_portal_ref.php, (2) jgs_portal_land.php, (3) jgs_portal_log.php, (4) jgs_portal_global_sponsor.php, (5) jgs_portal_global.php, (6) jgs_portal_system.php, (7) jgs_portal_views.php; or multiple files in the jgs_portal_include directory, including (8) jgs_portal_boardmenue.php, (9) jgs_portal_forenliste.php, (10) jgs_portal_geburtstag.php, (11) jgs_portal_guckloch.php, (12) jgs_portal_kalender.php, (13) jgs_portal_letztethemen.php, (14) jgs_portal_links.php, (15) jgs_portal_neustemember.php, (16) jgs_portal_newsboard.php, (17) jgs_portal_online.php, (18) jgs_portal_pn.php, (19) jgs_portal_portalmenue.php, (20) jgs_portal_styles.php, (21) jgs_portal_suchen.php, (22) jgs_portal_team.php, (23) jgs_portal_topforen.php, (24) jgs_portal_topposter.php, (25) jgs_portal_umfrage.php, (26) jgs_portal_useravatar.php, (27) jgs_portal_waronline.php, (28) jgs_portal_woonline.php, or (29) jgs_portal_zufallsavatar.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627681218415&amp;w=2" source="BUGTRAQ">20050516 [SePro Bugtraq] WBB Portal - JGS-Portal &lt;= 3.0.2 - Multiple Vulnerabilities (09.05.05)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgs-xa" name="jgs-portal">
        <vers prev="1" num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1636" published="2005-05-17" name="CVE-2005-1636" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=158688" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=158688</ref>
      <ref url="http://www.zataz.net/adviso/mysql-05172005.txt" source="MISC">http://www.zataz.net/adviso/mysql-05172005.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13660" source="BID">13660</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-685.html" source="REDHAT">RHSA-2005:685</ref>
      <ref url="http://secunia.com/advisories/17080" source="SECUNIA">17080</ref>
      <ref url="http://secunia.com/advisories/15369" source="SECUNIA">15369</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9504" source="OVAL">oval:org.mitre.oval:def:9504</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111632686805498&amp;w=2" source="FULLDISC">20050517 MySQL &lt; 4.0.12 &amp;&amp; MySQL &lt;= 5.0.4 : Insecure tmp</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:045" source="MANDRIVA">MDKSA-2006:045</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1637" published="2005-05-17" name="CVE-2005-1637" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.npds.org/article.php?sid=1258" source="CONFIRM" patch="1">http://www.npds.org/article.php?sid=1258</ref>
      <ref url="http://securitytracker.com/id?1013973" source="SECTRACK" patch="1">1013973</ref>
    </refs>
    <vuln_soft>
      <prod vendor="npds" name="npds">
        <vers num="4.8" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1638" published="2005-05-17" name="CVE-2005-1638" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://pixel-apes.com/safehtml/feed" source="CONFIRM" patch="1">http://pixel-apes.com/safehtml/feed</ref>
      <ref url="http://www.osvdb.org/16612" source="OSVDB">16612</ref>
      <ref url="http://secunia.com/advisories/15371" source="SECUNIA">15371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixel-apes_group" name="safehtml">
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1639" published="2005-05-17" name="CVE-2005-1639" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.under9round.com/sigma.txt" source="MISC" adv="1">http://www.under9round.com/sigma.txt</ref>
      <ref url="http://www.osvdb.org/16620" source="OSVDB">16620</ref>
      <ref url="http://secunia.com/advisories/15379" source="SECUNIA">15379</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atinegar" name="sigma_isp_manager">
        <vers prev="1" num="6.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1640" published="2005-05-17" name="CVE-2005-1640" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ignition-project.com/security/20050414-hosts-delete-owner-access-entries" source="CONFIRM" patch="1" adv="1">http://www.ignition-project.com/security/20050414-hosts-delete-owner-access-entries</ref>
      <ref url="http://secunia.com/advisories/15388" source="SECUNIA" patch="1">15388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_ignition_project" name="ignitionserver">
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1641" published="2005-05-17" name="CVE-2005-1641" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ignition-project.com/security/20050515-protected-opers-cannot-join-channel-with-key" source="CONFIRM" patch="1">http://www.ignition-project.com/security/20050515-protected-opers-cannot-join-channel-with-key</ref>
      <ref url="http://secunia.com/advisories/15388" source="SECUNIA" patch="1">15388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_ignition_project" name="ignitionserver">
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1642" published="2005-05-17" name="CVE-2005-1642" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0558" source="VUPEN">ADV-2005-0558</ref>
      <ref url="http://www.osvdb.org/16575" source="OSVDB">16575</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2005-May/000047.html" source="VIM">20050516 Re: Woltlab Burning Board SQL Injection Vulnerability (fwd)</ref>
      <ref url="http://secunia.com/advisories/15395" source="SECUNIA" adv="1">15395</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0199.html" source="BUGTRAQ" adv="1">20050516 Woltlab Burning Board SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1643" published="2005-05-17" name="CVE-2005-1643" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ZCom_BitStream::Deserialize function in Zoidcom 1.0 beta 4 and earlier allows remote attackers to cause a denial of service via a crafted UDP packet with a large size value, which causes a memory allocation error or an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zoidcom.com/download/changelog.txt" source="CONFIRM" patch="1">http://www.zoidcom.com/download/changelog.txt</ref>
      <ref url="http://securitytracker.com/id?1013939" source="SECTRACK" patch="1">1013939</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20511" source="XF" adv="1">zoidcom-deserialize-dos(20511)</ref>
      <ref url="http://www.osvdb.org/16495" source="OSVDB">16495</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0107.html" source="BUGTRAQ" adv="1">20050510 Crash in Zoidcom 1.0 beta 4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jorg_ruppel" name="zoidcom">
        <vers num="1.0_beta_2" />
        <vers num="1.0_beta_3" />
        <vers num="1.0_beta_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1644" published="2005-05-18" name="CVE-2005-1644" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php for 1Two Livre d'Or 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) livreornom, (2) livreoremail, or (3) livreormessage parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013971" source="SECTRACK" patch="1">1013971</ref>
      <ref url="http://www.securityfocus.com/bid/13631" source="BID">13631</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20589" source="XF">1two-livere-dor-guestbook-xss(20589)</ref>
      <ref url="http://www.osvdb.org/16717" source="OSVDB">16717</ref>
    </refs>
    <vuln_soft>
      <prod vendor="1two" name="livre_d_or">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1645" published="2005-05-18" name="CVE-2005-1645" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20592" source="XF">imagegallery-information-disclosure(20592)</ref>
      <ref url="http://www.securityfocus.com/bid/13630" source="BID">13630</ref>
      <ref url="http://securitytracker.com/id?1013970" source="SECTRACK">1013970</ref>
      <ref url="http://secunia.com/advisories/15362" source="SECUNIA" adv="1">15362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="keyvan1" name="imagegallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1646" published="2005-05-18" name="CVE-2005-1646" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.security.org.sg/vuln/netfileftp746port.html" source="MISC" patch="1">http://www.security.org.sg/vuln/netfileftp746port.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0556" source="VUPEN">ADV-2005-0556</ref>
      <ref url="http://secunia.com/advisories/15394" source="SECUNIA" adv="1">15394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="netfile_ftp_web_server">
        <vers num="7.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1647" published="2005-05-18" name="CVE-2005-1647" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Gurgens (GASoft) Guest Book 2.1 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013976" source="SECTRACK">1013976</ref>
      <ref url="http://secunia.com/advisories/15373" source="SECUNIA" adv="1">15373</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0351.html" source="FULLDISC">20050515 Gurgens Guest Book Password Database Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gurgens" name="gurgens_guest_book">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1648" published="2005-05-18" name="CVE-2005-1648" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0350.html" source="FULLDISC" patch="1">20050515 Ultimate Forum Password Database Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1013974" source="SECTRACK">1013974</ref>
      <ref url="http://secunia.com/advisories/15374" source="SECUNIA" adv="1">15374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gurgens" name="gurgens_ultimate_forum">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1649" published="2005-05-18" name="CVE-2005-1649" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IpV6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, a variant of CVE-2005-0688 and a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0559" source="VUPEN">ADV-2005-0559</ref>
      <ref url="http://www.securityfocus.com/bid/13658" source="BID">13658</ref>
      <ref url="http://www.ntbugtraq.com/default.aspx?pid=36&amp;sid=1&amp;A2=ind0505&amp;L=NTBUGTRAQ&amp;P=R409&amp;D=0&amp;F=N&amp;H=0&amp;O=D&amp;T=0" source="NTBUGTRAQ" adv="1">20050516 Windows (XP, 2k3, Longhorn) is vulnerable to IpV6 Land attack.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1650" published="2005-05-18" name="CVE-2005-1650" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13597" source="BID">13597</ref>
      <ref url="http://secunia.com/advisories/15268" source="SECUNIA">15268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woppoware" name="postmaster">
        <vers num="4.2.2_build3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1651" published="2005-05-18" name="CVE-2005-1651" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13597" source="BID">13597</ref>
      <ref url="http://secunia.com/advisories/15268" source="SECUNIA">15268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woppoware" name="postmaster">
        <vers num="4.2.2_build3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1652" published="2005-05-18" name="CVE-2005-1652" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to bypass authentication by modifying the email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13597" source="BID">13597</ref>
      <ref url="http://secunia.com/advisories/15268" source="SECUNIA">15268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woppoware" name="postmaster">
        <vers num="4.2.2_build3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1653" published="2005-05-18" name="CVE-2005-1653" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13597" source="BID">13597</ref>
      <ref url="http://secunia.com/advisories/15268" source="SECUNIA">15268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woppoware" name="postmaster">
        <vers num="4.2.2_build3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1654" published="2005-05-18" name="CVE-2005-1654" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://isun.shabgard.org/hc3.txt" source="MISC" patch="1">http://isun.shabgard.org/hc3.txt</ref>
      <ref url="http://secunia.com/advisories/15271" source="SECUNIA">15271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="6.1_hotfix_1.4" />
        <vers num="6.1_hotfix_1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1655" published="2005-05-18" name="CVE-2005-1655" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13553" source="BID">13553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="1.2" />
        <vers num="2.0.912" />
        <vers num="2.0.996" />
        <vers num="2.0_n" />
        <vers num="2.1.1236" />
        <vers num="2.5.1366" />
        <vers num="2.5.1598" />
        <vers num="3.0.1415" />
        <vers num="3.0.1470" />
        <vers num="3.0_n" />
        <vers num="3.5.1635" />
        <vers num="3.5.1670" />
        <vers num="3.5.1808" />
        <vers num="3.5.1856" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.2010" />
        <vers num="4.2" />
        <vers num="4.2.1193" />
        <vers num="4.3" />
        <vers num="4.3.2229" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.7.2480" />
        <vers num="4.8.2616" />
        <vers num="4.8.2646" />
        <vers num="4.8.2790" />
        <vers num="5.0.2938" />
        <vers num="5.1.3036" />
        <vers num="5.2.3292" />
        <vers num="5.5" />
        <vers num="5.5.3415_beta" />
        <vers num="5.5.3595" />
        <vers num="5.9.3702" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1656" published="2005-05-18" name="CVE-2005-1656" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mercur Messaging 2005 SP2 allows remote attackers to read the source code of .ctml files via a URL with a trailing hex-encoded space ("%20").</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16218" source="OSVDB">16218</ref>
      <ref url="http://secunia.com/advisories/15234" source="SECUNIA">15234</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercur" name="mercur_messaging">
        <vers num="2005_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1657" published="2005-05-18" name="CVE-2005-1657" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) deletemessage.ctml, (3) origmessage.ctml, or (4) readmessage.ctml, the Message.Id parameter to editmessage.ctml, or the (5) Message.Command parameter to messages.ctml.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16225" source="OSVDB">16225</ref>
      <ref url="http://www.osvdb.org/16224" source="OSVDB">16224</ref>
      <ref url="http://www.osvdb.org/16223" source="OSVDB">16223</ref>
      <ref url="http://www.osvdb.org/16222" source="OSVDB">16222</ref>
      <ref url="http://www.osvdb.org/16221" source="OSVDB">16221</ref>
      <ref url="http://www.osvdb.org/16220" source="OSVDB">16220</ref>
      <ref url="http://secunia.com/advisories/15234" source="SECUNIA">15234</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercur" name="mercur_messaging">
        <vers num="2005_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1658" published="2005-05-18" name="CVE-2005-1658" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to list the parent directory of the web root via a URL with a "..."  (triple dot).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15274" source="SECUNIA">15274</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/myserverweb/myserverweb/source/filemanager.cpp?rev=1.116&amp;view=log" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/myserverweb/myserverweb/source/filemanager.cpp?rev=1.116&amp;view=log</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myserver" name="myserver">
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1659" published="2005-05-18" name="CVE-2005-1659" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to inject arbitrary Javascript via a URL with a "..."  (triple dot) followed by an onmouseover event.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15274" source="SECUNIA" patch="1">15274</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/myserverweb/myserverweb/source/filemanager.cpp?rev=1.116&amp;view=log" source="CONFIRM" patch="1">http://cvs.sourceforge.net/viewcvs.py/myserverweb/myserverweb/source/filemanager.cpp?rev=1.116&amp;view=log</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1660" published="2005-05-18" name="CVE-2005-1660" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20487" source="XF">htmljunction-database-disclosure(20487)</ref>
      <ref url="http://www.osvdb.org/16444" source="OSVDB">16444</ref>
      <ref url="http://securitytracker.com/id?1013912" source="SECTRACK">1013912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htmljunction" name="ezguestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1661" published="2005-05-18" name="CVE-2005-1661" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jeuce Personal Webserver 2.13 allows remote attackers to cause a denial of service (server crash) via a long GET request, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16453" source="OSVDB">16453</ref>
      <ref url="http://users.pandora.be/bratax/advisories/b005.html" source="MISC">http://users.pandora.be/bratax/advisories/b005.html</ref>
      <ref url="http://securitytracker.com/id?1013902" source="SECTRACK">1013902</ref>
      <ref url="http://secunia.com/advisories/13732" source="SECUNIA" adv="1">13732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jeuce" name="jeuce_personal_web_server">
        <vers num="2.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1662" published="2005-05-18" name="CVE-2005-1662" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Jeuce Personal Web Server 2.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18787" source="XF">jeuce-dotdot-directory-traversal(18787)</ref>
      <ref url="http://www.securityfocus.com/bid/12183" source="BID">12183</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5JP011PEKY.html" source="MISC">http://www.securiteam.com/windowsntfocus/5JP011PEKY.html</ref>
      <ref url="http://www.osvdb.org/12718" source="OSVDB">12718</ref>
      <ref url="http://securitytracker.com/id?1012791" source="SECTRACK">1012791</ref>
      <ref url="http://secunia.com/advisories/13732" source="SECUNIA">13732</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1663" published="2005-05-18" name="CVE-2005-1663" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jeuce Personal Web Server 2.13 allows remote attackers to cause a denial of service (server crash) via a GET request beginning with "://".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18791" source="XF">jeuce-url-dos(18791)</ref>
      <ref url="http://www.securityfocus.com/bid/12183" source="BID">12183</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5JP011PEKY.html" source="MISC">http://www.securiteam.com/windowsntfocus/5JP011PEKY.html</ref>
      <ref url="http://www.osvdb.org/12719" source="OSVDB">12719</ref>
      <ref url="http://securitytracker.com/id?1012791" source="SECTRACK">1012791</ref>
      <ref url="http://secunia.com/advisories/13732" source="SECUNIA">13732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jeuce" name="jeuce_personal_web_server">
        <vers num="2.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1664" published="2005-05-18" name="CVE-2005-1664" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) reuse ViewState information after the application's state has changed, or (3) use the ViewState to conduct attacks or expose content to third parties.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20409" source="XF">ms-aspnet-viewstate-replay(20409)</ref>
      <ref url="http://www.osvdb.org/16196" source="OSVDB">16196</ref>
      <ref url="http://secunia.com/advisories/15241" source="SECUNIA" adv="1">15241</ref>
      <ref url="http://scottonwriting.net/sowblog/posts/3747.aspx" source="MISC">http://scottonwriting.net/sowblog/posts/3747.aspx</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111532887612517&amp;w=2" source="BUGTRAQ">20050505 Re: ASP.NET __VIEWSTATE crypto validation prone to replay attacks</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111513127704270&amp;w=2" source="BUGTRAQ" adv="1">20050503 ASP.NET __VIEWSTATE crypto validation prone to replay attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1665" published="2005-05-18" name="CVE-2005-1665" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20408" source="XF">ms-aspnet-viewstate-dos(20408)</ref>
      <ref url="http://www.osvdb.org/16195" source="OSVDB">16195</ref>
      <ref url="http://secunia.com/advisories/15241" source="SECUNIA" adv="1">15241</ref>
      <ref url="http://scottonwriting.net/sowblog/posts/3747.aspx" source="MISC" adv="1">http://scottonwriting.net/sowblog/posts/3747.aspx</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111513127704270&amp;w=2" source="BUGTRAQ">20050503 ASP.NET __VIEWSTATE crypto validation prone to replay attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1666" published="2005-05-18" name="CVE-2005-1666" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1) ftp_xlate_path, (2) ftp_is_canonical, or (3) os_fn_nativize functions, or (4) a long SSI command that is processed by the parse_cmd function in cgissi.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13549" source="BID" patch="1">13549</ref>
      <ref url="http://www.securityfocus.com/bid/13546" source="BID" patch="1">13546</ref>
      <ref url="http://securitytracker.com/id?1013923" source="SECTRACK" patch="1">1013923</ref>
      <ref url="http://hp.vector.co.jp/authors/VA027031/orenosv/index_en.html" source="CONFIRM" patch="1">http://hp.vector.co.jp/authors/VA027031/orenosv/index_en.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20512" source="XF" adv="1">orenosv-http-ftp-cgissi-bo(20512)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20510" source="XF" adv="1">orenosv-http-ftp-commands-bo(20510)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0499" source="VUPEN">ADV-2005-0499</ref>
      <ref url="http://www.security.org.sg/vuln/orenosv081.html" source="MISC" adv="1">http://www.security.org.sg/vuln/orenosv081.html</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5FP0H00FPS.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5FP0H00FPS.html</ref>
      <ref url="http://www.osvdb.org/16166" source="OSVDB">16166</ref>
      <ref url="http://www.osvdb.org/16165" source="OSVDB">16165</ref>
      <ref url="http://secunia.com/advisories/15302" source="SECUNIA" adv="1">15302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orenosv" name="orenosv_http_ftp_server">
        <vers prev="1" num="0.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1667" published="2005-05-18" name="CVE-2005-1667" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13558" source="BID">13558</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5FP052AFPA.html" source="MISC">http://www.securiteam.com/windowsntfocus/5FP052AFPA.html</ref>
      <ref url="http://www.osvdb.org/16168" source="OSVDB">16168</ref>
      <ref url="http://secunia.com/advisories/15291" source="SECUNIA">15291</ref>
      <ref url="http://milw0rm.com/exploits/983" source="MILW0RM">983</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datatrac" name="activity_console">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1668" published="2005-05-18" name="CVE-2005-1668" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/windowsntfocus/5OP0115FPQ.html" source="MISC" patch="1">http://www.securiteam.com/windowsntfocus/5OP0115FPQ.html</ref>
      <ref url="http://www.securityfocus.com/bid/13501" source="BID">13501</ref>
      <ref url="http://www.osvdb.org/16198" source="OSVDB">16198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yusasp" name="web_asset_manager">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1669" published="2005-06-16" name="CVE-2005-1669" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via "javascript:" URLs when a new window or frame is opened, which allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2005-5/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-5/advisory/</ref>
      <ref url="http://secunia.com/advisories/15411" source="SECUNIA" patch="1" adv="1">15411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="8.0_final_build_1095" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1670" published="2005-05-19" name="CVE-2005-1670" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Extreme BlackDiamond 10808 and 8800 switches running ExtremeWare XOS 11.1 before 11.1.3.3, 11.0 before 11.0.2.4, and 10.x allows remote authenticated users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/937838" source="CERT-VN" patch="1" adv="1">VU#937838</ref>
      <ref url="http://www.extremenetworks.com/services/documentation/FieldNotices_FN0215-Security_Alert_EXOS.asp" source="CONFIRM" patch="1">http://www.extremenetworks.com/services/documentation/FieldNotices_FN0215-Security_Alert_EXOS.asp</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0572" source="VUPEN">ADV-2005-0572</ref>
      <ref url="http://secunia.com/advisories/15438" source="SECUNIA" adv="1">15438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extremenetworks" name="blackdiamond_10808">
        <vers num="" />
      </prod>
      <prod vendor="extremenetworks" name="blackdiamond_8800">
        <vers num="" />
      </prod>
      <prod vendor="extremenetworks" name="extremeware_xos">
        <vers num="10.0" />
        <vers prev="1" num="11.0.2.3" />
        <vers num="11.1" />
        <vers prev="1" num="11.1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1671" published="2005-05-19" name="CVE-2005-1671" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111643475210982&amp;w=2" source="BUGTRAQ" adv="1">20050518 Yahoo! Messenger may be storing all session data 'Unencoded' on the local machine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.6.0.1351" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1672" published="2005-05-19" name="CVE-2005-1672" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/398457" source="BUGTRAQ" patch="1" adv="1">20050517 Help Center Live Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubertec" name="help_center_live">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1673" published="2005-05-19" name="CVE-2005-1673" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php or (7) view.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0" source="BUGTRAQ" patch="1" adv="1">20050517 Help Center Live Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubertec" name="help_center_live">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1674" published="2005-05-19" name="CVE-2005-1674" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0" source="BUGTRAQ" patch="1" adv="1">20050517 Help Center Live Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubertec" name="help_center_live">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1675" published="2005-05-20" name="CVE-2005-1675" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBODY permissions, which allows local users to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BCRBX" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/JGEI-6BCRBX</ref>
      <ref url="http://www.kb.cert.org/vuls/id/443370" source="CERT-VN" adv="1">VU#443370</ref>
      <ref url="http://secunia.com/advisories/15421" source="SECUNIA" patch="1" adv="1">15421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="groove" name="groove_workspace">
        <vers prev="1" num="2.5n_build_1871" />
      </prod>
      <prod vendor="groove" name="virtual_office">
        <vers prev="1" num="3.1_build_2338" />
        <vers prev="1" num="3.1a_build_2364" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1676" published="2005-05-20" name="CVE-2005-1676" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allow remote attackers to inject arbitrary web script or HTML via the (1) picture columns embedded within SharePoint lists or (2) drop-down menus in a SharePoint list.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BCRCC" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/JGEI-6BCRCC</ref>
      <ref url="http://www.kb.cert.org/vuls/id/514386" source="CERT-VN" adv="1">VU#514386</ref>
      <ref url="http://www.kb.cert.org/vuls/id/372618" source="CERT-VN" adv="1">VU#372618</ref>
      <ref url="http://secunia.com/advisories/15421" source="SECUNIA" patch="1" adv="1">15421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="groove" name="groove_workspace">
        <vers prev="1" num="2.5n_build_1871" />
      </prod>
      <prod vendor="groove" name="virtual_office">
        <vers prev="1" num="3.1_build_2338" />
        <vers prev="1" num="3.1a_build_2364" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1677" published="2005-05-20" name="CVE-2005-1677" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BCRCM" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/JGEI-6BCRCM</ref>
      <ref url="http://www.kb.cert.org/vuls/id/155610" source="CERT-VN" adv="1">VU#155610</ref>
      <ref url="http://secunia.com/advisories/15421" source="SECUNIA" patch="1" adv="1">15421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="groove" name="groove_workspace">
        <vers prev="1" num="2.5n_build_1871" />
      </prod>
      <prod vendor="groove" name="virtual_office">
        <vers prev="1" num="3.1_build_2338" />
        <vers prev="1" num="3.1a_build_2364" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1678" published="2005-05-20" name="CVE-2005-1678" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick users into executing malicious code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BCRD6" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/JGEI-6BCRD6</ref>
      <ref url="http://www.kb.cert.org/vuls/id/232232" source="CERT-VN" adv="1">VU#232232</ref>
      <ref url="http://secunia.com/advisories/15421" source="SECUNIA" patch="1" adv="1">15421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="groove" name="groove_workspace">
        <vers prev="1" num="2.5n_build_1871" />
      </prod>
      <prod vendor="groove" name="virtual_office">
        <vers prev="1" num="3.1_build_2338" />
        <vers prev="1" num="3.1a_build_2364" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1679" published="2005-05-20" name="CVE-2005-1679" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary code via a long error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.co.jyu.fi/~trossi/pic/" source="CONFIRM" patch="1">http://www.co.jyu.fi/~trossi/pic/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661253517089&amp;w=2" source="BUGTRAQ" patch="1">20050520 picasm error handling stack overflow vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/13698" source="BID">13698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="timo_rossi" name="picasm">
        <vers prev="1" num="1.12b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1680" published="2005-05-20" name="CVE-2005-1680" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">D-Link DSL-502T, DSL-504T, DSL-562T, and DSL-G604T, when /cgi-bin/firmwarecfg is executed, allows remote attackers to bypass authentication (1) if their IP address already exists in /var/tmp/fw_ip or (2) if their request is the first, which causes /var/tmp/fw_ip to be created and contain their IP address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0573" source="VUPEN">ADV-2005-0573</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111652806030943&amp;w=2" source="BUGTRAQ">20050519 D-Link DSL routers authentication bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="dsl-502t">
        <vers num="" />
      </prod>
      <prod vendor="d-link" name="dsl-504t">
        <vers num="" />
      </prod>
      <prod vendor="d-link" name="dsl-562t">
        <vers num="" />
      </prod>
      <prod vendor="d-link" name="dsl-g604t">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1681" published="2005-05-20" name="CVE-2005-1681" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16692" source="OSVDB">16692</ref>
      <ref url="http://securitytracker.com/id?1014008" source="SECTRACK">1014008</ref>
      <ref url="http://secunia.com/advisories/15420" source="SECUNIA">15420</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111653168810937&amp;w=2" source="BUGTRAQ">20050519 phpATM arbitrary PHP code inclusion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bugada_andrea" name="php_advanced_transfer_manager">
        <vers num="1.20" />
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1682" published="2005-05-20" name="CVE-2005-1682" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">** DISPUTED **  JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users' e-mail messages by modifying the msgno parameter.  NOTE: Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0574" source="VUPEN" adv="1">ADV-2005-0574</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111653029605189&amp;w=2" source="BUGTRAQ">20050519 JavaMail Information Disclosure (msgno)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="solstice" name="solstice_internet_mail_server">
        <vers num="pop3_2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1683" published="2005-05-20" name="CVE-2005-1683" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13687" source="BID">13687</ref>
      <ref url="http://www.securityfocus.com/archive/1/398649" source="BUGTRAQ">20050521 [UPDATE] UNICODE BUFFER OVERFLOW IN MS-WORD</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111653088303057&amp;w=2" source="BUGTRAQ">20050519 UNICODE BUFFER OVERFLOW IN MS-WORD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1684" published="2005-05-20" name="CVE-2005-1684" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp for episodex guestbook allows remote attackers to inject arbitrary web script or HTML via the Name field and other fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661380018313&amp;w=2" source="BUGTRAQ">20050520 episodex guestbook security bypass &amp; html injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="episodex" name="episodex_guestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1685" published="2005-05-20" name="CVE-2005-1685" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661380018313&amp;w=2" source="BUGTRAQ">20050520 episodex guestbook security bypass &amp; html injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="episodex" name="episodex_guestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1686" published="2005-05-20" name="CVE-2005-1686" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-138-1" source="UBUNTU">USN-138-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-499.html" source="REDHAT">RHSA-2005:499</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-09.xml" source="GENTOO">GLSA-200506-09</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9845" source="OVAL">oval:org.mitre.oval:def:9845</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661117701398&amp;w=2" source="BUGTRAQ">20050520 pst.advisory: gedit fun. opensource is god .lol windows</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.debian.org/security/2005/dsa-753" source="DEBIAN">DSA-753</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1245" source="OVAL" sig="1">oval:org.mitre.oval:def:1245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gedit">
        <vers num="2.10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1687" published="2005-05-20" name="CVE-2005-1687" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661517716733&amp;w=2" source="BUGTRAQ" patch="1">20050520 [BuHa Security] Wordpress SQL-Injection</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-04.xml" source="GENTOO">GLSA-200506-04</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=88926" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=88926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1688" published="2005-05-20" name="CVE-2005-1688" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661517716733&amp;w=2" source="BUGTRAQ" patch="1">20050520 [BuHa Security] Wordpress SQL-Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1689" published="2005-07-18" name="CVE-2005-1689" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/623332" source="CERT-VN" patch="1" adv="1">VU#623332</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-11.xml" source="GENTOO" patch="1" adv="1">GLSA-200507-11</ref>
      <ref url="http://www.debian.org/security/2005/dsa-757" source="DEBIAN" patch="1" adv="1">DSA-757</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21055" source="XF">kerberos-kdc-krb5recvauth-execute-code(21055)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3776" source="VUPEN">ADV-2006-3776</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1066" source="VUPEN">ADV-2005-1066</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1" source="UBUNTU">USN-224-1</ref>
      <ref url="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt" source="TURBO">TLSA-2005-78</ref>
      <ref url="http://www.trustix.org/errata/2005/0036" source="TRUSTIX">2005-0036</ref>
      <ref url="http://www.securityfocus.com/bid/14239" source="BID">14239</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded" source="HP">HPSBUX02152</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded" source="HP">HPSBUX02152</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-567.html" source="REDHAT">RHSA-2005:567</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-562.html" source="REDHAT">RHSA-2005:562</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_sr.html" source="SUSE">SUSE-SR:2005:017</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt" source="CONFIRM">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101810-1" source="SUNALERT">101810</ref>
      <ref url="http://securitytracker.com/id?1014461" source="SECTRACK">1014461</ref>
      <ref url="http://secunia.com/advisories/22090" source="SECUNIA" adv="1">22090</ref>
      <ref url="http://secunia.com/advisories/17899" source="SECUNIA" adv="1">17899</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA" adv="1">17135</ref>
      <ref url="http://secunia.com/advisories/16041" source="SECUNIA" adv="1">16041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9819" source="OVAL">oval:org.mitre.oval:def:9819</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112119974704542&amp;w=2" source="BUGTRAQ">20050712 MITKRB5-SA-2005-003: double-free in krb5_recvauth</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000993" source="CONECTIVA">CLA-2005:993</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc" source="SGI">20050703-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.3" />
        <vers num="5-1.3.1" />
        <vers num="5-1.3.2" />
        <vers num="5-1.3.3" />
        <vers num="5-1.3.4" />
        <vers num="5-1.3.5" />
        <vers num="5-1.3.6" />
        <vers num="5-1.4" />
        <vers num="5-1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1690" reject="1" published="2005-06-30" name="CVE-2005-1690" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1250.  Reason: This candidate is a duplicate of CVE-2005-1250.  Notes: this duplicate occurred as a result of multiple independent discoveries and insufficient coordination by the vendor and CNA.  All CVE users should reference CVE-2005-1250 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1691" published="2005-07-26" name="CVE-2005-1691" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via ".." sequences in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.corsaire.com/advisories/c050503-001.txt" source="MISC" adv="1">http://www.corsaire.com/advisories/c050503-001.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_r_3">
        <vers prev="1" num="6.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1692" published="2005-05-24" name="CVE-2005-1692" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0626" source="VUPEN">ADV-2005-0626</ref>
      <ref url="http://www.securityfocus.com/bid/13707" source="BID">13707</ref>
      <ref url="http://www.osvdb.org/16747" source="OSVDB">16747</ref>
      <ref url="http://www.0xbadexworm.org/adv/gxinefmt.txt" source="MISC">http://www.0xbadexworm.org/adv/gxinefmt.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200505-19.xml" source="GENTOO">GLSA-200505-19</ref>
      <ref url="http://secunia.com/advisories/15451" source="SECUNIA">15451</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670637812128&amp;w=2" source="BUGTRAQ" adv="1">20050521 pst.advisory 2005-21: gxine remote exploitable . opensource is god .lol windows</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/xine/gnome-xine/ChangeLog?rev=HEAD&amp;content-type=text/vnd.viewcvs-markup" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/xine/gnome-xine/ChangeLog?rev=HEAD&amp;content-type=text/vnd.viewcvs-markup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="gxine">
        <vers num="0.41" />
        <vers num="0.42" />
        <vers num="0.43" />
        <vers num="0.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1693" published="2005-05-24" name="CVE-2005-1693" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32896" source="MISC" patch="1" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32896</ref>
      <ref url="http://crm.my-etrust.com/login.asp?username=guest&amp;target=DOCUMENT&amp;openparameter=1588" source="CONFIRM" patch="1">http://crm.my-etrust.com/login.asp?username=guest&amp;target=DOCUMENT&amp;openparameter=1588</ref>
      <ref url="http://www.securityfocus.com/bid/13710" source="BID" adv="1">13710</ref>
      <ref url="http://www.rem0te.com/public/images/vet.pdf" source="MISC">http://www.rem0te.com/public/images/vet.pdf</ref>
      <ref url="http://securitytracker.com/id?1014050" source="SECTRACK">1014050</ref>
      <ref url="http://secunia.com/advisories/15479" source="SECUNIA">15479</ref>
      <ref url="http://secunia.com/advisories/15470" source="SECUNIA">15470</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686576416450&amp;w=2" source="BUGTRAQ">20050523 Computer Associates Vet Antivirus Library Remote Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" edition="" />
        <vers num="11.1" edition=":windows" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus">
        <vers num="6.0" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":gateway" />
        <vers num="7.0_sp2" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":gateway" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus_ee">
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.4.4" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor_le">
        <vers num="2.0" />
        <vers num="3.0.0.14" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="1.4.1.13" />
        <vers num="1.4.5" />
        <vers num="1.5" />
        <vers num="3.0" edition="sp1" />
      </prod>
      <prod vendor="ca" name="etrust_secure_content_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.1" />
      </prod>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
      <prod vendor="ca" name="vet_antivirus">
        <vers num="10.66" />
      </prod>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="" />
      </prod>
      <prod vendor="zonelabs" name="zonealarm_antivirus">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1694" published="2005-05-24" name="CVE-2005-1694" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691" source="CONFIRM" patch="1" adv="1">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670823128472&amp;w=2" source="BUGTRAQ" patch="1">20050521 [SECURITYREASON.COM] PostNuke SQL Injection 0.750=>x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1695" published="2005-05-24" name="CVE-2005-1695" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_url parameter to magpie_slashbox.php, or the url parameter to (2) magpie_simple.php or (3) magpie_debug.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691" source="CONFIRM" patch="1" adv="1">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670506926649&amp;w=2" source="BUGTRAQ" patch="1">20050521 [SECURITYREASON.COM] PostNuke XSS and Full path disclosure</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670482500552&amp;w=2" source="BUGTRAQ" adv="1">20050521 [SECURITYREASON.COM] PostNuke XSS 0.760{RC2,RC3}</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
        <vers num="0.760_rc2" />
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1696" published="2005-05-24" name="CVE-2005-1696" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.750 and 0.760RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) skin or (2) paletteid parameter to demo.php in the Xanthia module, or (3) the serverName parameter to config.php in the Multisites (aka NS-Multisites) module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691" source="CONFIRM" patch="1" adv="1">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670506926649&amp;w=2" source="BUGTRAQ" patch="1">20050521 [SECURITYREASON.COM] PostNuke XSS and Full path disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1697" published="2005-05-24" name="CVE-2005-1697" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670482500552&amp;w=2" source="BUGTRAQ" adv="1">20050521 [SECURITYREASON.COM] PostNuke XSS 0.760{RC2,RC3}</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
        <vers num="0.760_rc2" />
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1698" published="2005-05-24" name="CVE-2005-1698" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9) button.php in the pnblocks directory in the Blocks module, (10) config.php in the NS-Multisites (aka Multisites) module, or (11) xmlrpc.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670506926649&amp;w=2" source="BUGTRAQ" patch="1">20050521 [SECURITYREASON.COM] PostNuke XSS and Full path disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1699" published="2005-05-24" name="CVE-2005-1699" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670586322172&amp;w=2" source="BUGTRAQ" patch="1">20050521 [SECURITYREASON.COM] PostNuke Non Critical SQL Injection and Include 0.760-RC3=>x cXIb8O3.10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1700" published="2005-05-24" name="CVE-2005-1700" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670586322172&amp;w=2" source="BUGTRAQ" patch="1">20050521 [SECURITYREASON.COM] PostNuke Non Critical SQL Injection and Include 0.760-RC3=>x cXIb8O3.10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.760_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1701" published="2005-05-24" name="CVE-2005-1701" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to the (1) News, (2) File, (3) Liens, or (4) Faq modules.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13708" source="BID">13708</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686643823025&amp;w=2" source="BUGTRAQ">20050521 SQL injections in PortailPHP</ref>
      <ref url="http://securitytracker.com/id?1014036" source="SECTRACK">1014036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="portailphp" name="portailphp">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1702" published="2005-05-24" name="CVE-2005-1702" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13711" source="BID">13711</ref>
      <ref url="http://aluigi.altervista.org/adv/warkings-adv.txt" source="MISC">http://aluigi.altervista.org/adv/warkings-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1014041" source="SECTRACK">1014041</ref>
      <ref url="http://securitytracker.com/id?1014040" source="SECTRACK">1014040</ref>
      <ref url="http://secunia.com/advisories/15482" source="SECUNIA">15482</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686776303832&amp;w=2" source="BUGTRAQ">20050523 Format string and crash in Warrior Kings 1.3 and Battles 1.23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="black_cactus" name="warrior_kings">
        <vers prev="1" num="1.3" />
      </prod>
      <prod vendor="black_cactus" name="warrior_kings_battles">
        <vers prev="1" num="1.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1703" published="2005-05-24" name="CVE-2005-1703" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13712" source="BID">13712</ref>
      <ref url="http://aluigi.altervista.org/adv/warkings-adv.txt" source="MISC">http://aluigi.altervista.org/adv/warkings-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1014041" source="SECTRACK">1014041</ref>
      <ref url="http://securitytracker.com/id?1014040" source="SECTRACK">1014040</ref>
      <ref url="http://secunia.com/advisories/15482" source="SECUNIA">15482</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686776303832&amp;w=2" source="BUGTRAQ">20050523 Format string and crash in Warrior Kings 1.3 and Battles 1.23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="black_cactus" name="warrior_kings_battles">
        <vers num="1.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1704" published="2005-05-24" name="CVE-2005-1704" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1267" source="VUPEN" adv="1">ADV-2007-1267</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-55052-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-55052-patch.html</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-136-1" source="UBUNTU">USN-136-1</ref>
      <ref url="http://www.trustix.org/errata/2005/0025/" source="TRUSTIX">2005-0025</ref>
      <ref url="http://www.securityfocus.com/bid/13697" source="BID">13697</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded" source="BUGTRAQ">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0368.html" source="REDHAT">RHSA-2006:0368</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0354.html" source="REDHAT">RHSA-2006:0354</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-801.html" source="REDHAT" adv="1">RHSA-2005:801</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-763.html" source="REDHAT" adv="1">RHSA-2005:763</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-709.html" source="REDHAT" adv="1">RHSA-2005:709</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-673.html" source="REDHAT" adv="1">RHSA-2005:673</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-659.html" source="REDHAT" adv="1">RHSA-2005:659</ref>
      <ref url="http://www.osvdb.org/16757" source="OSVDB">16757</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:215" source="MANDRAKE">MDKSA-2005:215</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:095" source="MANDRAKE">MDKSA-2005:095</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-01.xml" source="GENTOO">GLSA-200506-01</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-178.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-178.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-015.htm" source="SECUNIA">18506</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-222.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-222.pdf</ref>
      <ref url="http://securitytracker.com/id?1016544" source="SECTRACK">1016544</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200505-15.xml" source="GENTOO" adv="1">GLSA-200505-15</ref>
      <ref url="http://secunia.com/advisories/24788" source="SECUNIA" adv="1">24788</ref>
      <ref url="http://secunia.com/advisories/21717" source="SECUNIA" adv="1">21717</ref>
      <ref url="http://secunia.com/advisories/21262" source="SECUNIA" adv="1">21262</ref>
      <ref url="http://secunia.com/advisories/21122" source="SECUNIA" adv="1">21122</ref>
      <ref url="http://secunia.com/advisories/17718" source="SECUNIA" adv="1">17718</ref>
      <ref url="http://secunia.com/advisories/17356" source="SECUNIA" adv="1">17356</ref>
      <ref url="http://secunia.com/advisories/17257" source="SECUNIA" adv="1">17257</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA" adv="1">17135</ref>
      <ref url="http://secunia.com/advisories/17072" source="SECUNIA" adv="1">17072</ref>
      <ref url="http://secunia.com/advisories/17001" source="SECUNIA" adv="1">17001</ref>
      <ref url="http://secunia.com/advisories/15527" source="SECUNIA" adv="1">15527</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9071" source="OVAL">oval:org.mitre.oval:def:9071</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001060" source="CONECTIVA">CLA-2006:1060</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=91398" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=91398</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc" source="SGI">20060703-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gdb">
        <vers prev="1" num="6.3" edition="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1705" published="2005-05-24" name="CVE-2005-1705" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-801.html" source="REDHAT" patch="1" adv="1">RHSA-2005:801</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-709.html" source="REDHAT" patch="1" adv="1">RHSA-2005:709</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:095" source="MANDRAKE" patch="1" adv="1">MDKSA-2005:095</ref>
      <ref url="http://secunia.com/advisories/17072" source="SECUNIA" patch="1" adv="1">17072</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-015.htm" source="SECUNIA">18506</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200505-15.xml" source="GENTOO" adv="1">GLSA-200505-15</ref>
      <ref url="http://secunia.com/advisories/17356" source="SECUNIA">17356</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11072" source="OVAL">oval:org.mitre.oval:def:11072</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=88398" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=88398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gdb">
        <vers prev="1" num="6.3" edition="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1706" published="2005-05-24" name="CVE-2005-1706" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has released a fixed version (4.42.2)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.sng.ecs.soton.ac.uk/mailscanner/ChangeLog" source="CONFIRM">http://www.sng.ecs.soton.ac.uk/mailscanner/ChangeLog</ref>
      <ref url="http://securitytracker.com/id?1014024" source="SECTRACK">1014024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailscanner" name="mailscanner">
        <vers num="4.39.1" />
        <vers num="4.39.4" />
        <vers num="4.39.6" />
        <vers num="4.40.1" />
        <vers num="4.40.11" />
        <vers num="4.40.2" />
        <vers num="4.40.4" />
        <vers num="4.40.6" />
        <vers num="4.40.7" />
        <vers num="4.40.8" />
        <vers num="4.41.1" />
        <vers num="4.41.2" />
        <vers prev="1" num="4.41.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1707" published="2005-05-24" name="CVE-2005-1707" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014027" source="SECTRACK" patch="1">1014027</ref>
      <ref url="http://www.zataz.net/adviso/webapp-config-05182005.txt" source="MISC" adv="1">http://www.zataz.net/adviso/webapp-config-05182005.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0809" source="VUPEN">ADV-2005-0809</ref>
      <ref url="http://www.securityfocus.com/bid/13780" source="BID">13780</ref>
      <ref url="http://www.osvdb.org/16746" source="OSVDB">16746</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-13.xml" source="GENTOO">GLSA-200506-13</ref>
      <ref url="http://secunia.com/advisories/15445" source="SECUNIA" adv="1">15445</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=91785" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=91785</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux_webapp-config">
        <vers num="1.10" edition="r14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1708" published="2005-05-24" name="CVE-2005-1708" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html" source="CONFIRM" patch="1">http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0589" source="VUPEN">ADV-2005-0589</ref>
      <ref url="http://www.securityfocus.com/bid/13723" source="BID">13723</ref>
      <ref url="http://www.osvdb.org/16763" source="OSVDB">16763</ref>
      <ref url="http://secunia.com/advisories/15452" source="SECUNIA" adv="1">15452</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695726810435&amp;w=2" source="BUGTRAQ">20050524 Blue Coat Reporter multiple remote vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluecoat" name="reporter">
        <vers prev="1" num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1709" published="2005-05-24" name="CVE-2005-1709" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html" source="CONFIRM" patch="1">http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0589" source="VUPEN">ADV-2005-0589</ref>
      <ref url="http://www.securityfocus.com/bid/13725" source="BID">13725</ref>
      <ref url="http://www.osvdb.org/16764" source="OSVDB">16764</ref>
      <ref url="http://secunia.com/advisories/15452" source="SECUNIA" adv="1">15452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluecoat" name="reporter">
        <vers prev="1" num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1710" published="2005-05-24" name="CVE-2005-1710" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html" source="CONFIRM" patch="1">http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0589" source="VUPEN">ADV-2005-0589</ref>
      <ref url="http://www.osvdb.org/16766" source="OSVDB">16766</ref>
      <ref url="http://www.osvdb.org/16765" source="OSVDB">16765</ref>
      <ref url="http://secunia.com/advisories/15452" source="SECUNIA" adv="1">15452</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695726810435&amp;w=2" source="BUGTRAQ">20050524 Blue Coat Reporter multiple remote vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluecoat" name="reporter">
        <vers prev="1" num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1711" published="2005-05-24" name="CVE-2005-1711" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014030" source="SECTRACK" patch="1">1014030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.90.2" />
      </prod>
      <prod vendor="gibraltar" name="gibraltar_firewall">
        <vers num="2.2" />
      </prod>
      <prod vendor="squid" name="squid">
        <vers num="2.6.stable1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1712" published="2005-05-24" name="CVE-2005-1712" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Serendipity 0.8, when used with multiple authors, allows unprivileged authors to upload arbitrary media files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=328092" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=328092</ref>
      <ref url="http://secunia.com/advisories/15405" source="SECUNIA" patch="1">15405</ref>
      <ref url="http://www.osvdb.org/16659" source="OSVDB">16659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sy9" name="serendipity">
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1713" published="2005-05-24" name="CVE-2005-1713" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16660" source="OSVDB" patch="1">16660</ref>
      <ref url="http://secunia.com/advisories/15405" source="SECUNIA" patch="1">15405</ref>
      <ref url="http://www.osvdb.org/16661" source="OSVDB" adv="1">16661</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=328092" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=328092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1714" published="2005-05-24" name="CVE-2005-1714" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15425" source="SECUNIA" patch="1">15425</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0576" source="VUPEN">ADV-2005-0576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="surgemail">
        <vers num="3.0c2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1715" published="2005-05-24" name="CVE-2005-1715" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in the comments section.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lostmon.blogspot.com/2005/05/topo-22-multiple-variable-fields-xss.html" source="MISC" patch="1">http://lostmon.blogspot.com/2005/05/topo-22-multiple-variable-fields-xss.html</ref>
      <ref url="http://www.securityfocus.com/bid/13701" source="BID">13701</ref>
      <ref url="http://www.securityfocus.com/bid/13700" source="BID">13700</ref>
      <ref url="http://www.osvdb.org/16699" source="OSVDB">16699</ref>
      <ref url="http://securitytracker.com/id?1014016" source="SECTRACK">1014016</ref>
      <ref url="http://secunia.com/advisories/15325" source="SECUNIA">15325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ej3" name="topo">
        <vers num="2.2" />
        <vers num="2.2.178" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1716" published="2005-05-24" name="CVE-2005-1716" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16700" source="OSVDB">16700</ref>
      <ref url="http://securitytracker.com/id?1014016" source="SECTRACK">1014016</ref>
      <ref url="http://secunia.com/advisories/15325" source="SECUNIA">15325</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/topo-22-multiple-variable-fields-xss.html" source="MISC">http://lostmon.blogspot.com/2005/05/topo-22-multiple-variable-fields-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ej3" name="topo">
        <vers num="2.2" />
        <vers num="2.2.178" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1717" published="2005-05-24" name="CVE-2005-1717" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13703" source="BID">13703</ref>
      <ref url="http://www.osvdb.org/16779" source="OSVDB" adv="1">16779</ref>
      <ref url="http://www.infobyte.com.ar/adv/ISR-10.html" source="MISC" adv="1">http://www.infobyte.com.ar/adv/ISR-10.html</ref>
      <ref url="http://secunia.com/advisories/15463" source="SECUNIA" adv="1">15463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zyxel" name="prestige_650r-31">
        <vers num="3.40_ko.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1718" published="2005-05-24" name="CVE-2005-1718" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16619" source="OSVDB">16619</ref>
      <ref url="http://securitytracker.com/id?1013981" source="SECTRACK">1013981</ref>
      <ref url="http://secunia.com/advisories/15363" source="SECUNIA">15363</ref>
      <ref url="http://aluigi.altervista.org/adv/wartimesboom-adv.txt" source="MISC">http://aluigi.altervista.org/adv/wartimesboom-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ls_games" name="war_times">
        <vers num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1719" published="2005-05-24" name="CVE-2005-1719" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.avast.com/eng/av4_revision_history.html" source="MISC" patch="1">http://www.avast.com/eng/av4_revision_history.html</ref>
      <ref url="http://securitytracker.com/id?1013991" source="SECTRACK" adv="1">1013991</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alwil" name="avast_antivirus">
        <vers num="4.0.168" />
        <vers num="4.0.172" />
        <vers num="4.0.183" />
        <vers num="4.0.202" />
        <vers num="4.0.211" />
        <vers num="4.0.229" />
        <vers num="4.0.235" />
        <vers num="4.1.260" />
        <vers num="4.1.268" />
        <vers num="4.1.278" />
        <vers num="4.1.287" />
        <vers num="4.1.289" />
        <vers num="4.1.304" />
        <vers num="4.1.319" />
        <vers num="4.1.335" />
        <vers num="4.1.342" />
        <vers num="4.1.357" />
        <vers num="4.1.389" />
        <vers num="4.1.396" />
        <vers num="4.1.412" />
        <vers num="4.1.418" />
        <vers num="4.1.501" />
        <vers num="4.5.518" />
        <vers num="4.5.549" />
        <vers num="4.5.561" />
        <vers num="4.6.603" />
        <vers num="4.6.623" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1720" published="2005-06-16" name="CVE-2005-1720" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">AFP Server for Mac OS X 10.4.1, when using an ACL enabled volume, does not properly remove an ACL when a file is copied to a directory that does not use ACLs, which will override the POSIX file permissions for that ACL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="afp_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1721" published="2005-06-16" name="CVE-2005-1721" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
      <ref url="http://securitytracker.com/id?1014138" source="SECTRACK">1014138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="afp_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1722" published="2005-06-16" name="CVE-2005-1722" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1723" published="2005-06-08" name="CVE-2005-1723" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to the database of unsafe types, which could allow attackers to bypass intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-06-08</ref>
      <ref url="http://securitytracker.com/id?1014141" source="SECTRACK">1014141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1724" published="2005-06-08" name="CVE-2005-1724" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-06-08</ref>
      <ref url="http://securitytracker.com/id?1014142" source="SECTRACK">1014142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1725" published="2005-06-08" name="CVE-2005-1725" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-06-08</ref>
      <ref url="http://www.suresec.org/advisories/adv3.pdf" source="MISC" adv="1">http://www.suresec.org/advisories/adv3.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111833509424379&amp;w=2" source="BUGTRAQ" adv="1">20050608 [ Suresec Advisories ] - Mac OS X 10.4 - launchd local root vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1726" published="2005-12-31" name="CVE-2005-1726" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The CoreGraphics Window Server in Mac OS X 10.4.1 allows local users with console access to gain privileges by "launching commands into root sessions."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/Security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=301742" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=301742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1727" published="2005-06-08" name="CVE-2005-1727" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-06-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1728" published="2005-06-08" name="CVE-2005-1728" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-06-08</ref>
      <ref url="http://securitytracker.com/id?1014148" source="SECTRACK">1014148</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1729" published="2005-06-12" name="CVE-2005-1729" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cirt.dk/advisories/cirt-33-advisory.pdf" source="MISC" adv="1">http://www.cirt.dk/advisories/cirt-33-advisory.pdf</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034536.html" source="FULLDISC" adv="1">20050612 [CIRT.DK - Advisory] Novell eDirectory 8.7.3 DOS Device name Denial of Service</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097766.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097766.htm</ref>
      <ref url="http://securitytracker.com/id?1014177" source="SECTRACK">1014177</ref>
      <ref url="http://secunia.com/advisories/15676" source="SECUNIA">15676</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="edirectory">
        <vers num="8.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1730" published="2005-12-31" name="CVE-2005-1730" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer."  NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.</descript>
      <descript source="nvd">This vulnerability is addressed in the following product update:
http://www.novell.com/products/consoles/ </descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0744" source="VUPEN">ADV-2005-0744</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-32-advisory.pdf" source="MISC" adv="1">http://www.cirt.dk/advisories/cirt-32-advisory.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/8732" source="BID">8732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="imanager">
        <vers prev="1" num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1732" published="2005-05-24" name="CVE-2005-1732" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cookie Cart allows remote attackers to read the Order Notification list via the testmycgi and path parameters to testmy.cgi.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt" source="MISC" adv="1">http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1014026" source="SECTRACK">1014026</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686721022831&amp;w=2" source="BUGTRAQ">20050521 Cookie Cart Default Installation Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/15448" source="SECUNIA">15448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metro_marketing" name="cookie_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1733" published="2005-05-24" name="CVE-2005-1733" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt" source="MISC">http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1014026" source="SECTRACK">1014026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metro_marketing" name="cookie_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1734" published="2005-05-24" name="CVE-2005-1734" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013992" source="SECTRACK" adv="1">1013992</ref>
      <ref url="http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91" source="CONFIRM">http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91</ref>
      <ref url="http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz" source="CONFIRM">http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electricmonk" name="proms">
        <vers prev="1" num="0.10" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1735" published="2005-05-24" name="CVE-2005-1735" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PROMS before 0.11 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013992" source="SECTRACK" adv="1">1013992</ref>
      <ref url="http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91" source="CONFIRM">http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91</ref>
      <ref url="http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz" source="CONFIRM">http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electricmonk" name="proms">
        <vers prev="1" num="0.10" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1736" published="2005-05-24" name="CVE-2005-1736" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91" source="CONFIRM">http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91</ref>
      <ref url="http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz" source="CONFIRM">http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electricmonk" name="proms">
        <vers num="0.10" />
        <vers prev="1" num="0.11" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1737" published="2005-05-24" name="CVE-2005-1737" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013992" source="SECTRACK" adv="1">1013992</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electricmonk" name="proms">
        <vers num="0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1738" published="2005-05-24" name="CVE-2005-1738" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrary code via certain inputs that are not properly handled in a syslog call.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in version 0.3 d</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13720" source="BID" patch="1">13720</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=329340" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=329340</ref>
      <ref url="http://secunia.com/advisories/15473" source="SECUNIA" adv="1">15473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iron_bars_shell" name="iron_bars_shell">
        <vers num="0.3a" />
        <vers num="0.3b" />
        <vers num="0.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1739" published="2005-05-24" name="CVE-2005-1739" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-132-1" source="UBUNTU" patch="1">USN-132-1</ref>
      <ref url="http://www.securityfocus.com/bid/13705" source="BID" patch="1">13705</ref>
      <ref url="http://www.osvdb.org/16775" source="OSVDB">16775</ref>
      <ref url="http://www.osvdb.org/16774" source="OSVDB">16774</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200505-16.xml" source="GENTOO">GLSA-200505-16</ref>
      <ref url="http://secunia.com/advisories/15446" source="SECUNIA">15446</ref>
      <ref url="http://secunia.com/advisories/15429" source="SECUNIA" adv="1">15429</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11667" source="OVAL">oval:org.mitre.oval:def:11667</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=90423" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=90423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-480.html" source="REDHAT">RHSA-2005:480</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:107" source="MANDRAKE">MDKSA-2005:107</ref>
      <ref url="http://secunia.com/advisories/15453" source="SECUNIA">15453</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:960" source="OVAL" sig="1">oval:org.mitre.oval:def:960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="graphicsmagick" name="graphicsmagick">
        <vers num="1.0" />
        <vers num="1.0.6" />
        <vers num="1.1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
      </prod>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.4" />
        <vers num="5.5.6" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.2.5" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.1" />
        <vers num="6.1.1.6" />
        <vers num="6.1.2" />
        <vers num="6.1.3" />
        <vers num="6.1.4" />
        <vers num="6.1.5" />
        <vers num="6.1.6" />
        <vers num="6.1.7" />
        <vers num="6.1.8" />
        <vers num="6.2" />
        <vers num="6.2.0.4" />
        <vers num="6.2.0.7" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1740" published="2005-05-24" name="CVE-2005-1740" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zataz.net/adviso/net-snmp-05182005.txt" source="MISC">http://www.zataz.net/adviso/net-snmp-05182005.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0598" source="VUPEN">ADV-2005-0598</ref>
      <ref url="http://www.osvdb.org/16778" source="OSVDB">16778</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200505-18.xml" source="GENTOO" adv="1">GLSA-200505-18</ref>
      <ref url="http://secunia.com/advisories/15471" source="SECUNIA">15471</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11659" source="OVAL">oval:org.mitre.oval:def:11659</ref>
      <ref url="http://www.securityfocus.com/bid/13715" source="BID">13715</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-395.html" source="REDHAT">RHSA-2005:395</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-373.html" source="REDHAT">RHSA-2005:373</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:025" source="MANDRIVA">MDKSA-2006:025</ref>
      <ref url="http://securitytracker.com/id?1014039" source="SECTRACK">1014039</ref>
      <ref url="http://secunia.com/advisories/18635" source="SECUNIA">18635</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA">17135</ref>
      <ref url="http://secunia.com/advisories/16999" source="SECUNIA">16999</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net-snmp" name="net-snmp">
        <vers num="5.0.1" />
        <vers num="5.0.3" />
        <vers num="5.0.4_pre2" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
        <vers num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1741" published="2005-05-24" name="CVE-2005-1741" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0616" source="VUPEN">ADV-2005-0616</ref>
      <ref url="http://www.securityfocus.com/bid/13728" source="BID">13728</ref>
      <ref url="http://securitytracker.com/id?1014067" source="SECTRACK">1014067</ref>
      <ref url="http://secunia.com/advisories/15501" source="SECUNIA">15501</ref>
      <ref url="http://aluigi.altervista.org/adv/haloloop-adv.txt" source="MISC">http://aluigi.altervista.org/adv/haloloop-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gearbox_software" name="halo_combat_evolved">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1742" published="2005-05-24" name="CVE-2005-1742" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0602" source="VUPEN">ADV-2005-0602</ref>
      <ref url="http://www.securityfocus.com/bid/13717" source="BID">13717</ref>
      <ref url="http://securitytracker.com/id?1014049" source="SECTRACK">1014049</ref>
      <ref url="http://secunia.com/advisories/15486" source="SECUNIA" adv="1">15486</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/125" source="BEA" adv="1">BEA05-75.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1743" published="2005-05-24" name="CVE-2005-1743" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0603" source="VUPEN">ADV-2005-0603</ref>
      <ref url="http://www.securityfocus.com/bid/13717" source="BID">13717</ref>
      <ref url="http://securitytracker.com/id?1014049" source="SECTRACK">1014049</ref>
      <ref url="http://secunia.com/advisories/15486" source="SECUNIA" adv="1">15486</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/126" source="BEA" adv="1">BEA05-76.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1744" published="2005-05-24" name="CVE-2005-1744" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0604" source="VUPEN">ADV-2005-0604</ref>
      <ref url="http://www.securityfocus.com/bid/13717" source="BID">13717</ref>
      <ref url="http://securitytracker.com/id?1014049" source="SECTRACK">1014049</ref>
      <ref url="http://secunia.com/advisories/15486" source="SECUNIA" adv="1">15486</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/127" source="BEA" adv="1">BEA05-77.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1745" published="2005-05-24" name="CVE-2005-1745" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0605" source="VUPEN">ADV-2005-0605</ref>
      <ref url="http://www.securityfocus.com/bid/13717" source="BID">13717</ref>
      <ref url="http://securitytracker.com/id?1014049" source="SECTRACK">1014049</ref>
      <ref url="http://secunia.com/advisories/15486" source="SECUNIA" adv="1">15486</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/128" source="BEA" adv="1">BEA05-78.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1746" published="2005-05-24" name="CVE-2005-1746" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown) via modified cookies.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0606" source="VUPEN">ADV-2005-0606</ref>
      <ref url="http://www.securityfocus.com/bid/13717" source="BID">13717</ref>
      <ref url="http://securitytracker.com/id?1014049" source="SECTRACK">1014049</ref>
      <ref url="http://secunia.com/advisories/15486" source="SECUNIA" adv="1">15486</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/129" source="BEA" adv="1">BEA05-79.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1747" published="2005-05-24" name="CVE-2005-1747" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username or (2) j_password parameters in the login page (LoginForm.jsp), (3) parameters to the error page in the Administration Console, (4) unknown vectors in the Server Console while the administrator has an active session to obtain the ADMINCONSOLESESSION cookie, or (5) an alternate vector in the Server Console that does not require an active session but also leaks the username and password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0607" source="VUPEN">ADV-2005-0607</ref>
      <ref url="http://www.securityfocus.com/bid/13717" source="BID">13717</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/general/BEA-002.html" source="MISC">http://www.appsecinc.com/resources/alerts/general/BEA-002.html</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/general/BEA-001.html" source="MISC">http://www.appsecinc.com/resources/alerts/general/BEA-001.html</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-2005-05-24-2-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-2005-05-24-2-PUB.txt</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-2005-05-24-1-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-2005-05-24-1-PUB.txt</ref>
      <ref url="http://securitytracker.com/id?1014049" source="SECTRACK">1014049</ref>
      <ref url="http://secunia.com/advisories/15486" source="SECUNIA" adv="1">15486</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/130" source="BEA" adv="1">BEA05-80.00</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722380313416&amp;w=2" source="BUGTRAQ">20050527 [AppSecInc Advisory BEA05-V0101] BEA WebLogic Administration Console login page cross-site scripting vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722298705561&amp;w=2" source="BUGTRAQ">20050527 [AppSecInc Advisory BEA05-V0100] BEA WebLogic Administration Console error page cross-site scripting vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695921212456&amp;w=2" source="BUGTRAQ">20050524 ACROS Security: HTML Injection in BEA WebLogic Server Console (1)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695844803328&amp;w=2" source="BUGTRAQ">20050524 ACROS Security: HTML Injection in BEA WebLogic Server Console (2)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1748" published="2005-05-24" name="CVE-2005-1748" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0608" source="VUPEN">ADV-2005-0608</ref>
      <ref url="http://www.securityfocus.com/bid/13717" source="BID">13717</ref>
      <ref url="http://securitytracker.com/id?1014049" source="SECTRACK">1014049</ref>
      <ref url="http://secunia.com/advisories/15486" source="SECUNIA" adv="1">15486</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/131" source="BEA" adv="1">BEA05-81.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1749" published="2005-05-24" name="CVE-2005-1749" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0609" source="VUPEN">ADV-2005-0609</ref>
      <ref url="http://www.securityfocus.com/bid/13717" source="BID">13717</ref>
      <ref url="http://secunia.com/advisories/15486" source="SECUNIA" adv="1">15486</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/132" source="BEA" adv="1">BEA05-82.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1750" published="2005-05-25" name="CVE-2005-1750" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.under9round.com/nez.txt" source="MISC" adv="1">http://www.under9round.com/nez.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13730" source="BID">13730</ref>
      <ref url="http://secunia.com/advisories/15469" source="SECUNIA">15469</ref>
      <ref url="http://securitytracker.com/id?1014038" source="SECTRACK">1014038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="distinct_web_creations" name="newsletterez">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1751" published="2005-05-25" name="CVE-2005-1751" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zataz.net/adviso/shtool-05252005.txt" source="MISC" adv="1">http://www.zataz.net/adviso/shtool-05252005.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-08.xml" source="GENTOO">GLSA-200506-08</ref>
      <ref url="http://securitytracker.com/id?1014059" source="SECTRACK">1014059</ref>
      <ref url="http://secunia.com/advisories/15496" source="SECUNIA">15496</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9639" source="OVAL">oval:org.mitre.oval:def:9639</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=93782" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=93782</ref>
      <ref url="http://www.securityfocus.com/bid/13767" source="BID">13767</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-564.html" source="REDHAT">RHSA-2005:564</ref>
      <ref url="http://www.debian.org/security/2005/dsa-789" source="DEBIAN">DSA-789</ref>
      <ref url="http://secunia.com/advisories/15668" source="SECUNIA">15668</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111955937622637&amp;w=2" source="OPENPKG">OpenPKG-SA-2005.011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:345" source="OVAL" sig="1">oval:org.mitre.oval:def:345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shtool" name="shtool">
        <vers prev="1" num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1752" published="2005-12-31" name="CVE-2005-1752" modified="2008-09-05" discovered="2005-05-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13716" source="BID" patch="1">13716</ref>
      <ref url="http://secunia.com/advisories/13845" source="SECUNIA" patch="1" adv="1">13845</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695779919830&amp;w=2" source="BUGTRAQ">20050524 Gforge - viewFile.php security flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.21" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1753" published="2005-12-31" name="CVE-2005-1753" modified="2008-09-05" discovered="2005-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue.  Sun states: "The report makes references to source code and files that do not exist in the mentioned products."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://tomcat.apache.org/security-5.html" source="MISC">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111697083812367&amp;w=2" source="BUGTRAQ">20050524 Javamail Multiple Information Disclosure Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="javamail">
        <vers num="1.1.3" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1754" published="2005-12-31" name="CVE-2005-1754" modified="2008-09-05" discovered="2005-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter.  NOTE: Sun and Apache dispute this issue.  Sun states: "The report makes references to source code and files that do not exist in the mentioned products."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13753" source="BID">13753</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="MISC">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111697083812367&amp;w=2" source="BUGTRAQ">20050524 Javamail Multiple Information Disclosure Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache_tomcat" name="apache_tomcat">
        <vers num="5.0.16" />
      </prod>
      <prod vendor="sun" name="javamail">
        <vers num="1.1.3" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1755" published="2005-12-31" name="CVE-2005-1755" modified="2008-09-05" discovered="2005-05-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in poll_vote.php in PHP Poll Creator 1.01 allows remote attackers to execute arbitrary PHP code via the relativer_pfad parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16846" source="OSVDB" patch="1">16846</ref>
      <ref url="http://securitytracker.com/id?1014061" source="SECTRACK">1014061</ref>
      <ref url="http://secunia.com/advisories/15510" source="SECUNIA" adv="1">15510</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111704581329860&amp;w=2" source="BUGTRAQ">20050525 PHP Injection in PHP Poll Creator</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_poll_creator" name="php_poll_creator">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1756" published="2005-06-08" name="CVE-2005-1756" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm</ref>
      <ref url="http://secunia.com/advisories/15644" source="SECUNIA" patch="1" adv="1">15644</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0727" source="VUPEN">ADV-2005-0727</ref>
      <ref url="http://www.securityfocus.com/bid/13926" source="BID">13926</ref>
      <ref url="http://www.osvdb.org/17240" source="OSVDB">17240</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netmail">
        <vers num="3.0.3a" edition="a" />
        <vers num="3.0.3a" edition="b" />
        <vers num="3.1" edition="f" />
        <vers num="3.10" edition="a" />
        <vers num="3.10" edition="b" />
        <vers num="3.10" edition="c" />
        <vers num="3.10" edition="d" />
        <vers num="3.10" edition="e" />
        <vers num="3.10" edition="f" />
        <vers num="3.10" edition="g" />
        <vers num="3.10" edition="h" />
        <vers num="3.5.2" edition="a" />
        <vers num="3.5.2" edition="b" />
        <vers num="3.5.2" edition="e-ftfl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1757" published="2005-06-08" name="CVE-2005-1757" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm</ref>
      <ref url="http://secunia.com/advisories/15644" source="SECUNIA" patch="1" adv="1">15644</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0727" source="VUPEN">ADV-2005-0727</ref>
      <ref url="http://www.securityfocus.com/bid/13926" source="BID">13926</ref>
      <ref url="http://www.osvdb.org/17241" source="OSVDB">17241</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netmail">
        <vers num="3.0.3a" edition="a" />
        <vers num="3.0.3a" edition="b" />
        <vers num="3.1" edition="f" />
        <vers num="3.10" edition="a" />
        <vers num="3.10" edition="b" />
        <vers num="3.10" edition="c" />
        <vers num="3.10" edition="d" />
        <vers num="3.10" edition="e" />
        <vers num="3.10" edition="f" />
        <vers num="3.10" edition="g" />
        <vers num="3.10" edition="h" />
        <vers num="3.5.2" edition="a" />
        <vers num="3.5.2" edition="b" />
        <vers num="3.5.2" edition="e-ftfl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1758" published="2005-06-08" name="CVE-2005-1758" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm</ref>
      <ref url="http://secunia.com/advisories/15644" source="SECUNIA" patch="1" adv="1">15644</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0727" source="VUPEN">ADV-2005-0727</ref>
      <ref url="http://www.securityfocus.com/bid/14718" source="BID">14718</ref>
      <ref url="http://www.securityfocus.com/bid/13926" source="BID">13926</ref>
      <ref url="http://www.osvdb.org/17239" source="OSVDB">17239</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netmail">
        <vers num="3.0.3a" edition="a" />
        <vers num="3.0.3a" edition="b" />
        <vers num="3.1" edition="f" />
        <vers num="3.10" edition="a" />
        <vers num="3.10" edition="b" />
        <vers num="3.10" edition="c" />
        <vers num="3.10" edition="d" />
        <vers num="3.10" edition="e" />
        <vers num="3.10" edition="f" />
        <vers num="3.10" edition="g" />
        <vers num="3.10" edition="h" />
        <vers num="3.5.2" edition="a" />
        <vers num="3.5.2" edition="b" />
        <vers num="3.5.2" edition="e-ftfl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1759" published="2005-06-28" name="CVE-2005-1759" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in shtool 2.0.1 and earlier allows local users to modify or create arbitrary files via a symlink attack on temporary files after they have been created, a different vulnerability than CVE-2005-1751.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-08</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111955937622637&amp;w=2" source="OPENPKG" patch="1" adv="1">OpenPKG-SA-2005.011</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=93782" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=93782</ref>
      <ref url="http://www.securityfocus.com/bid/13767" source="BID">13767</ref>
      <ref url="http://secunia.com/advisories/15668" source="SECUNIA">15668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shtool" name="shtool">
        <vers prev="1" num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1760" published="2005-06-13" name="CVE-2005-1760" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-502.html" source="REDHAT" patch="1" adv="1">RHSA-2005:502</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9522" source="OVAL">oval:org.mitre.oval:def:9522</ref>
      <ref url="http://www.securityfocus.com/bid/13936" source="BID">13936</ref>
      <ref url="http://securitytracker.com/id?1014181" source="SECTRACK">1014181</ref>
      <ref url="http://secunia.com/advisories/15675" source="SECUNIA">15675</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:623" source="OVAL" sig="1">oval:org.mitre.oval:def:623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="sysreport">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ia64" />
        <vers num="2.1" edition=":itanium_processor" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1761" published="2005-08-05" name="CVE-2005-1761" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_44_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:044</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.securityfocus.com/bid/14051" source="BID">14051</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-551.html" source="REDHAT">RHSA-2005:551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.1</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1018" source="DEBIAN">DSA-1018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://securitytracker.com/id?1014275" source="SECTRACK">1014275</ref>
      <ref url="http://secunia.com/advisories/19369" source="SECUNIA">19369</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10487" source="OVAL">oval:org.mitre.oval:def:10487</ref>
      <ref url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=4ea78729b8dbfc400fe165a57b90a394a7275a54" source="CONFIRM">http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=4ea78729b8dbfc400fe165a57b90a394a7275a54</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="open_enterprise_server">
        <vers num="9" />
      </prod>
      <prod vendor="novell" name="linux_desktop">
        <vers num="9" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
        <vers num="9.2" />
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1762" published="2005-08-02" name="CVE-2005-1762" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ptrace call in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform allows local users to cause a denial of service (kernel crash) via a "non-canonical" address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_29_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:029</ref>
      <ref url="http://secunia.com/advisories/15786" source="SECUNIA" patch="1" adv="1">15786</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-143-1" source="UBUNTU" adv="1">USN-143-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10630" source="OVAL">oval:org.mitre.oval:def:10630</ref>
      <ref url="http://www.securityfocus.com/bid/13904" source="BID">13904</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded" source="FEDORA">FLSA:157459-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://www.debian.org/security/2005/dsa-921" source="DEBIAN">DSA-921</ref>
      <ref url="http://secunia.com/advisories/18059" source="SECUNIA">18059</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" />
        <vers num="2.6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1763" published="2005-06-09" name="CVE-2005-1763" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_29_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:029</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10182" source="OVAL">oval:org.mitre.oval:def:10182</ref>
      <ref url="http://www.securityfocus.com/bid/13903" source="BID">13903</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="linux_desktop">
        <vers num="9" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1764" published="2005-10-07" name="CVE-2005-1764" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux 2.6.11 on 64-bit x86 (x86_64) platforms does not use a guard page for the 47-bit address page to protect against an AMD K8 bug, which allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://freshmeat.net/articles/view/1678/" source="SUSE" patch="1" adv="1">SUSE-SA:2005:029</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRAKE">MDKSA-2005:220</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=637716a3825e186555361574aa1fa3c0ebf8018b" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=637716a3825e186555361574aa1fa3c0ebf8018b</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=637716a3825e186555361574aa1fa3c0ebf8018b" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=637716a3825e186555361574aa1fa3c0ebf8018b</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43324" source="XF">linux-kernel-guardpage-dos(43324)</ref>
      <ref url="http://www.securityfocus.com/bid/13904" source="BID">13904</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.11" edition="" />
        <vers num="2.6.11" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1765" published="2005-05-31" name="CVE-2005-1765" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">syscall in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform, when running in 32-bit compatibility mode, allows local users to cause a denial of service (kernel hang) via crafted arguments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_29_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:029</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-143-1" source="UBUNTU">USN-143-1</ref>
      <ref url="http://www.securityfocus.com/bid/13904" source="BID">13904</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" />
        <vers num="2.6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1766" published="2005-06-28" name="CVE-2005-1766" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-826" source="DEBIAN" patch="1" adv="1">DSA-826</ref>
      <ref url="http://service.real.com/help/faq/security/050623_player/EN/" source="CONFIRM" patch="1">http://service.real.com/help/faq/security/050623_player/EN/</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-523.html" source="REDHAT" adv="1">RHSA-2005:523</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_37_real_player.html" source="SUSE">SUSE-SA:2005:037</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=250&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20050623 RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9509" source="OVAL">oval:org.mitre.oval:def:9509</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-517.html" source="REDHAT">RHSA-2005:517</ref>
      <ref url="http://secunia.com/advisories/16981" source="SECUNIA">16981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers prev="1" num="10.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1767" published="2005-08-05" name="CVE-2005-1767" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_44_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:044</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11101" source="OVAL">oval:org.mitre.oval:def:11101</ref>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044" source="MANDRIVA">MDKSA-2006:044</ref>
      <ref url="http://www.ubuntu.com/usn/usn-187-1" source="UBUNTU">USN-187-1</ref>
      <ref url="http://www.securityfocus.com/bid/14467" source="BID">14467</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://www.debian.org/security/2005/dsa-921" source="DEBIAN">DSA-921</ref>
      <ref url="http://secunia.com/advisories/18977" source="SECUNIA">18977</ref>
      <ref url="http://secunia.com/advisories/18059" source="SECUNIA">18059</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=51e31546a2fc46cb978da2ee0330a6a68f07541e" source="CONFIRM">http://kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=51e31546a2fc46cb978da2ee0330a6a68f07541e</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="open_enterprise_server">
        <vers num="9" />
      </prod>
      <prod vendor="novell" name="linux_desktop">
        <vers num="9" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
        <vers num="9.2" />
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1768" published="2005-07-11" name="CVE-2005-1768" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that increments a pointer count after the nargs function has counted the pointers, but before the count is copied from user space to kernel space, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.suresec.org/advisories/adv4.pdf" source="MISC">http://www.suresec.org/advisories/adv4.pdf</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11117" source="OVAL">oval:org.mitre.oval:def:11117</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112110120216116&amp;w=2" source="BUGTRAQ">20050711 [ Suresec Advisories ] - Linux kernel ia32 compatibility (ia64/x86-64)</ref>
      <ref url="http://www.securityfocus.com/bid/14205" source="BID">14205</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-551.html" source="REDHAT">RHSA-2005:551</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_44_kernel.html" source="SUSE">SUSE-SA:2005:044</ref>
      <ref url="http://www.debian.org/security/2005/dsa-921" source="DEBIAN">DSA-921</ref>
      <ref url="http://securitytracker.com/id?1014442" source="SECTRACK">1014442</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="http://secunia.com/advisories/19185" source="SECUNIA">19185</ref>
      <ref url="http://secunia.com/advisories/18059" source="SECUNIA">18059</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://secunia.com/advisories/15980" source="SECUNIA">15980</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.30" edition="rc2" />
        <vers num="2.4.30" edition="rc3" />
        <vers num="2.4.31" edition="pre1" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1769" published="2005-06-16" name="CVE-2005-1769" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2005-06-15" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2005-06-15</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9852" source="OVAL">oval:org.mitre.oval:def:9852</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893827711390&amp;w=2" source="BUGTRAQ">20050616 [SM-ANNOUNCE] Patch fixes SquirrelMail cross site scripting vulnerabilities [CAN-2005-1769]</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163047" source="FEDORA">FLSA:163047</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-595.html" source="REDHAT">RHSA-2005:595</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:108" source="MANDRAKE">MDKSA-2005:108</ref>
      <ref url="http://www.debian.org/security/2005/dsa-756" source="DEBIAN">DSA-756</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
        <vers num="1.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1770" published="2005-05-31" name="CVE-2005-1770" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (system crash) and possibly execute arbitrary code via certain signals combined with crafted input.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://pb.specialised.info/all/adv/avast-adv.txt" source="MISC" adv="1">http://pb.specialised.info/all/adv/avast-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111712494620031&amp;w=2" source="BUGTRAQ" adv="1">20050526 Alwil Software Avast Antivirus Device Driver Memory Overwrite Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alwil" name="avast_antivirus">
        <vers num="4.0.168" />
        <vers num="4.0.172" />
        <vers num="4.0.183" />
        <vers num="4.0.202" />
        <vers num="4.0.211" />
        <vers num="4.0.229" />
        <vers num="4.0.235" />
        <vers num="4.1.260" />
        <vers num="4.1.268" />
        <vers num="4.1.278" />
        <vers num="4.1.287" />
        <vers num="4.1.289" />
        <vers num="4.1.304" />
        <vers num="4.1.319" />
        <vers num="4.1.335" />
        <vers num="4.1.342" />
        <vers num="4.1.357" />
        <vers num="4.1.389" />
        <vers num="4.1.396" />
        <vers num="4.1.412" />
        <vers num="4.1.418" />
        <vers num="4.1.501" />
        <vers num="4.5.518" />
        <vers num="4.5.549" />
        <vers num="4.5.561" />
        <vers num="4.6.603" />
        <vers num="4.6.623" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1771" published="2005-05-31" name="CVE-2005-1771" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in HP-UX trusted systems B.11.00 through B.11.23 allows remote attackers to gain unauthorized access, possibly involving remshd and/or telnet -t.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713178014478&amp;w=2" source="HP" patch="1">SSRT5899</ref>
      <ref url="http://securitytracker.com/id?1014060" source="SECTRACK">1014060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713178014478&amp;w=2" source="HP">SSRT5899</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1772" published="2005-05-31" name="CVE-2005-1772" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the client cd-key hash in Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a long client cd-key hash value, a different vulnerability than CVE-2005-1556.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/t3wmbof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/t3wmbof-adv.txt</ref>
      <ref url="http://secunia.com/advisories/15520" source="SECUNIA">15520</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713248227479&amp;w=2" source="BUGTRAQ">20050526 Buffer-overflow and crash in Terminator 3: War of the Machines 1.16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atari" name="terminator_3_war_of_the_machines">
        <vers prev="1" num="1.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1773" published="2005-05-31" name="CVE-2005-1773" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service.  NOTE: this candidate may be SPLIT in the future when more precise technical details become available.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13768" source="BID" patch="1">13768</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111705329308546&amp;w=2" source="BUGTRAQ" patch="1">20050525 High Risk Vulnerability in L-Soft's LISTSERV Server</ref>
      <ref url="http://securitytracker.com/id?1014051" source="SECTRACK">1014051</ref>
      <ref url="http://secunia.com/advisories/15498" source="SECUNIA">15498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lsoft" name="listserv">
        <vers num="1.8d" />
        <vers num="1.8e" />
        <vers num="14.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1774" published="2005-05-31" name="CVE-2005-1774" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WEB-DAV Linux File System (davfs2) 0.2.3 does not properly enforce Unix permissions, which allows local users to write arbitrary files on a davfs2 mounted filesystem.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15497" source="SECUNIA">15497</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111705524308096&amp;w=2" source="BUGTRAQ">20050525 davfs2 does not honour Unix permissions</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=310757" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=310757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="davfs2" name="davfs2">
        <vers num="0.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1775" published="2005-05-31" name="CVE-2005-1775" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a large nickname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713248227479&amp;w=2" source="BUGTRAQ" adv="1">20050526 Buffer-overflow and crash in Terminator 3: War of the Machines 1.16</ref>
      <ref url="http://secunia.com/advisories/15520" source="SECUNIA">15520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atari" name="terminator_3_war_of_the_machines">
        <vers num="1.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1776" published="2005-05-31" name="CVE-2005-1776" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/cnedrabof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/cnedrabof-adv.txt</ref>
      <ref url="http://secunia.com/advisories/15519" source="SECUNIA">15519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713300212601&amp;w=2" source="BUGTRAQ">20050526 Buffer-overflow in C'Nedra 0.4.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cnedra" name="cnedra">
        <vers num="0.1.0" />
        <vers num="0.1.5" />
        <vers num="0.3.0" />
        <vers num="0.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1777" published="2005-05-31" name="CVE-2005-1777" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://news.postnuke.com/Article2691.html" source="CONFIRM" patch="1" adv="1">http://news.postnuke.com/Article2691.html</ref>
      <ref url="http://securitytracker.com/id?1014066" source="SECTRACK">1014066</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111721364707520&amp;w=2" source="BUGTRAQ">20050527 PostNuke Critical SQL Injection and XSS 0.750=>x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1778" published="2005-05-31" name="CVE-2005-1778" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://news.postnuke.com/Article2691.html" source="CONFIRM" patch="1" adv="1">http://news.postnuke.com/Article2691.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111721364707520&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050527 PostNuke Critical SQL Injection and XSS 0.750=>x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.750" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1779" published="2005-05-31" name="CVE-2005-1779" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014048" source="SECTRACK" adv="1">1014048</ref>
      <ref url="http://secunia.com/advisories/15511" source="SECUNIA" adv="1">15511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.35" />
        <vers num="1.36" />
        <vers num="2.0" />
        <vers num="2005-04-18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1780" published="2005-05-31" name="CVE-2005-1780" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.under9round.com/anm.txt" source="MISC" adv="1">http://www.under9round.com/anm.txt</ref>
      <ref url="http://securitytracker.com/id?1014057" source="SECTRACK">1014057</ref>
      <ref url="http://secunia.com/advisories/15493" source="SECUNIA" adv="1">15493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotnetindex" name="active_news_manager">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1781" published="2005-05-31" name="CVE-2005-1781" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15487" source="SECUNIA" patch="1" adv="1">15487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_enterprise">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
      </prod>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1782" published="2005-05-26" name="CVE-2005-1782" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13783" source="BID" adv="1">13783</ref>
      <ref url="http://www.osvdb.org/16879" source="OSVDB" adv="1">16879</ref>
      <ref url="http://www.osvdb.org/16878" source="OSVDB" adv="1">16878</ref>
      <ref url="http://www.osvdb.org/16877" source="OSVDB" adv="1">16877</ref>
      <ref url="http://www.osvdb.org/16876" source="OSVDB" adv="1">16876</ref>
      <ref url="http://www.osvdb.org/16875" source="OSVDB" adv="1">16875</ref>
      <ref url="http://www.osvdb.org/16874" source="OSVDB" adv="1">16874</ref>
      <ref url="http://www.osvdb.org/16873" source="OSVDB" adv="1">16873</ref>
      <ref url="http://www.osvdb.org/16872" source="OSVDB" adv="1">16872</ref>
      <ref url="http://www.osvdb.org/16871" source="OSVDB" adv="1">16871</ref>
      <ref url="http://securitytracker.com/id?1014058" source="SECTRACK" adv="1">1014058</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w.m.r._simpson" name="bookreview">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1783" published="2005-05-31" name="CVE-2005-1783" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the resulting error message.  NOTE: it is not clear whether BookReview is available to the public.  If not, then it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16881" source="OSVDB" adv="1">16881</ref>
      <ref url="http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html</ref>
      <ref url="http://www.osvdb.org/16880" source="OSVDB">16880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w.m.r._simpson" name="bookreview">
        <vers num="beta_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1784" published="2005-05-27" name="CVE-2005-1784" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014062" source="SECTRACK" adv="1">1014062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers prev="1" num="6.1_hotfix_2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1785" published="2005-05-31" name="CVE-2005-1785" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0636" source="VUPEN">ADV-2005-0636</ref>
      <ref url="http://www.under9round.com/zongg.txt" source="MISC" adv="1">http://www.under9round.com/zongg.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13787" source="BID" adv="1">13787</ref>
      <ref url="http://securitytracker.com/id?1014063" source="SECTRACK" adv="1">1014063</ref>
      <ref url="http://secunia.com/advisories/15515" source="SECUNIA">15515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zongg" name="zongg">
        <vers num="v1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1786" published="2005-05-25" name="CVE-2005-1786" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin.asp in FunkyASP AD System 1.1 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.funkyasp.co.uk/product.asp?prod=1&amp;currency=USD" source="CONFIRM" patch="1" adv="1">http://www.funkyasp.co.uk/product.asp?prod=1&amp;currency=USD</ref>
      <ref url="http://www.under9round.com/funky-asp.txt" source="MISC" adv="1">http://www.under9round.com/funky-asp.txt</ref>
      <ref url="http://securitytracker.com/id?1014056" source="SECTRACK">1014056</ref>
      <ref url="http://secunia.com/advisories/15494" source="SECUNIA" adv="1">15494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="funkyasp" name="funkyasp_ad_system">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1787" published="2005-05-27" name="CVE-2005-1787" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soulblack.com.ar/repo/tools/sbphpstatpoc.txt" source="MISC" adv="1">http://www.soulblack.com.ar/repo/tools/sbphpstatpoc.txt</ref>
      <ref url="http://www.soulblack.com.ar/repo/papers/advisory/PhpStat_advisory.txt" source="MISC">http://www.soulblack.com.ar/repo/papers/advisory/PhpStat_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1014064" source="SECTRACK">1014064</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111721290726958&amp;w=2" source="BUGTRAQ" adv="1">20050527 PHP Stat Administrative User Authentication Bypass</ref>
      <ref url="http://secunia.com/advisories/15516" source="SECUNIA">15516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpstat" name="phpstat">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1788" published="2005-06-01" name="CVE-2005-1788" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014071" source="SECTRACK">1014071</ref>
      <ref url="http://secunia.com/advisories/15540" source="SECUNIA">15540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="6.1_hotfix_2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1789" published="2005-05-29" name="CVE-2005-1789" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014074" source="SECTRACK" adv="1">1014074</ref>
      <ref url="http://ir-hackers.com/indsc.txt" source="MISC" adv="1">http://ir-hackers.com/indsc.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="india_software_solution" name="shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1790" published="2005-06-01" name="CVE-2005-1790" modified="2011-09-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-347A.html" source="CERT">TA05-347A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/887861" source="CERT-VN">VU#887861</ref>
      <ref url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375420" source="MISC">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375420</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2909" source="VUPEN" adv="1">ADV-2005-2909</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2867" source="VUPEN" adv="1">ADV-2005-2867</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2509" source="VUPEN" adv="1">ADV-2005-2509</ref>
      <ref url="http://www.securityfocus.com/bid/13799" source="BID">13799</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/417326/30/0/threaded" source="BUGTRAQ">20051121 Computer Terrorism Security Advisory (Reclassification) - Microsoft Internet Explorer JavaScript Window() Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx" source="MS">MS05-054</ref>
      <ref url="http://www.computerterrorism.com/research/ie/ct21-11-2005" source="MISC">http://www.computerterrorism.com/research/ie/ct21-11-2005</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-234.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-234.pdf</ref>
      <ref url="http://securitytracker.com/id?1015251" source="SECTRACK">1015251</ref>
      <ref url="http://secunia.com/advisories/18311" source="SECUNIA" adv="1">18311</ref>
      <ref url="http://secunia.com/advisories/18064" source="SECUNIA" adv="1">18064</ref>
      <ref url="http://secunia.com/advisories/15546" source="SECUNIA" adv="1">15546</ref>
      <ref url="http://secunia.com/advisories/15368" source="SECUNIA" adv="1">15368</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755552306013&amp;w=2" source="BUGTRAQ" adv="1">20050530 Re: Microsoft Internet Explorer - Crash on JavaScript </ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746394106172&amp;w=2" source="BUGTRAQ" adv="1">20050528 Microsoft Internet Explorer - Crash on JavaScript </ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:722" source="OVAL" sig="1">oval:org.mitre.oval:def:722</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1508" source="OVAL" sig="1">oval:org.mitre.oval:def:1508</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1489" source="OVAL" sig="1">oval:org.mitre.oval:def:1489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1303" source="OVAL" sig="1">oval:org.mitre.oval:def:1303</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1299" source="OVAL" sig="1">oval:org.mitre.oval:def:1299</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1091" source="OVAL" sig="1">oval:org.mitre.oval:def:1091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2800.1106" />
        <vers num="6.0.2900.2180" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1791" published="2005-05-28" name="CVE-2005-1791" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address.  NOTE: if there is not an exploit scenario in which an attacker can trigger this behavior, then perhaps this issue should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13798" source="BID" adv="1">13798</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746303509720&amp;w=2" source="BUGTRAQ" adv="1">20050531 Microsoft Internet Explorer - Crash on adding sites to restricted zone (05/28/2005)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1792" published="2005-06-01" name="CVE-2005-1792" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13801" source="BID" patch="1">13801</ref>
      <ref url="http://www.networksecurity.fi/advisories/windows-wmi-rpc.html" source="MISC" patch="1" adv="1">http://www.networksecurity.fi/advisories/windows-wmi-rpc.html</ref>
      <ref url="http://support.microsoft.com/kb/890196" source="MSKB" patch="1" adv="1">890196</ref>
      <ref url="http://www.osvdb.org/13020" source="OSVDB">13020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1793" published="2005-06-01" name="CVE-2005-1793" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1794" published="2005-06-01" name="CVE-2005-1794" modified="2011-07-18" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13818" source="BID">13818</ref>
      <ref url="http://www.oxid.it/downloads/rdp-gbu.pdf" source="MISC" adv="1">http://www.oxid.it/downloads/rdp-gbu.pdf</ref>
      <ref url="http://secunia.com/advisories/15605/" source="SECUNIA">15605</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12441" source="OVAL">oval:org.mitre.oval:def:12441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="remote_desktop_connection">
        <vers num="5.1.2600.2180" edition="" />
        <vers num="5.1.2600.2180" edition=":windows_xp" />
      </prod>
      <prod vendor="microsoft" name="windows_terminal_services_using_rdp">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1795" published="2005-05-27" name="CVE-2005-1795" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014070" source="SECTRACK" patch="1" adv="1">1014070</ref>
      <ref url="http://www.sentinelchicken.com/advisories/clamav" source="MISC" adv="1">http://www.sentinelchicken.com/advisories/clamav</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers prev="1" num="0.84" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1796" published="2005-05-31" name="CVE-2005-1796" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15535" source="SECUNIA" patch="1" adv="1">15535</ref>
      <ref url="http://ettercap.sourceforge.net/history.php" source="CONFIRM" patch="1" adv="1">http://ettercap.sourceforge.net/history.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0670" source="VUPEN">ADV-2005-0670</ref>
      <ref url="http://www.securityfocus.com/bid/13820" source="BID">13820</ref>
      <ref url="http://securitytracker.com/id?1014084" source="SECTRACK">1014084</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-07.xml" source="GENTOO">GLSA-200506-07</ref>
      <ref url="http://www.debian.org/security/2005/dsa-749" source="DEBIAN">DSA-749</ref>
      <ref url="http://secunia.com/advisories/16000" source="SECUNIA">16000</ref>
      <ref url="http://secunia.com/advisories/15664" source="SECUNIA">15664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ettercap" name="ettercap">
        <vers prev="1" num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1797" published="2005-05-26" name="CVE-2005-1797" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The design of Advanced Encryption Standard (AES), aka Rijndael, allows remote attackers to recover AES keys via timing attacks on S-box lookups, which are difficult to perform in constant time in AES implementations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13785" source="BID" adv="1">13785</ref>
      <ref url="http://cr.yp.to/antiforgery/cachetiming-20050414.pdf" source="MISC" adv="1">http://cr.yp.to/antiforgery/cachetiming-20050414.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c" />
        <vers num="0.9.2b" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.5a" />
        <vers num="0.9.6" />
        <vers num="0.9.6a" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.6l" />
        <vers num="0.9.6m" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
        <vers num="0.9.7d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1798" published="2005-05-29" name="CVE-2005-1798" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rgod.altervista.org/hacking/news/serverscheck.html" source="MISC" adv="1">http://www.rgod.altervista.org/hacking/news/serverscheck.html</ref>
      <ref url="http://securitytracker.com/id?1014075" source="SECTRACK" adv="1">1014075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serverscheck" name="monitoring_software">
        <vers num="5.10.0" />
        <vers num="5.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1799" published="2005-05-31" name="CVE-2005-1799" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15538" source="SECUNIA" patch="1" adv="1">15538</ref>
      <ref url="http://www.securityfocus.com/bid/13824" source="BID">13824</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freestyle" name="wiki">
        <vers num="3.5.7" />
      </prod>
      <prod vendor="freestyle" name="wikilite">
        <vers num=".10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1800" published="2005-05-28" name="CVE-2005-1800" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/034354.html" source="FULLDISC" patch="1" adv="1">20050529 XSS Bug in Jaws Glossary Action: ViewTerm ( v 0.4 - 0.5.1 (latest version))</ref>
      <ref url="http://www.securityfocus.com/bid/13796" source="BID">13796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1801" published="2005-05-26" name="CVE-2005-1801" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/infocus/1836" source="MISC">http://www.securityfocus.com/infocus/1836</ref>
      <ref url="http://www.securityfocus.com/bid/13784" source="BID" adv="1">13784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="9500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1802" published="2005-05-27" name="CVE-2005-1802" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13792" source="BID" patch="1" adv="1">13792</ref>
      <ref url="http://www.securityfocus.com/archive/1/399423" source="BUGTRAQ">20050531 Nortel VPN Router Malformed Packet DoS Vulnerability</ref>
      <ref url="http://www.nta-monitor.com/news/vpn-flaws/nortel/vpn-router-dos/" source="MISC">http://www.nta-monitor.com/news/vpn-flaws/nortel/vpn-router-dos/</ref>
      <ref url="http://securitytracker.com/id?1014068" source="SECTRACK">1014068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="contivity">
        <vers num="1000_vpn_switch" />
        <vers num="1500_vpn_switch" />
        <vers num="1600_secure_ip_services_gateway" />
        <vers num="2000_vpn_switch" />
        <vers num="2500_vpn_switch" />
        <vers num="2600_secure_ip_services_gateway" />
        <vers num="4000_vpn_switch" />
        <vers num="4500_secure_ip_services_gateway" />
        <vers num="4600_secure_ip_services_gateway" />
      </prod>
      <prod vendor="nortel" name="vpn_router_1010">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="vpn_router_1050">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="vpn_router_1100">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="vpn_router_1700">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="vpn_router_1740">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="vpn_router_2700">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="vpn_router_5000">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="vpn_router_600">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1803" published="2005-05-29" name="CVE-2005-1803" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, or (2) powerpack_f.php, (3) the sitename parameter to sdv_infos.php, (4) the categories parameter to faq.php, (5) the lettre parameter to the glossaire module, (6) the title parameter to reviews.php, or (7) the image_subject parameter to reply.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014073" source="SECTRACK" patch="1" adv="1">1014073</ref>
      <ref url="http://www.npds.org/download.php?op=geninfo&amp;did=115" source="CONFIRM" adv="1">http://www.npds.org/download.php?op=geninfo&amp;did=115</ref>
      <ref url="http://www.osvdb.org/16922" source="OSVDB">16922</ref>
      <ref url="http://www.osvdb.org/16464" source="OSVDB">16464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net_portal_dynamic_system" name="net_portal_dynamic_system">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1804" published="2005-05-29" name="CVE-2005-1804" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) terme parameter in the glossaire module (glossaire.php) or (2) query parameter to links.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.npds.org/download.php?op=geninfo&amp;did=115" source="CONFIRM" patch="1" adv="1">http://www.npds.org/download.php?op=geninfo&amp;did=115</ref>
      <ref url="http://securitytracker.com/id?1014073" source="SECTRACK" patch="1" adv="1">1014073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net_portal_dynamic_system" name="net_portal_dynamic_system">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1805" published="2005-05-28" name="CVE-2005-1805" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0645" source="VUPEN">ADV-2005-0645</ref>
      <ref url="http://www.under9round.com/os4e.txt" source="MISC" adv="1">http://www.under9round.com/os4e.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13804" source="BID" adv="1">13804</ref>
      <ref url="http://securitytracker.com/id?1014072" source="SECTRACK" adv="1">1014072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="online_solutions_for_educators" name="online_solutions_for_educators">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1806" published="2005-05-28" name="CVE-2005-1806" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format strings in the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.peercast.org/forum/viewtopic.php?p=11596" source="CONFIRM" patch="1" adv="1">http://www.peercast.org/forum/viewtopic.php?p=11596</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00077-05282005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00077-05282005</ref>
      <ref url="http://secunia.com/advisories/15536" source="SECUNIA" patch="1" adv="1">15536</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746603629979&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050528 Format String Vulnerability In Peercast 0.1211 And Earlier</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0651" source="VUPEN">ADV-2005-0651</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-15.xml" source="GENTOO">GLSA-200506-15</ref>
      <ref url="http://secunia.com/advisories/15753" source="SECUNIA">15753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peercast" name="peercast">
        <vers prev="1" num="0.1211" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1807" published="2005-05-28" name="CVE-2005-1807" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2242" source="VUPEN">ADV-2007-2242</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0448" source="VUPEN">ADV-2006-0448</ref>
      <ref url="http://www.cybsec.com/vuln/PHPMailer-DOS.pdf" source="MISC" adv="1">http://www.cybsec.com/vuln/PHPMailer-DOS.pdf</ref>
      <ref url="http://securitytracker.com/id?1014069" source="SECTRACK" adv="1">1014069</ref>
      <ref url="http://www.securityfocus.com/bid/13805" source="BID">13805</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=341210&amp;group_id=26031" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=341210&amp;group_id=26031</ref>
      <ref url="http://secunia.com/advisories/25726" source="SECUNIA">25726</ref>
      <ref url="http://secunia.com/advisories/18732" source="SECUNIA">18732</ref>
      <ref url="http://secunia.com/advisories/15543" source="SECUNIA">15543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmailer" name="phpmailer">
        <vers prev="1" num="1.72" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1808" published="2005-05-30" name="CVE-2005-1808" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefly Studios Stronghold 2 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large size value for the nickname, which causes a memory allocation failure and generates an exception.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15556" source="SECUNIA">15556</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111747562806999&amp;w=2" source="BUGTRAQ">20050530 Crash in Stronghold 2 1.2</ref>
      <ref url="http://aluigi.altervista.org/adv/strong2boom-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/strong2boom-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firefly_studios" name="stronghold_2">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1809" published="2005-06-01" name="CVE-2005-1809" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sony Ericsson P900 Beamer allows remote attackers to cause a denial of service (panic) via an obexftp session with a long filename in an OBEX File Transfer or OBEX Object Push.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/infocus/1836" source="MISC">http://www.securityfocus.com/infocus/1836</ref>
      <ref url="http://www.securityfocus.com/bid/13872" source="BID">13872</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1810" published="2005-06-01" name="CVE-2005-1810" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15517" source="SECUNIA" patch="1">15517</ref>
      <ref url="http://www.securityfocus.com/bid/13809" source="BID">13809</ref>
      <ref url="http://www.osvdb.org/16905" source="OSVDB">16905</ref>
      <ref url="http://wordpress.org/development/2005/05/security-update/" source="CONFIRM" adv="1">http://wordpress.org/development/2005/05/security-update/</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-04.xml" source="GENTOO">GLSA-200506-04</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=94512" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=94512</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817436619067&amp;w=2" source="BUGTRAQ">20050607 SQL Injection Exploit for WordPress &lt;= 1.5.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1811" published="2005-06-01" name="CVE-2005-1811" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in usercp.php for MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via the website field in a user profile.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15552" source="SECUNIA" patch="1">15552</ref>
      <ref url="http://www.securityfocus.com/bid/13819" source="BID">13819</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/May/0338.html" source="BUGTRAQ">20050530 MyBB 1.0 RC4 XSS Bug</ref>
      <ref url="http://securitytracker.com/id?1014081" source="SECTRACK">1014081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1812" published="2005-06-01" name="CVE-2005-1812" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13821" source="BID">13821</ref>
      <ref url="http://www.security.org.sg/vuln/tftp2000-1001.html" source="MISC">http://www.security.org.sg/vuln/tftp2000-1001.html</ref>
      <ref url="http://securitytracker.com/id?1014079" source="SECTRACK">1014079</ref>
      <ref url="http://secunia.com/advisories/15539" source="SECUNIA">15539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="futuresoft" name="tftp_server_2000">
        <vers num="1.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1813" published="2005-06-01" name="CVE-2005-1813" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13821" source="BID">13821</ref>
      <ref url="http://www.security.org.sg/vuln/tftp2000-1001.html" source="MISC">http://www.security.org.sg/vuln/tftp2000-1001.html</ref>
      <ref url="http://securitytracker.com/id?1014079" source="SECTRACK">1014079</ref>
      <ref url="http://secunia.com/advisories/15539" source="SECUNIA">15539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="futuresoft" name="tftp_server_2000">
        <vers num="1.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1814" published="2005-06-01" name="CVE-2005-1814" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in PicoWebServer 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13807" source="BID">13807</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746551802380&amp;w=2" source="BUGTRAQ">20050528 PicoWebServer Remote Unicode Stack Overflow</ref>
      <ref url="http://secunia.com/advisories/15541" source="SECUNIA">15541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newmad_technologies" name="picowebserver">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1815" published="2005-06-01" name="CVE-2005-1815" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of data to LPD (Lpdw.exe).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13790" source="BID" patch="1" adv="1">13790</ref>
      <ref url="http://www.securityfocus.com/bid/13788" source="BID" patch="1" adv="1">13788</ref>
      <ref url="http://secunia.com/advisories/15557" source="SECUNIA" patch="1" adv="1">15557</ref>
      <ref url="http://connectivity.hummingbird.com/support/nc/exceed/lpdw_advisory.html" source="CONFIRM" patch="1">http://connectivity.hummingbird.com/support/nc/exceed/lpdw_advisory.html</ref>
      <ref url="http://connectivity.hummingbird.com/support/nc/exceed/ftpd_advisory.html?cks=y" source="CONFIRM" patch="1">http://connectivity.hummingbird.com/support/nc/exceed/ftpd_advisory.html?cks=y</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="connectivity">
        <vers num="10.0" />
        <vers num="7.1" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1816" published="2005-06-01" name="CVE-2005-1816" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13797" source="BID">13797</ref>
      <ref url="http://secunia.com/advisories/15545" source="SECUNIA">15545</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0635.html" source="FULLDISC">20050528 Invision Power Board 1.x and 2.x Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1_final" />
        <vers num="1.3_final" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0_alpha_3" />
        <vers num="2.0_pdr3" />
        <vers num="2.0_pf1" />
        <vers num="2.0_pf2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1817" published="2005-06-01" name="CVE-2005-1817" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13802" source="BID" adv="1">13802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1818" published="2005-06-01" name="CVE-2005-1818" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.sevengraff.com/index.php" source="CONFIRM" patch="1">http://www.sevengraff.com/index.php</ref>
      <ref url="http://www.securityfocus.com/bid/13815" source="BID" patch="1" adv="1">13815</ref>
      <ref url="http://secunia.com/advisories/15523" source="SECUNIA" patch="1" adv="1">15523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newlife_blogger" name="newlife_blogger">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1819" published="2005-06-01" name="CVE-2005-1819" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in NikoSoft WebMail before 0.11.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nikosoft.net/nswm/" source="CONFIRM" patch="1">http://www.nikosoft.net/nswm/</ref>
      <ref url="http://secunia.com/advisories/15518" source="SECUNIA" patch="1" adv="1">15518</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nikosoft" name="webmail">
        <vers num="0.1" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.9" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="o.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1820" published="2005-06-01" name="CVE-2005-1820" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13823" source="BID">13823</ref>
      <ref url="http://www.securiteam.com/exploits/5KP0V0AFPA.html" source="MISC">http://www.securiteam.com/exploits/5KP0V0AFPA.html</ref>
      <ref url="http://pandora.sapzil.info/text/notify/20050123.zb41advisory.php" source="MISC">http://pandora.sapzil.info/text/notify/20050123.zb41advisory.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2" />
        <vers num="4.1_pl3" />
        <vers num="4.1_pl4" />
        <vers num="4.1_pl5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1821" published="2005-06-01" name="CVE-2005-1821" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soulblack.com.ar/repo/papers/advisory/powerdownload_advisory.txt" source="MISC" adv="1">http://www.soulblack.com.ar/repo/papers/advisory/powerdownload_advisory.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13822" source="BID" adv="1">13822</ref>
      <ref url="http://securitytracker.com/id?1014078" source="SECTRACK" adv="1">1014078</ref>
      <ref url="http://secunia.com/advisories/15537" source="SECUNIA" adv="1">15537</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755754126095&amp;w=2" source="BUGTRAQ">20050531 PowerDownload Remote File Inclusion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerscripts.org" name="powerdownload">
        <vers num="3.0.2" />
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1822" published="2005-06-01" name="CVE-2005-1822" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20773" source="XF">xcart-multiple-parameters-sql-injection(20773)</ref>
      <ref url="http://www.securityfocus.com/bid/13817" source="BID">13817</ref>
      <ref url="http://securitytracker.com/id?1014077" source="SECTRACK">1014077</ref>
      <ref url="http://secunia.com/advisories/15555" source="SECUNIA">15555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111748583101076&amp;w=2" source="BUGTRAQ">20050530 Multiple vulnerabilities in x-cart Gold</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualiteam" name="x-cart">
        <vers num="4.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1823" published="2005-06-01" name="CVE-2005-1823" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20774" source="XF">xcart-multiple-scripts-xss(20774)</ref>
      <ref url="http://www.securityfocus.com/bid/13817" source="BID">13817</ref>
      <ref url="http://securitytracker.com/id?1014077" source="SECTRACK">1014077</ref>
      <ref url="http://secunia.com/advisories/15555" source="SECUNIA">15555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111748583101076&amp;w=2" source="BUGTRAQ">20050530 Multiple vulnerabilities in x-cart Gold</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualiteam" name="x-cart">
        <vers num="4.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1824" published="2005-06-02" name="CVE-2005-1824" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=308031" source="CONFIRM" patch="1" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=308031</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-02.xml" source="GENTOO">GLSA-200506-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailutils">
        <vers num="1.0.6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1825" published="2005-05-03" name="CVE-2005-1825" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0681" source="VUPEN">ADV-2005-0681</ref>
      <ref url="http://www.grok.org.uk/advisories/radexecd.html" source="MISC" adv="1">http://www.grok.org.uk/advisories/radexecd.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034394.html" source="HP" adv="1">SSRT5962</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034394.html" source="HP">HPSBMA01143</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034387.html" source="FULLDISC" adv="1">20050601 HP Radia Notify Daemon: Multiple Buffer Overflow Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1014089" source="SECTRACK">1014089</ref>
      <ref url="http://secunia.com/advisories/15567" source="SECUNIA">15567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="radia_client">
        <vers num="3.1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1826" published="2005-05-03" name="CVE-2005-1826" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0681" source="VUPEN">ADV-2005-0681</ref>
      <ref url="http://www.grok.org.uk/advisories/radexecd.html" source="MISC">http://www.grok.org.uk/advisories/radexecd.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034394.html" source="HP" adv="1">HPSBMA01143</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034394.html" source="HP">HPSBMA01143</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034387.html" source="FULLDISC" adv="1">20050601 HP Radia Notify Daemon: Multiple Buffer Overflow Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1014089" source="SECTRACK">1014089</ref>
      <ref url="http://secunia.com/advisories/15567" source="SECUNIA">15567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="radia_client">
        <vers num="3.1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1827" published="2005-05-26" name="CVE-2005-1827" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecfg.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722515805478&amp;w=2" source="BUGTRAQ" adv="1">20050526 DSL-504T (and maybe many other) remote access without password bug</ref>
      <ref url="http://www.securityfocus.com/bid/13679" source="BID">13679</ref>
      <ref url="http://secunia.com/advisories/15422" source="SECUNIA">15422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="dsl-504t">
        <vers num="v1.00b01t16.eu.2004-02-17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1828" published="2005-05-26" name="CVE-2005-1828" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722515805478&amp;w=2" source="BUGTRAQ" adv="1">20050526 DSL-504T (and maybe many other) remote access without password bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="dsl-504t">
        <vers num="v1.00b01t16.eu.2004-02-17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1829" published="2005-05-28" name="CVE-2005-1829" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746441220149&amp;w=2" source="BUGTRAQ" adv="1">20050528 Microsoft Internet Explorer - Crash on processing embedded files with endless loop (05/28/2005)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1830" published="2005-05-29" name="CVE-2005-1830" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DbgMsg.sys driver in Compuware SoftICE DriverStudio 3.1 and 3.2 allows remote attackers to cause a denial of service (application crash) via an invalid Debug Message pointer.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15522" source="SECUNIA" adv="1">15522</ref>
      <ref url="http://pb.specialised.info/all/adv/sice-adv.txt" source="MISC" adv="1">http://pb.specialised.info/all/adv/sice-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746654827861&amp;w=2" source="BUGTRAQ" adv="1">20050529 Compuware Softice (DbgMsg driver) Local Denial Of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compuware" name="softice_driverstudio">
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1831" published="2005-05-31" name="CVE-2005-1831" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">** DISPUTED **  Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don't see how this could happen unless the user's actual password was empty."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/20417" source="OSVDB">20417</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755694008928&amp;w=2" source="BUGTRAQ" adv="1">20050531 [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html" source="BUGTRAQ">20050531 RE: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html" source="BUGTRAQ">20050531 Re: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.6.8p7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1832" published="2005-05-31" name="CVE-2005-1832" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 and earlier allow remote attackers to execute arbitrary web script or HTML via the (1) forums, (2) version, or (3) limit parameter to misc.php, (4) page or (5) datecut parameter to forumdisplay.php, (6) username, (7) email, or (8) email2 parameter to member.php, (9) page or (10) usersearch parameter to memberlist.php, (11) pid or (12) tid parameter to showthread.php, or (13) tid parameter to printthread.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mybboard.com/community/showthread.php?tid=2559" source="CONFIRM" patch="1" adv="1">http://www.mybboard.com/community/showthread.php?tid=2559</ref>
      <ref url="http://secunia.com/advisories/15552" source="SECUNIA" patch="1" adv="1">15552</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111757191118050&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050531 Multiple vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers prev="1" num="1.00_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1833" published="2005-05-31" name="CVE-2005-1833" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4) pid parameter to editpost.php, (5) fid parameter to forumdisplay.php, (6) tid parameter to newreply.php, (7) sid parameter to search.php, (8) tid or (9) pid parameter to showthread.php, (10) tid parameter to usercp2.php, (11) tid parameter to printthread.php, or (12) pid parameter to reputation.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mybboard.com/community/showthread.php?tid=2559" source="CONFIRM" patch="1" adv="1">http://www.mybboard.com/community/showthread.php?tid=2559</ref>
      <ref url="http://secunia.com/advisories/15552" source="SECUNIA" patch="1" adv="1">15552</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111757191118050&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050531 Multiple vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4</ref>
      <ref url="http://www.osvdb.org/17024" source="OSVDB">17024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers prev="1" num="1.00_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1834" published="2005-06-01" name="CVE-2005-1834" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in NEXTWEB (i)Site allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15560" source="SECUNIA" adv="1">15560</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111764682925083&amp;w=2" source="BUGTRAQ" adv="1">20050601 [ZH2005-13SA] NEXTWEB (i)Site website management multiple</ref>
      <ref url="http://securitytracker.com/id?1014085" source="SECTRACK">1014085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nextweb" name="nextweb_(i)site">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1835" published="2005-06-01" name="CVE-2005-1835" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15560" source="SECUNIA" adv="1">15560</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111764682925083&amp;w=2" source="BUGTRAQ" adv="1">20050601 [ZH2005-13SA] NEXTWEB (i)Site website management multiple</ref>
      <ref url="http://securitytracker.com/id?1014085" source="SECTRACK">1014085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nextweb" name="nextweb_(i)site">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1836" published="2005-06-01" name="CVE-2005-1836" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NEXTWEB (i)Site allows remote attackers to cause a denial of service (error 500) via a crafted HTTP request, possibly involving wildcard requests for .jsp files.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15560" source="SECUNIA" adv="1">15560</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111764682925083&amp;w=2" source="BUGTRAQ" adv="1">20050601 [ZH2005-13SA] NEXTWEB (i)Site website management multiple</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nextweb" name="nextweb_(i)site">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1837" published="2005-06-01" name="CVE-2005-1837" modified="2009-10-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773657526375&amp;w=2" source="BUGTRAQ" adv="1">20050601 Backdoor in =?ISO-8859-1?Q?Fortinet=B4s_firewall_Fortigate?=</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fortinet" name="fortinet_firewall">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1838" published="2005-06-02" name="CVE-2005-1838" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in castnewPost.asp in Liberum Help Desk 0.97.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Email, (2) Title, or (3) Description fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773586701991&amp;w=2" source="BUGTRAQ" adv="1">20050602 [ECHO_ADV_14$2005] Multiple Vulnerabilities in Liberum Help Desk</ref>
      <ref url="http://echo.or.id/adv/adv14-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv14-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liberum" name="liberum_help_desk">
        <vers num="0.97.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1839" published="2005-06-02" name="CVE-2005-1839" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.asp or (2) print.asp or (3) edit parameter to register.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15593" source="SECUNIA">15593</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773586701991&amp;w=2" source="BUGTRAQ" adv="1">20050602 [ECHO_ADV_14$2005] Multiple Vulnerabilities in Liberum Help Desk</ref>
      <ref url="http://echo.or.id/adv/adv14-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv14-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liberum" name="liberum_help_desk">
        <vers num="0.97.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1840" published="2005-06-02" name="CVE-2005-1840" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpcms.de/download/index.en.html" source="CONFIRM" patch="1" adv="1">http://www.phpcms.de/download/index.en.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773774916907&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050602 SEC-CONSULT SA20050602-1 :: Arbitrary File Inclusion in phpCMS 1.2.x</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpcms/phpcms/parser/include/class.layout_phpcms.php?rev=1.12.2.37&amp;view=markup" source="MISC" patch="1" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcms/phpcms/parser/include/class.layout_phpcms.php?rev=1.12.2.37&amp;view=markup</ref>
      <ref url="http://secunia.com/advisories/15586" source="SECUNIA">15586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcms" name="phpcms">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.1_p12" />
        <vers num="1.2.1_pl1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1841" published="2005-07-07" name="CVE-2005-1841" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/329121.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/329121.html</ref>
      <ref url="http://secunia.com/secunia_research/2005-6/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-6/advisory/</ref>
      <ref url="http://secunia.com/advisories/14457" source="SECUNIA" adv="1">14457</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-575.html" source="REDHAT">RHSA-2005:575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.0.10" />
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1842" published="2005-08-24" name="CVE-2005-1842" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/327129.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/327129.html</ref>
      <ref url="http://secunia.com/advisories/16541" source="SECUNIA" patch="1" adv="1">16541</ref>
      <ref url="http://www.securityfocus.com/bid/14638" source="BID">14638</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=297&amp;type=vulnerabilities" source="IDEFENSE">20050829 Adobe Version Cue VCNative Arbitrary File Overwrite Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014776" source="SECTRACK">1014776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="version_cue">
        <vers num="1.0" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1843" published="2005-08-24" name="CVE-2005-1843" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, allows local users to load arbitrary libraries and execute arbitrary code via the -lib command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/327129.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/327129.html</ref>
      <ref url="http://secunia.com/advisories/16541" source="SECUNIA" patch="1" adv="1">16541</ref>
      <ref url="http://www.securityfocus.com/bid/14638" source="BID">14638</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=296&amp;type=vulnerabilities" source="IDEFENSE">20050829 Adobe Version Cue VCNative Arbitrary Library Loading Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014776" source="SECTRACK">1014776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="version_cue">
        <vers num="1.0" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1846" published="2005-01-20" name="CVE-2005-1846" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html" source="CONFIRM" patch="1" adv="1">http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html" source="CONFIRM" patch="1" adv="1">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yamt" name="yamt">
        <vers num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1847" published="2005-01-20" name="CVE-2005-1847" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html" source="CONFIRM" patch="1" adv="1">http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html" source="CONFIRM" patch="1" adv="1">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yamt" name="yamt">
        <vers prev="1" num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1848" published="2005-07-11" name="CVE-2005-1848" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-750" source="DEBIAN" patch="1" adv="1">DSA-750</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-603.html" source="REDHAT">RHSA-2005:603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phystech" name="dhcpcd">
        <vers num="1.3.17_pl2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1849" published="2005-07-26" name="CVE-2005-1849" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-763" source="DEBIAN" patch="1" adv="1">DSA-763</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162680" source="FEDORA">FLSA:162680</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21456" source="XF">zlib-codetable-dos(21456)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1267" source="VUPEN">ADV-2007-1267</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-9916286-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-9916286-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-3616065-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-3616065-patch.html</ref>
      <ref url="http://www.ubuntulinux.org/usn/usn-151-3" source="UBUNTU">USN-151-3</ref>
      <ref url="http://www.securityfocus.com/bid/14340" source="BID">14340</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded" source="BUGTRAQ">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0629.html" source="REDHAT">RHSA-2008:0629</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-584.html" source="REDHAT">RHSA-2005:584</ref>
      <ref url="http://www.osvdb.org/18141" source="OSVDB">18141</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_43_zlib.html" source="SUSE">SUSE-SA:2005:043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:070" source="MANDRIVA">MDKSA-2006:070</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:196" source="MANDRIVA">MDKSA-2005:196</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-18.xml" source="GENTOO">GLSA-200603-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200509-18.xml" source="GENTOO">GLSA-200509-18</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1026" source="DEBIAN">DSA-1026</ref>
      <ref url="http://www.debian.org/security/2005/dsa-797" source="DEBIAN">DSA-797</ref>
      <ref url="http://securitytracker.com/id?1014540" source="SECTRACK">1014540</ref>
      <ref url="http://security.debian.org/pool/updates/main/z/zlib/zlib_1.2.2-4.sarge.2.diff.gz" source="MISC">http://security.debian.org/pool/updates/main/z/zlib/zlib_1.2.2-4.sarge.2.diff.gz</ref>
      <ref url="http://secunia.com/advisories/31492" source="SECUNIA" adv="1">31492</ref>
      <ref url="http://secunia.com/advisories/24788" source="SECUNIA" adv="1">24788</ref>
      <ref url="http://secunia.com/advisories/19597" source="SECUNIA" adv="1">19597</ref>
      <ref url="http://secunia.com/advisories/19550" source="SECUNIA" adv="1">19550</ref>
      <ref url="http://secunia.com/advisories/19334" source="SECUNIA" adv="1">19334</ref>
      <ref url="http://secunia.com/advisories/18377" source="SECUNIA" adv="1">18377</ref>
      <ref url="http://secunia.com/advisories/17516" source="SECUNIA" adv="1">17516</ref>
      <ref url="http://secunia.com/advisories/17326" source="SECUNIA" adv="1">17326</ref>
      <ref url="http://secunia.com/advisories/16137" source="SECUNIA" adv="1">16137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11402" source="OVAL">oval:org.mitre.oval:def:11402</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.6/SCOSA-2006.6.txt" source="SCO">SCOSA-2006.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="zlib">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1850" published="2005-07-19" name="CVE-2005-1850" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Certain contributed scripts for ekg Gadu Gadu client 1.5 and earlier create temporary files insecurely, with unknown impact and attack vectors, a different vulnerability than CVE-2005-1916.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-760" source="DEBIAN" patch="1" adv="1">DSA-760</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2" source="BUGTRAQ">20050721 Multiple vulnerabilities in libgadu and ekg package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="1.0" />
        <vers num="1.0_rc2" />
        <vers num="1.0_rc3" />
        <vers num="1.1" />
        <vers num="1.1_rc1" />
        <vers num="1.1_rc2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5_rc1" />
        <vers num="1.5_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1851" published="2005-07-19" name="CVE-2005-1851" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A certain contributed script for ekg Gadu Gadu client 1.5 and earlier allows attackers to execute shell commands via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-760" source="DEBIAN" patch="1" adv="1">DSA-760</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2" source="BUGTRAQ">20050721 Multiple vulnerabilities in libgadu and ekg package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="1.0" />
        <vers num="1.0_rc2" />
        <vers num="1.0_rc3" />
        <vers num="1.1" />
        <vers num="1.1_rc1" />
        <vers num="1.1_rc2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5_rc1" />
        <vers num="1.5_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1852" published="2005-07-26" name="CVE-2005-1852" modified="2010-12-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14345" source="BID" patch="1">14345 </ref>
      <ref url="http://www.kde.org/info/security/advisory-20050721-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050721-1.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200507-23.xml" source="GENTOO" patch="1" adv="1">GLSA-200507-23</ref>
      <ref url="http://lwn.net/Articles/144724/" source="FEDORA" patch="1" adv="1">FEDORA-2005-624</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-639.html" source="REDHAT">RHSA-2005:639</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-26.xml" source="GENTOO">GLSA-200507-26</ref>
      <ref url="http://secunia.com/advisories/16242" source="SECUNIA" adv="1">16242</ref>
      <ref url="http://secunia.com/advisories/16211" source="SECUNIA" adv="1">16211</ref>
      <ref url="http://secunia.com/advisories/16155" source="SECUNIA" adv="1">16155</ref>
      <ref url="http://secunia.com/advisories/16140" source="SECUNIA" adv="1">16140</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9532" source="OVAL">oval:org.mitre.oval:def:9532</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2" source="BUGTRAQ" adv="1">20050721 Multiple vulnerabilities in libgadu and ekg package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centericq" name="centericq">
        <vers num="" />
      </prod>
      <prod vendor="ekg" name="ekg">
        <vers num="1.0" />
        <vers num="1.0_rc2" />
        <vers num="1.0_rc3" />
        <vers num="1.1" />
        <vers num="1.1_rc1" />
        <vers num="1.1_rc2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5_rc1" />
        <vers num="1.5_rc2" />
      </prod>
      <prod vendor="kadu" name="kadu">
        <vers num="" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.4" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1853" published="2005-08-03" name="CVE-2005-1853" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/alerts/2005/Jul/1014599.html" source="SECTRACK">1014599</ref>
      <ref url="http://www.debian.org/security/2005/dsa-770" source="DEBIAN" adv="1">DSA-770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_minnesota" name="gopher">
        <vers num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1854" published="2005-08-05" name="CVE-2005-1854" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on the caching server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21664" source="XF" patch="1">aptcacher-command-execution(21664)</ref>
      <ref url="http://www.securityfocus.com/bid/14459" source="BID" patch="1">14459</ref>
      <ref url="http://www.debian.org/security/2005/dsa-772" source="DEBIAN" patch="1" adv="1">DSA-772</ref>
      <ref url="http://secunia.com/advisories/16327" source="SECUNIA" patch="1" adv="1">16327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="apt-cacher">
        <vers num="0.9.4" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1855" published="2005-08-30" name="CVE-2005-1855" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.sukria.net/packages/backup-manager/" source="CONFIRM" patch="1">http://www.sukria.net/packages/backup-manager/</ref>
      <ref url="http://www.securityfocus.com/bid/13892" source="BID" patch="1">13892</ref>
      <ref url="http://www.debian.org/security/2005/dsa-787" source="DEBIAN" patch="1" adv="1">DSA-787</ref>
      <ref url="http://securitytracker.com/id?1014124" source="SECTRACK" patch="1">1014124</ref>
      <ref url="http://secunia.com/advisories/15615" source="SECUNIA" patch="1" adv="1">15615</ref>
      <ref url="http://www.usenetlinux.com/archive/index.php/t-411815.html" source="MISC">http://www.usenetlinux.com/archive/index.php/t-411815.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sukria" name="backup_manager">
        <vers num="0.5.6" />
        <vers num="0.5.7" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":ia-32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1856" published="2005-08-30" name="CVE-2005-1856" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-787" source="DEBIAN" patch="1" adv="1">DSA-787</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1857" published="2005-09-02" name="CVE-2005-1857" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/139421" source="CERT-VN">VU#139421</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22016" source="XF" patch="1">simpleproxy-reply-format-string(22016)</ref>
      <ref url="http://www.securityfocus.com/bid/14666" source="BID" patch="1">14666</ref>
      <ref url="http://www.debian.org/security/2005/dsa-786" source="DEBIAN" patch="1" adv="1">DSA-786</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=604&amp;release_id=351847" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=604&amp;release_id=351847</ref>
      <ref url="http://secunia.com/advisories/16567/" source="SECUNIA" adv="1">16567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simpleproxy" name="simpleproxy">
        <vers num="2.2b" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1858" published="2005-06-03" name="CVE-2005-1858" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15561/" source="SECUNIA" patch="1" adv="1">15561</ref>
      <ref url="http://www.sven-tantau.de/public_files/fuse/fuse_20050603.txt" source="MISC" adv="1">http://www.sven-tantau.de/public_files/fuse/fuse_20050603.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13857" source="BID">13857</ref>
      <ref url="http://www.osvdb.org/17042" source="OSVDB" adv="1">17042</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=331884" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=331884</ref>
      <ref url="http://bugs.debian.org/311634" source="CONFIRM" adv="1">http://bugs.debian.org/311634</ref>
      <ref url="http://www.debian.org/security/2005/dsa-744" source="DEBIAN">DSA-744</ref>
      <ref url="http://securitytracker.com/id?1014107" source="SECTRACK">1014107</ref>
      <ref url="http://secunia.com/advisories/16024" source="SECUNIA">16024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fuse" name="fuse">
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.3_pre" />
        <vers num="2.3_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1859" published="2005-07-12" name="CVE-2005-1859" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in arshell in the Array Service (arrayd) for SGI ProPack 3 with SP 5 and 6, and SGI ProPack 4, allows local users to execute arbitrary shells as root on other hosts in the cluster or array.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014454" source="SECTRACK" patch="1">1014454</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050701-01-P.asc" source="SGI" patch="1" adv="1">20050701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" edition="sp5" />
        <vers num="3.0" edition="sp6" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1864" published="2005-06-09" name="CVE-2005-1864" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/alerts/2005/May/1014083.html" source="SECTRACK" adv="1">1014083</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0356.html" source="BUGTRAQ" adv="1">20050531 multiple vulnerability Calendarix Advanced</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vincent_hor" name="calendarix_advanced">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1865" published="2005-06-09" name="CVE-2005-1865" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Calendarix Advanced 1.5 allow remote attackers to execute arbitrary SQL commands via the catview parameter to (1) cal_week.php, (2) cal_cat.php, or (3) cal_day.php, or (4) id parameter to cal_pophols.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16975" source="OSVDB">16975</ref>
      <ref url="http://www.osvdb.org/16974" source="OSVDB">16974</ref>
      <ref url="http://www.osvdb.org/16972" source="OSVDB">16972</ref>
      <ref url="http://www.osvdb.org/16971" source="OSVDB">16971</ref>
      <ref url="http://securitytracker.com/alerts/2005/May/1014083.html" source="SECTRACK">1014083</ref>
      <ref url="http://secunia.com/advisories/15569" source="SECUNIA">15569</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0356.html" source="BUGTRAQ">20050531 multiple vulnerability Calendarix Advanced</ref>
      <ref url="http://www.calendarix.com/download_basic.php" source="CONFIRM">http://www.calendarix.com/download_basic.php</ref>
      <ref url="http://www.calendarix.com/download_advanced.php" source="CONFIRM">http://www.calendarix.com/download_advanced.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vincent_hor" name="calendarix_advanced">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1866" published="2005-05-31" name="CVE-2005-1866" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/16973" source="OSVDB" adv="1">16973</ref>
      <ref url="http://securitytracker.com/alerts/2005/May/1014083.html" source="SECTRACK" adv="1">1014083</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0356.html" source="BUGTRAQ" adv="1">20050531 multiple vulnerability Calendarix Advanced</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vincent_hor" name="calendarix_advanced">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1867" published="2005-06-09" name="CVE-2005-1867" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2005.05.31a.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2005.05.31a.html</ref>
      <ref url="http://secunia.com/advisories/15562" source="SECUNIA" patch="1" adv="1">15562</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20804" source="XF">brightmail-static-database-security-bypass(20804)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0671" source="VUPEN">ADV-2005-0671</ref>
      <ref url="http://securitytracker.com/id?1014088" source="SECTRACK">1014088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="brightmail_antispam">
        <vers num="4.0" />
        <vers num="5.5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1868" published="2005-06-09" name="CVE-2005-1868" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=331422" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=331422</ref>
      <ref url="http://secunia.com/advisories/15558/" source="SECUNIA" patch="1" adv="1">15558</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20857" source="XF">iman-file-upload(20857)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="i-man" name="i-man">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1869" published="2005-06-07" name="CVE-2005-1869" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in start_lobby.php in MWChat 6.x allows remote attackers to execute arbitrary PHP code via the CONFIG[MWCHAT_Libs] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/alerts/2005/Jun/1014090.html" source="SECTRACK" patch="1" adv="1">1014090</ref>
      <ref url="http://www.appindex.net" source="CONFIRM" patch="1" adv="1">http://www.appindex.net</ref>
      <ref url="http://www.osvdb.org/17087" source="OSVDB" adv="1">17087</ref>
      <ref url="http://www.defacers.com.mx/advisories/4.txt" source="MISC" adv="1">http://www.defacers.com.mx/advisories/4.txt</ref>
      <ref url="http://secunia.com/advisories/15596" source="SECUNIA">15596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="appindex" name="mwchat">
        <vers prev="1" num="6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1870" published="2005-06-09" name="CVE-2005-1870" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17085" source="OSVDB">17085</ref>
      <ref url="http://securitytracker.com/id?1014116" source="SECTRACK">1014116</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-06-07" source="MISC">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-06-07</ref>
      <ref url="http://secunia.com/advisories/15584" source="SECUNIA" adv="1">15584</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111801389729155&amp;w=2" source="FULLDISC">20050605 Re: LSS.hr false positives. (correction)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034425.html" source="FULLDISC">20050606 Popper webmail remote code execution vulnerability - advisory fix</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034408.html" source="FULLDISC">20050604 LSS.hr false positives.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="popper" name="popper">
        <vers num="1.41_r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1871" published="2005-06-09" name="CVE-2005-1871" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17028" source="OSVDB">17028</ref>
      <ref url="http://secunia.com/advisories/15372" source="SECUNIA">15372</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111782257601422&amp;w=2" source="BUGTRAQ">20050603 [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-06/0010.html" source="FULLDISC">20050603 [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.5.0" />
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1872" published="2005-06-03" name="CVE-2005-1872" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg24009775" source="MISC" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg24009775</ref>
      <ref url="http://secunia.com/advisories/15598/" source="SECUNIA" patch="1" adv="1">15598</ref>
      <ref url="http://www.osvdb.org/17041" source="OSVDB" adv="1">17041</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/general/WEBSPHERE-001.html" source="MISC" adv="1">http://www.appsecinc.com/resources/alerts/general/WEBSPHERE-001.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817727120752&amp;w=2" source="BUGTRAQ" adv="1">20050607 [AppSecInc Advisory WEBSP05-V0098] Remote Buffer overflow in WebSphere Application Server Administrative Console</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1873" published="2005-06-09" name="CVE-2005-1873" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command with a long string or (2) a globbing ("*") character followed by a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034426.html" source="FULLDISC">20050606 Crob FTP Server remote buffer overflows</ref>
      <ref url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-06-06" source="MISC">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-06-06</ref>
      <ref url="http://secunia.com/advisories/15585" source="SECUNIA">15585</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crob" name="crob_ftp">
        <vers num="3.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1874" published="2005-06-09" name="CVE-2005-1874" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Dzip before 2.9 allows remote attackers to create arbitrary files via a filename containing a .. (dot dot) in a .dz archive.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=93079" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=93079</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0692" source="VUPEN">ADV-2005-0692</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-03.xml" source="GENTOO" adv="1">GLSA-200506-03</ref>
      <ref url="http://secunia.com/advisories/15614" source="SECUNIA">15614</ref>
      <ref url="http://secunia.com/advisories/15599" source="SECUNIA">15599</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1875" published="2005-06-02" name="CVE-2005-1875" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15583" source="SECUNIA" patch="1" adv="1">15583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773894525119&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050602 SEC-CONSULT SA20050602-2 :: Exhibit Engine Blind SQL Injection</ref>
      <ref url="http://www.securityfocus.com/bid/13844" source="BID" adv="1">13844</ref>
      <ref url="http://www.osvdb.org/17006" source="OSVDB" adv="1">17006</ref>
      <ref url="http://photography-on-the.net/forum/showthread.php?p=579692" source="CONFIRM" adv="1">http://photography-on-the.net/forum/showthread.php?p=579692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exhibit_engine" name="exhibit_engine">
        <vers num="1.22" />
        <vers num="1.54_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1876" published="2005-06-09" name="CVE-2005-1876" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17030" source="OSVDB">17030</ref>
      <ref url="http://secunia.com/advisories/15594" source="SECUNIA">15594</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773528322711&amp;w=2" source="BUGTRAQ">20050602 PHP Execution Vulnerability in CuteNews</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1877" published="2005-06-06" name="CVE-2005-1877" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13869" source="BID" adv="1">13869</ref>
      <ref url="http://secunia.com/advisories/15589/" source="SECUNIA">15589</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034413.html" source="FULLDISC" adv="1">20050606 Lpanel.NET's Lpanel (all versions up to and including 1.59) is vulnerable to plain-text session credential leakage via script injection.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lpanel" name="lpanel">
        <vers num="1.59" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1878" published="2005-06-09" name="CVE-2005-1878" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zataz.net/adviso/giptables-05222005.txt" source="MISC">http://www.zataz.net/adviso/giptables-05222005.txt</ref>
      <ref url="http://secunia.com/advisories/15604" source="SECUNIA">15604</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034423.html" source="FULLDISC">20050606 GIPTables Firewall &lt;= v1.1 insecure temporary file creation</ref>
      <ref url="http://securitytracker.com/id?1014109" source="SECTRACK">1014109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="giptables" name="giptables_firewall">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1879" published="2005-06-09" name="CVE-2005-1879" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">LutelWall 0.97 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zataz.net/adviso/lutelwall-05222005.txt" source="MISC">http://www.zataz.net/adviso/lutelwall-05222005.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13863" source="BID">13863</ref>
      <ref url="http://securitytracker.com/id?1014112" source="SECTRACK">1014112</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-10.xml" source="GENTOO">GLSA-200506-10</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034424.html" source="FULLDISC">20050606 LutelWall &lt;= 0.97 insecure temporary file creation</ref>
      <ref url="http://firewall.lutel.pl/download/0.98/ChangeLog" source="CONFIRM">http://firewall.lutel.pl/download/0.98/ChangeLog</ref>
      <ref url="http://secunia.com/advisories/15665" source="SECUNIA">15665</ref>
      <ref url="http://secunia.com/advisories/15647" source="SECUNIA">15647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomasz_lutelmowski" name="lutelwall">
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1880" published="2005-06-06" name="CVE-2005-1880" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zataz.net/adviso/everybuddy-06062005.txt" source="MISC" adv="1">http://www.zataz.net/adviso/everybuddy-06062005.txt</ref>
      <ref url="http://www.securityfocus.com/bid/13865" source="BID" adv="1">13865</ref>
      <ref url="http://securitytracker.com/id?1014110" source="SECTRACK" adv="1">1014110</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034422.html" source="FULLDISC" adv="1">20050606 everybuddy &lt;= 0.4.3 insecure temporary file creation</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=94473" source="MISC" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=94473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="everybuddy" name="everybuddy">
        <vers num="0.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1881" published="2005-06-06" name="CVE-2005-1881" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17115" source="OSVDB" adv="1">17115</ref>
      <ref url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt" source="MISC" adv="1">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref>
      <ref url="http://securitytracker.com/id?1014103" source="SECTRACK" adv="1">1014103</ref>
      <ref url="http://secunia.com/advisories/15600/" source="SECUNIA" adv="1">15600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yapig" name="yapig">
        <vers num="0.92b" />
        <vers num="0.93u" />
        <vers num="0.94u" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1882" published="2005-06-09" name="CVE-2005-1882" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17117" source="OSVDB">17117</ref>
      <ref url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt" source="MISC" adv="1">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref>
      <ref url="http://securitytracker.com/id?1014103" source="SECTRACK">1014103</ref>
      <ref url="http://secunia.com/advisories/15600/" source="SECUNIA" adv="1">15600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yapig" name="yapig">
        <vers num="0.93u" />
        <vers num="0.94u" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1883" published="2005-06-09" name="CVE-2005-1883" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17116" source="OSVDB">17116</ref>
      <ref url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt" source="MISC" adv="1">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref>
      <ref url="http://securitytracker.com/id?1014103" source="SECTRACK" adv="1">1014103</ref>
      <ref url="http://secunia.com/advisories/15600/" source="SECUNIA" adv="1">15600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yapig" name="yapig">
        <vers num="0.92b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1884" published="2005-06-09" name="CVE-2005-1884" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13877" source="BID">13877</ref>
      <ref url="http://www.osvdb.org/17120" source="OSVDB">17120</ref>
      <ref url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt" source="MISC" adv="1">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref>
      <ref url="http://securitytracker.com/id?1014103" source="SECTRACK">1014103</ref>
      <ref url="http://secunia.com/advisories/15600/" source="SECUNIA">15600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yapig" name="yapig">
        <vers num="0.92b" />
        <vers num="0.93u" />
        <vers num="0.94u" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1885" published="2005-06-06" name="CVE-2005-1885" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to obtain sensitive information via a phid parameter that is not an integer, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17119" source="OSVDB" adv="1">17119</ref>
      <ref url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt" source="MISC" adv="1">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref>
      <ref url="http://securitytracker.com/id?1014103" source="SECTRACK" adv="1">1014103</ref>
      <ref url="http://secunia.com/advisories/15600/" source="SECUNIA" adv="1">15600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yapig" name="yapig">
        <vers num="0.92b" />
        <vers num="0.93u" />
        <vers num="0.94u" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1886" published="2005-06-09" name="CVE-2005-1886" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13876" source="BID">13876</ref>
      <ref url="http://www.securityfocus.com/bid/13875" source="BID">13875</ref>
      <ref url="http://www.osvdb.org/17118" source="OSVDB">17118</ref>
      <ref url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt" source="MISC" adv="1">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref>
      <ref url="http://securitytracker.com/id?1014103" source="SECTRACK" adv="1">1014103</ref>
      <ref url="http://secunia.com/advisories/15600/" source="SECUNIA" adv="1">15600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yapig" name="yapig">
        <vers num="0.92b" />
        <vers num="0.93u" />
        <vers num="0.94u" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1887" published="2005-06-09" name="CVE-2005-1887" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20874" source="XF">solaris-clibrary-libproject-gain-privileges(20874)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0690" source="VUPEN">ADV-2005-0690</ref>
      <ref url="http://www.osvdb.org/17099" source="OSVDB">17099</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101740-1" source="SUNALERT" adv="1">101740</ref>
      <ref url="http://secunia.com/advisories/15613" source="SECUNIA">15613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1888" published="2005-06-06" name="CVE-2005-1888" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13861" source="BID" patch="1" adv="1">13861</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=332231" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=332231</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4_beta1" />
        <vers num="1.4_beta2" />
        <vers num="1.4_beta3" />
        <vers num="1.4_beta4" />
        <vers num="1.4_beta5" />
        <vers num="stable_2003-08-29" />
        <vers num="stable_2003-11-07" />
        <vers num="stable_2003-11-17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1889" published="2005-06-07" name="CVE-2005-1889" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101690-1" source="SUNALERT" patch="1" adv="1">101690</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0695" source="VUPEN">ADV-2005-0695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers prev="1" num="6.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1890" published="2005-06-07" name="CVE-2005-1890" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Mortiforo before 0.9.1 allows users to access private forums via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014120" source="SECTRACK" patch="1" adv="1">1014120</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=332807" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=332807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mortiforo" name="mortiforo">
        <vers prev="1" num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1891" published="2005-06-09" name="CVE-2005-1891" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13880" source="BID">13880</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817881214343&amp;w=2" source="BUGTRAQ">20050607 Re: AOL AIM Instant Messenger Buddy Icon "ateimg32.dll" DoS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111816939928640&amp;w=2" source="BUGTRAQ">20050607 AOL AIM Instant Messenger Buddy Icon "ateimg32.dll" DoS</ref>
      <ref url="http://securitytracker.com/id?1014145" source="SECTRACK">1014145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="5.0.2938" />
        <vers num="5.1.3036" />
        <vers num="5.2.3292" />
        <vers num="5.5" />
        <vers num="5.5.3415_beta" />
        <vers num="5.5.3595" />
        <vers num="5.9.3797" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1892" published="2005-06-09" name="CVE-2005-1892" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt" source="MISC" patch="1" adv="1">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0697" source="VUPEN">ADV-2005-0697</ref>
      <ref url="http://securitytracker.com/id?1014114" source="SECTRACK">1014114</ref>
      <ref url="http://secunia.com/advisories/15603" source="SECUNIA">15603</ref>
      <ref url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256" source="CONFIRM">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="1.0" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="2.0" />
        <vers prev="1" num="2.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1893" published="2005-06-09" name="CVE-2005-1893" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt" source="MISC" patch="1" adv="1">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref>
      <ref url="http://securitytracker.com/id?1014114" source="SECTRACK" patch="1">1014114</ref>
      <ref url="http://secunia.com/advisories/15603" source="SECUNIA" patch="1">15603</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0697" source="VUPEN">ADV-2005-0697</ref>
      <ref url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256" source="CONFIRM">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="2.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1894" published="2005-06-09" name="CVE-2005-1894" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt" source="MISC" patch="1" adv="1">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref>
      <ref url="http://securitytracker.com/id?1014114" source="SECTRACK" patch="1">1014114</ref>
      <ref url="http://secunia.com/advisories/15603" source="SECUNIA" patch="1" adv="1">15603</ref>
      <ref url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256" source="CONFIRM" patch="1">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0697" source="VUPEN">ADV-2005-0697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="2.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1895" published="2005-06-09" name="CVE-2005-1895" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014114" source="SECTRACK" patch="1">1014114</ref>
      <ref url="http://secunia.com/advisories/15603" source="SECUNIA" patch="1">15603</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0697" source="VUPEN">ADV-2005-0697</ref>
      <ref url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt" source="MISC" adv="1">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref>
      <ref url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256" source="CONFIRM">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="2.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1896" published="2005-06-09" name="CVE-2005-1896" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via the image parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt" source="MISC" patch="1" adv="1">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref>
      <ref url="http://securitytracker.com/id?1014114" source="SECTRACK" patch="1">1014114</ref>
      <ref url="http://secunia.com/advisories/15603" source="SECUNIA" patch="1" adv="1">15603</ref>
      <ref url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256" source="CONFIRM" patch="1">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0697" source="VUPEN">ADV-2005-0697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="2.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1897" published="2005-06-09" name="CVE-2005-1897" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15441" source="SECUNIA">15441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flexcast" name="flexcast_audio_video_streaming_server">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1898" published="2005-06-09" name="CVE-2005-1898" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15534" source="SECUNIA" patch="1">15534</ref>
      <ref url="http://www.securityfocus.com/bid/13842" source="BID">13842</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=330469" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=330469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpthumb" name="phpthumb">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1899" published="2005-06-09" name="CVE-2005-1899" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13862" source="BID">13862</ref>
      <ref url="http://aluigi.altervista.org/adv/rakzero-adv.txt" source="MISC">http://aluigi.altervista.org/adv/rakzero-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1014111" source="SECTRACK">1014111</ref>
      <ref url="http://secunia.com/advisories/15597" source="SECUNIA">15597</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111809312423958&amp;w=2" source="BUGTRAQ">20050605 Server termination in Raknet 2.33 (before 30 May 2005)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rakkarsoft" name="raknet">
        <vers prev="1" num="2.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1900" published="2005-06-09" name="CVE-2005-1900" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15499" source="SECUNIA" patch="1">15499</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20880" source="XF">sawmill-unknown-add-license(20880)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20879" source="XF">sawmill-unknown-gain-access(20879)</ref>
      <ref url="http://www.sawmill.net/version_history7.html" source="CONFIRM">http://www.sawmill.net/version_history7.html</ref>
      <ref url="http://www.osvdb.org/17101" source="OSVDB">17101</ref>
      <ref url="http://www.osvdb.org/17100" source="OSVDB">17100</ref>
      <ref url="http://www.networksecurity.fi/advisories/sawmill-admin.html" source="MISC">http://www.networksecurity.fi/advisories/sawmill-admin.html</ref>
      <ref url="http://securitytracker.com/id?1014106" source="SECTRACK">1014106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sawmill" name="sawmill">
        <vers prev="1" num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.1b" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1901" published="2005-06-09" name="CVE-2005-1901" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the username in the Add User window or (2) the license key in the Licensing page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15499" source="SECUNIA" patch="1">15499</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20881" source="XF">sawmill-add-user-xss(20881)</ref>
      <ref url="http://www.sawmill.net/version_history7.html" source="CONFIRM">http://www.sawmill.net/version_history7.html</ref>
      <ref url="http://www.osvdb.org/17103" source="OSVDB">17103</ref>
      <ref url="http://www.osvdb.org/17102" source="OSVDB">17102</ref>
      <ref url="http://www.networksecurity.fi/advisories/sawmill-admin.html" source="MISC">http://www.networksecurity.fi/advisories/sawmill-admin.html</ref>
      <ref url="http://securitytracker.com/id?1014106" source="SECTRACK">1014106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sawmill" name="sawmill">
        <vers prev="1" num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.1b" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1902" published="2005-06-09" name="CVE-2005-1902" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, and (4) RENAME commands.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20860" source="XF" patch="1">spa-pro-imap-diectory-traversal(20860)</ref>
      <ref url="http://www.security.org.sg/vuln/spa-promail4.html" source="MISC" patch="1" adv="1">http://www.security.org.sg/vuln/spa-promail4.html</ref>
      <ref url="http://secunia.com/advisories/15573" source="SECUNIA" patch="1" adv="1">15573</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0680" source="VUPEN">ADV-2005-0680</ref>
      <ref url="http://www.osvdb.org/16989" source="OSVDB">16989</ref>
      <ref url="http://securitytracker.com/id?1014095" source="SECTRACK">1014095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-post_corporation" name="spa-pro_mail_atsolomon">
        <vers num="4.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1903" published="2005-06-02" name="CVE-2005-1903" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrary code via a long CREATE command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20862" source="XF" patch="1" adv="1">spa-pro-create-bo(20862)</ref>
      <ref url="http://www.security.org.sg/vuln/spa-promail4.html" source="MISC" patch="1" adv="1">http://www.security.org.sg/vuln/spa-promail4.html</ref>
      <ref url="http://www.osvdb.org/16990" source="OSVDB" patch="1" adv="1">16990</ref>
      <ref url="http://secunia.com/advisories/15573" source="SECUNIA" patch="1" adv="1">15573</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0680" source="VUPEN">ADV-2005-0680</ref>
      <ref url="http://securitytracker.com/id?1014095" source="SECTRACK">1014095</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1904" published="2005-06-09" name="CVE-2005-1904" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in JiRo's Upload System (JUS) 1 allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.under9round.com/jus.txt" source="MISC" adv="1">http://www.under9round.com/jus.txt</ref>
      <ref url="http://www.osvdb.org/16969" source="OSVDB">16969</ref>
      <ref url="http://securitytracker.com/id?1014086" source="SECTRACK">1014086</ref>
      <ref url="http://secunia.com/advisories/15564" source="SECUNIA">15564</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1905" published="2005-06-09" name="CVE-2005-1905" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13878" source="BID">13878</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817777430401&amp;w=2" source="BUGTRAQ">20050607 Kaspersky AntiVirus "klif.sys" Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="5.0.227" edition="" />
        <vers num="5.0.227" edition=":windows_file_servers" />
        <vers num="5.0.228" edition="" />
        <vers num="5.0.228" edition=":windows_file_servers" />
        <vers num="5.0.335" edition="" />
        <vers num="5.0.335" edition=":windows_file_servers" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus_personal">
        <vers num="5.0.227" />
        <vers num="5.0.228" />
        <vers num="5.0.325" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1906" published="2005-06-02" name="CVE-2005-1906" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in livingmailing 1.3 allows remote attackers to execute arbitrary SQL commands via the password. NOTE: there is little public information about this product and its vendor, and the original researcher announcement is no longer available.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0678" source="VUPEN">ADV-2005-0678</ref>
      <ref url="http://securitytracker.com/id?1014087" source="SECTRACK" adv="1">1014087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="livingmailing" name="livingmailing">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1907" published="2005-05-31" name="CVE-2005-1907" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13846" source="BID">13846</ref>
      <ref url="http://www.osvdb.org/17031" source="OSVDB">17031</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/br-20050602-00456.html?lang=en" source="MISC">http://www.niscc.gov.uk/niscc/docs/br-20050602-00456.html?lang=en</ref>
      <ref url="http://www.networksecurity.fi/advisories/windows-isa-firewall.html" source="MISC">http://www.networksecurity.fi/advisories/windows-isa-firewall.html</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;894864" source="MSKB">894864</ref>
      <ref url="http://securitytracker.com/id?1014113" source="SECTRACK">1014113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1908" published="2005-06-09" name="CVE-2005-1908" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17084" source="OSVDB">17084</ref>
      <ref url="http://securitytracker.com/id?1014096" source="SECTRACK">1014096</ref>
      <ref url="http://secunia.com/advisories/15592" source="SECUNIA">15592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perception" name="liteweb">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1909" published="2005-06-09" name="CVE-2005-1909" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The web server control panel in 602LAN SUITE 2004 allows remote attackers to make it more difficult for the administrator to read portions of log files via a "&lt;/pre>&lt;!-" sequence in an HTTP GET request in the logon, possibly due to a cross-site scripting (XSS) vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014105" source="SECTRACK">1014105</ref>
      <ref url="http://rgod.altervista.org/602_en.html" source="MISC">http://rgod.altervista.org/602_en.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602lan_suite">
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1910" published="2005-06-05" name="CVE-2005-1910" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp for WWWeb Concepts Events System 1.0 allows remote attackers to execute arbitrary SQL commands via the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.under9round.com/wecs.txt" source="MISC" adv="1">http://www.under9round.com/wecs.txt</ref>
      <ref url="http://securitytracker.com/id?1014104" source="SECTRACK">1014104</ref>
      <ref url="http://secunia.com/advisories/15595" source="SECUNIA">15595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wwweb_concepts" name="events_system">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1911" published="2005-06-09" name="CVE-2005-1911" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The fetchnews NNTP client in leafnode 1.11.2 and earlier can hang while waiting for input that never arrives, which allows remote NNTP servers to cause a denial of service (news loss).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://leafnode.sourceforge.net/leafnode-SA-2005-02.txt" source="CONFIRM" adv="1">http://leafnode.sourceforge.net/leafnode-SA-2005-02.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leafnode" name="leafnode">
        <vers num="1.10.0" />
        <vers num="1.11.1" />
        <vers num="1.9.19" />
        <vers num="1.9.20" />
        <vers num="1.9.21" />
        <vers num="1.9.22" />
        <vers num="1.9.23" />
        <vers num="1.9.24" />
        <vers num="1.9.25" />
        <vers num="1.9.26" />
        <vers num="1.9.27" />
        <vers num="1.9.28" />
        <vers num="1.9.29" />
        <vers num="1.9.30" />
        <vers num="1.9.31" />
        <vers num="1.9.32" />
        <vers num="1.9.33" />
        <vers num="1.9.34" />
        <vers num="1.9.35" />
        <vers num="1.9.36" />
        <vers num="1.9.37" />
        <vers num="1.9.38" />
        <vers num="1.9.39" />
        <vers num="1.9.40" />
        <vers num="1.9.41" />
        <vers num="1.9.42" />
        <vers num="1.9.43" />
        <vers num="1.9.44" />
        <vers num="1.9.45" />
        <vers num="1.9.46" />
        <vers num="1.9.47" />
        <vers num="1.9.48" />
        <vers num="1.9.52" />
        <vers num="1.9.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1912" reject="1" published="2005-07-07" name="CVE-2005-1912" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1841.  Reason: This candidate is a duplicate of CVE-2005-1841.  Notes: this duplicate occurred as a result of separate assignments by multiple CNAs, one to the researcher and one to the vendor.  All CVE users should reference CVE-2005-1841 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1913" published="2005-09-14" name="CVE-2005-1913" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Linux kernel 2.6 before 2.6.12.1 allows local users to cause a denial of service (kernel panic) via a non group-leader thread executing a different program than was pending in itimer, which causes the signal to be delivered to the old group-leader task, which does not exist.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21138" source="XF" patch="1">kernel-subthread-dos(21138)</ref>
      <ref url="http://www.securityfocus.com/bid/14054" source="BID" patch="1">14054</ref>
      <ref url="http://secunia.com/advisories/15786/" source="SECUNIA" patch="1" adv="1">15786</ref>
      <ref url="http://www.ubuntu.com/usn/usn-178-1" source="UBUNTU" adv="1">USN-178-1</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.1" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1914" published="2005-07-18" name="CVE-2005-1914" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">CenterICQ 4.20.0 and earlier creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack on the gg.token.PID temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-754" source="DEBIAN" patch="1" adv="1">DSA-754</ref>
      <ref url="http://www.zataz.net/adviso/centericq-06152005.txt" source="MISC" adv="1">http://www.zataz.net/adviso/centericq-06152005.txt</ref>
      <ref url="http://www.securityfocus.com/bid/14144" source="BID">14144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centericq" name="centericq">
        <vers num="4.10.0.1" />
        <vers num="4.11.0.1" />
        <vers num="4.12" />
        <vers num="4.12.0.1" />
        <vers num="4.13" />
        <vers num="4.13.0.1" />
        <vers num="4.14" />
        <vers num="4.14.0.1" />
        <vers num="4.20" />
        <vers num="4.20.0.1" />
        <vers num="4.5.0.3" />
        <vers num="4.5.1" />
        <vers num="4.5.1.3" />
        <vers num="4.6.0" />
        <vers num="4.6.0.3" />
        <vers num="4.6.5" />
        <vers num="4.6.5.3" />
        <vers num="4.6.9" />
        <vers num="4.6.9.3" />
        <vers num="4.7.1" />
        <vers num="4.7.1.3" />
        <vers num="4.7.2" />
        <vers num="4.7.2.3" />
        <vers num="4.7.7" />
        <vers num="4.7.7.3" />
        <vers num="4.7.8" />
        <vers num="4.7.8.3" />
        <vers num="4.8.0" />
        <vers num="4.8.0.1" />
        <vers num="4.8.2" />
        <vers num="4.8.2.1" />
        <vers num="4.8.3" />
        <vers num="4.8.3.1" />
        <vers num="4.8.4" />
        <vers num="4.8.4.1" />
        <vers num="4.8.5" />
        <vers num="4.8.5.1" />
        <vers num="4.8.6" />
        <vers num="4.8.6.1" />
        <vers num="4.8.7" />
        <vers num="4.8.7.1" />
        <vers num="4.8.8" />
        <vers num="4.8.8.1" />
        <vers num="4.8.9" />
        <vers num="4.9.0" />
        <vers num="4.9.0.1" />
        <vers num="4.9.1" />
        <vers num="4.9.1.1" />
        <vers num="4.9.10" />
        <vers num="4.9.10.1" />
        <vers num="4.9.11" />
        <vers num="4.9.11.1" />
        <vers num="4.9.12" />
        <vers num="4.9.12.1" />
        <vers num="4.9.2" />
        <vers num="4.9.2.1" />
        <vers num="4.9.3" />
        <vers num="4.9.3.1" />
        <vers num="4.9.4" />
        <vers num="4.9.4.1" />
        <vers num="4.9.5" />
        <vers num="4.9.5.1" />
        <vers num="4.9.6" />
        <vers num="4.9.6.1" />
        <vers num="4.9.7" />
        <vers num="4.9.7.1" />
        <vers num="4.9.8" />
        <vers num="4.9.9" />
        <vers num="4.9.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1915" published="2005-09-02" name="CVE-2005-1915" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The log4sh_readProperties function in log4sh 1.2.5 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable log4sh.$$ filenames.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14140" source="BID" patch="1">14140</ref>
      <ref url="http://www.zataz.net/adviso/log4sh-06092005.txt" source="MISC" adv="1">http://www.zataz.net/adviso/log4sh-06092005.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0957" source="VUPEN">ADV-2005-0957</ref>
      <ref url="http://secunia.com/advisories/15899" source="SECUNIA" adv="1">15899</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=94069" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=94069</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-July/034873.html" source="FULLDISC">20050704 log4sh insecure temporary file creation</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q3/0001.html" source="VULNWATCH">20050705 log4sh insecure temporary file creation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="log4sh" name="log4sh">
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1916" published="2005-07-06" name="CVE-2005-1916" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zataz.net/adviso/ekg-06062005.txt" source="MISC" adv="1">http://www.zataz.net/adviso/ekg-06062005.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112060146011122&amp;w=2" source="BUGTRAQ" adv="1">20050705 ekg insecure temporary file creation and arbitrary code execution</ref>
      <ref url="http://www.debian.org/security/2005/dsa-760" source="DEBIAN">DSA-760</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2" source="BUGTRAQ">20050721 Multiple vulnerabilities in libgadu and ekg package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="2005-06-05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1917" published="2005-07-05" name="CVE-2005-1917" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zataz.net/adviso/kpopper-06152005.txt" source="MISC" adv="1">http://www.zataz.net/adviso/kpopper-06152005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kpopper" name="kpopper">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1918" published="2005-12-31" name="CVE-2005-1918" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/5834" source="BID" patch="1">5834</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430297/100/0/threaded" source="FEDORA" patch="1" adv="1">FLSA:183571-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0195.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0195</ref>
      <ref url="http://securitytracker.com/id?1015655" source="SECTRACK" patch="1">1015655</ref>
      <ref url="http://secunia.com/advisories/19183" source="SECUNIA" patch="1" adv="1">19183</ref>
      <ref url="http://secunia.com/advisories/18988" source="SECUNIA" patch="1" adv="1">18988</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=140589" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=140589</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE" adv="1">SUSE-SR:2006:005</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-110.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-110.htm</ref>
      <ref url="http://secunia.com/advisories/20397" source="SECUNIA" adv="1">20397</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA" adv="1">19130</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9946" source="OVAL">oval:org.mitre.oval:def:9946</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc" source="SGI">20060301-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="tar">
        <vers num="1.13.25" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ia64" />
        <vers num="2.1" edition=":itanium" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1919" reject="1" published="2005-12-31" name="CVE-2005-1919" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1920" published="2005-07-26" name="CVE-2005-1920" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050718-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050718-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112171434023679&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050718 [KDE Security Advisory]: Kate backup file permission leak</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9434" source="OVAL">oval:org.mitre.oval:def:9434</ref>
      <ref url="http://www.securityfocus.com/bid/14297" source="BID">14297</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" source="FEDORA">FLSA:178606</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-612.html" source="REDHAT">RHSA-2005:612</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-804" source="DEBIAN">DSA-804</ref>
      <ref url="http://securitytracker.com/id?1014512" source="SECTRACK">1014512</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200611-21.xml" source="GENTOO">GLSA-200611-21</ref>
      <ref url="http://secunia.com/advisories/23099" source="SECUNIA">23099</ref>
      <ref url="http://secunia.com/advisories/16099" source="SECUNIA">16099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.4" />
        <vers num="3.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1921" published="2005-07-05" name="CVE-2005-1921" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:109" source="MANDRAKE" patch="1" adv="1">MDKSA-2005:109</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00087-07012005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00087-07012005</ref>
      <ref url="http://pear.php.net/package/XML_RPC/download/1.3.1" source="MISC" patch="1">http://pear.php.net/package/XML_RPC/download/1.3.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008638320145&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050629 Advisory 02/2005: Remote code execution in Serendipity</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2827" source="VUPEN">ADV-2005-2827</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded" source="HP">HPSBTU02083</ref>
      <ref url="http://www.hardened-php.net/advisory-022005.php" source="MISC" adv="1">http://www.hardened-php.net/advisory-022005.php</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11294" source="OVAL">oval:org.mitre.oval:def:11294</ref>
      <ref url="http://www.securityfocus.com/bid/14088" source="BID">14088</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded" source="HP">HPSBTU02083</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-564.html" source="REDHAT">RHSA-2005:564</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_49_php.html" source="SUSE">SUSE-SA:2005:049</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_41_php_pear.html" source="SUSE">SUSE-SA:2005:041</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt" source="CONFIRM">http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt</ref>
      <ref url="http://www.debian.org/security/2005/dsa-789" source="DEBIAN">DSA-789</ref>
      <ref url="http://www.debian.org/security/2005/dsa-747" source="DEBIAN">DSA-747</ref>
      <ref url="http://www.debian.org/security/2005/dsa-746" source="DEBIAN">DSA-746</ref>
      <ref url="http://www.debian.org/security/2005/dsa-745" source="DEBIAN">DSA-745</ref>
      <ref url="http://www.ampache.org/announce/3_3_1_2.php" source="CONFIRM">http://www.ampache.org/announce/3_3_1_2.php</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=338803" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=338803</ref>
      <ref url="http://sourceforge.net/project/showfiles.php?group_id=87163" source="CONFIRM">http://sourceforge.net/project/showfiles.php?group_id=87163</ref>
      <ref url="http://securitytracker.com/id?1015336" source="SECTRACK">1015336</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200507-07.xml" source="GENTOO">GLSA-200507-07</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200507-06.xml" source="GENTOO">GLSA-200507-06</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200507-01.xml" source="GENTOO">GLSA-200507-01</ref>
      <ref url="http://secunia.com/advisories/18003" source="SECUNIA">18003</ref>
      <ref url="http://secunia.com/advisories/17674" source="SECUNIA">17674</ref>
      <ref url="http://secunia.com/advisories/17440" source="SECUNIA">17440</ref>
      <ref url="http://secunia.com/advisories/16693" source="SECUNIA">16693</ref>
      <ref url="http://secunia.com/advisories/16339" source="SECUNIA">16339</ref>
      <ref url="http://secunia.com/advisories/16001" source="SECUNIA">16001</ref>
      <ref url="http://secunia.com/advisories/15957" source="SECUNIA">15957</ref>
      <ref url="http://secunia.com/advisories/15947" source="SECUNIA">15947</ref>
      <ref url="http://secunia.com/advisories/15944" source="SECUNIA">15944</ref>
      <ref url="http://secunia.com/advisories/15922" source="SECUNIA">15922</ref>
      <ref url="http://secunia.com/advisories/15917" source="SECUNIA">15917</ref>
      <ref url="http://secunia.com/advisories/15916" source="SECUNIA">15916</ref>
      <ref url="http://secunia.com/advisories/15904" source="SECUNIA">15904</ref>
      <ref url="http://secunia.com/advisories/15903" source="SECUNIA">15903</ref>
      <ref url="http://secunia.com/advisories/15895" source="SECUNIA">15895</ref>
      <ref url="http://secunia.com/advisories/15884" source="SECUNIA">15884</ref>
      <ref url="http://secunia.com/advisories/15883" source="SECUNIA">15883</ref>
      <ref url="http://secunia.com/advisories/15872" source="SECUNIA">15872</ref>
      <ref url="http://secunia.com/advisories/15861" source="SECUNIA">15861</ref>
      <ref url="http://secunia.com/advisories/15855" source="SECUNIA">15855</ref>
      <ref url="http://secunia.com/advisories/15852" source="SECUNIA">15852</ref>
      <ref url="http://secunia.com/advisories/15810" source="SECUNIA">15810</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2" source="SUSE">SUSE-SA:2005:051</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112015336720867&amp;w=2" source="BUGTRAQ">20050629 [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:350" source="OVAL" sig="1">oval:org.mitre.oval:def:350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pear" name="xml_rpc">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.0rc1" />
        <vers num="1.2.0rc2" />
        <vers num="1.2.0rc3" />
        <vers num="1.2.0rc4" />
        <vers num="1.2.0rc5" />
        <vers num="1.2.0rc6" />
        <vers num="1.2.0rc7" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.3.0rc1" />
        <vers num="1.3.0rc2" />
        <vers num="1.3.0rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1922" published="2005-07-05" name="CVE-2005-1922" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=276&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" patch="1" adv="1">20050629 Clam AntiVirus ClamAV MS-Expand File Handling DoS Vulnerability</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=336462" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=336462</ref>
      <ref url="http://www.debian.org/security/2005/dsa-737" source="DEBIAN">DSA-737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1923" published="2005-07-05" name="CVE-2005-1923" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff, which causes a zero-length read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=275&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050629 Clam AntiVirus ClamAV Cabinet File Handling DoS Vulnerability</ref>
      <ref url="http://www.debian.org/security/2005/dsa-737" source="DEBIAN">DSA-737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.83" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1924" published="2005-12-31" name="CVE-2005-1924" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b) import_key_text.php, and (c) keyring_main.php; and (2) the keyserver parameter to the gpg_recv_key function in gpg_key_functions.php, as called by gpg_options.php.  NOTE: this issue may overlap CVE-2007-3636.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2513" source="VUPEN">ADV-2007-2513</ref>
      <ref url="http://www.securityfocus.com/bid/24874" source="BID">24874</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/473370/100/0/threaded" source="BUGTRAQ">20070711 SquirrelMail G/PGP Encryption Plug-in Remote Command Execution Vulnerability</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-July/001710.html" source="VIM">20070711 True: SquirrelMail G/PGP Encryption Plug-in 2.0 Command Execution Vuln</ref>
      <ref url="http://secunia.com/advisories/26035" source="SECUNIA" adv="1">26035</ref>
      <ref url="http://milw0rm.com/exploits/4173" source="MILW0RM">4173</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=331" source="IDEFENSE">20070711 SquirrelMail G/PGP Plugin gpg_recv_key() Command Injection Vulnerability</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=329" source="IDEFENSE">20070711 SquirrelMail G/PGP Plugin deleteKey() Command Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35364" source="XF">squirrelmail-gpgp-keyfunc-command-execution(35364)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35355" source="XF">squirrelmail-gpgp-keyring-command-execution(35355)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200708-08.xml" source="GENTOO">GLSA-200708-08</ref>
      <ref url="http://secunia.com/advisories/26424" source="SECUNIA">26424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="gpg_plugin">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1925" published="2005-11-18" name="CVE-2005-1925" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=337&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20051110 Tikiwiki tiki-editpage Arbitrary File Exposure Vulnerability</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=335&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20051110 Tikiwiki tiki-user_preferences Command Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23099" source="XF">tikiwiki-tikiuserpreferences-dir-traversal(23099)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23095" source="XF">tikiwiki-tikieditpage-directory-traversal(23095)</ref>
      <ref url="http://www.securityfocus.com/bid/15392" source="BID">15392</ref>
      <ref url="http://www.securityfocus.com/bid/15390" source="BID">15390</ref>
      <ref url="http://securitytracker.com/id?1015190" source="SECTRACK">1015190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki_project" name="tikiwiki">
        <vers num="0.9" />
        <vers num="0.95" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.1.1" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1928" published="2005-12-14" name="CVE-2005-1928" modified="2011-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of crafted packets with a certain "magic value" to port 5005, which also leads to a memory leak.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/2907" source="VUPEN" adv="1">ADV-2005-2907</ref>
      <ref url="http://www.securityfocus.com/bid/15868" source="BID">15868</ref>
      <ref url="http://www.osvdb.org/21773" source="OSVDB">21773</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=356&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20051214 Trend Micro ServerProtect EarthAgent Remote DoS Vulnerability</ref>
      <ref url="http://solutionfile.trendmicro.com/SolutionFile/25254/en/Hotfix_Readme_SPNT5_58_B1137.txt" source="MISC">http://solutionfile.trendmicro.com/SolutionFile/25254/en/Hotfix_Readme_SPNT5_58_B1137.txt</ref>
      <ref url="http://securitytracker.com/id?1015358" source="SECTRACK">1015358</ref>
      <ref url="http://securityreason.com/securityalert/259" source="SREASON">259</ref>
      <ref url="http://secunia.com/advisories/18038" source="SECUNIA" adv="1">18038</ref>
      <ref url="http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=25254" source="MISC">http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=25254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect_earthagent">
        <vers num="5.58" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1929" published="2005-12-14" name="CVE-2005-1929" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests.  NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load.  As such, this might not be a vulnerability in Trend Micro's product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/2907" source="VUPEN" adv="1">ADV-2005-2907</ref>
      <ref url="http://www.securityfocus.com/bid/15866" source="BID">15866</ref>
      <ref url="http://www.securityfocus.com/bid/15865" source="BID">15865</ref>
      <ref url="http://www.osvdb.org/21772" source="OSVDB">21772</ref>
      <ref url="http://www.osvdb.org/21771" source="OSVDB">21771</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=353&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20051214 Trend Micro ServerProtect isaNVWRequest.dll Chunked Overflow</ref>
      <ref url="http://securitytracker.com/id?1015358" source="SECTRACK">1015358</ref>
      <ref url="http://securityreason.com/securityalert/257" source="SREASON">257</ref>
      <ref url="http://securityreason.com/securityalert/256" source="SREASON">256</ref>
      <ref url="http://secunia.com/advisories/18038" source="SECUNIA" adv="1">18038</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/039978.html" source="FULLDISC">20051214 Re: iDefense Security Advisory 12.14.05: Trend Micro ServerProtect relay.dll Chunked Overflow Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/039972.html" source="FULLDISC">20051214 Re: iDefense Security Advisory 12.14.05: Trend Micro ServerProtect relay.dll Chunked Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers prev="1" num="5.58" edition="" />
        <vers prev="1" num="5.58" edition=":emc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1930" published="2005-12-14" name="CVE-2005-1930" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary files via the IMAGE parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/2907" source="VUPEN">ADV-2005-2907</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=352&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20051214 Trend Micro ServerProtect Crystal Reports ReportServer File Disclosure</ref>
      <ref url="http://www.securityfocus.com/bid/15867" source="BID">15867</ref>
      <ref url="http://www.osvdb.org/21770" source="OSVDB">21770</ref>
      <ref url="http://securitytracker.com/id?1015358" source="SECTRACK">1015358</ref>
      <ref url="http://securityreason.com/securityalert/258" source="SREASON">258</ref>
      <ref url="http://secunia.com/advisories/18038" source="SECUNIA">18038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58" edition="" />
        <vers num="5.58" edition=":emc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1931" published="2005-07-05" name="CVE-2005-1931" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15623" source="SECUNIA" patch="1" adv="1">15623</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817606013776&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050607 Denial of Service vulnerability in GoodTech SMTP Server for Windows NT/2000/XP version 5.14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goodtech_systems" name="goodtech_smtp_server">
        <vers num="5.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1932" published="2005-07-05" name="CVE-2005-1932" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13869" source="BID" patch="1">13869</ref>
      <ref url="http://www.lpanel.net/changelog.php" source="CONFIRM">http://www.lpanel.net/changelog.php</ref>
      <ref url="http://secunia.com/advisories/15589/" source="SECUNIA" adv="1">15589</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034419.html" source="FULLDISC">20050606 Lpanel.NET's Lpanel (all versions up to and including 1.59) is vulnerable in that it allows an attacker to reset the DNS information of any domain name managed by the system.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034418.html" source="FULLDISC" adv="1">20050606 Lpanel.NET's Lpanel (all versions up to and including 1.59) is vulnerable in that it allows an attacker to respond to any support ticket on the system.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034417.html" source="FULLDISC" adv="1">20050606 Lpanel.NET's Lpanel (all versions up to and including 1.59) is vulnerable to the unauthorized viewing of client invoice information.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034416.html" source="FULLDISC" adv="1">20050606 Lpanel.NET's Lpanel (all versions up to and including 1.59) is vulnerable to unauthorized domain management access.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034415.html" source="FULLDISC" adv="1">20050606 Lpanel.NET's Lpanel (all versions up to and including 1.59) is vulnerable in that it allows an attacker to open any support ticket within the system.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034414.html" source="FULLDISC" adv="1">20050606 Lpanel.NET's Lpanel (all versions up to and including 1.59) is vulnerable in that it allows an attacker to close any support ticket within the system.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lpanel" name="lpanel">
        <vers num="1.59" />
        <vers num="1.593" />
        <vers num="1.594" />
        <vers num="1.596" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1933" published="2005-06-13" name="CVE-2005-1933" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/983429" source="CERT-VN" adv="1">VU#983429</ref>
      <ref url="http://www1.cs.columbia.edu/~aaron/files/widgets/" source="MISC" adv="1">http://www1.cs.columbia.edu/~aaron/files/widgets/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1934" published="2005-05-19" name="CVE-2005-1934" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gaim before 1.3.1 allows remote attackers to cause a denial of service (crash) via a malformed MSN message that leads to a memory allocation of a large size, possibly due to an integer signedness error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1205290&amp;group_id=235&amp;atid=100235" source="CONFIRM" adv="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1205290&amp;group_id=235&amp;atid=100235</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-11.xml" source="GENTOO">GLSA-200506-11</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10368" source="OVAL">oval:org.mitre.oval:def:10368</ref>
      <ref url="http://www.securityfocus.com/bid/13932" source="BID">13932</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-518.html" source="REDHAT">RHSA-2005:518</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:099" source="MANDRAKE">MDKSA-2005:099</ref>
      <ref url="http://www.debian.org/security/2005/dsa-734" source="DEBIAN">DSA-734</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:263" source="OVAL" sig="1">oval:org.mitre.oval:def:263</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers prev="1" num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1935" published="2005-06-13" name="CVE-2005-1935" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a SPNEGO token with a constructed bit string during HTTP authentication, and a different vulnerability than CVE-2003-0818.  NOTE: the researcher has claimed that MS:MS04-007 fixes this issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20870" source="XF" patch="1">asn1-constructed-heap-overflow(20870)</ref>
      <ref url="http://www.phreedom.org/solar/exploits/msasn1-bitstring/" source="MISC">http://www.phreedom.org/solar/exploits/msasn1-bitstring/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:workstation" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1936" published="2005-06-13" name="CVE-2005-1936" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the web server for the ESS/ Network Controller for Xerox Document Centre 240 through 555 running System Software 27.18.017 and earlier allows attackers to "gain unauthorized access."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19661" source="XF" patch="1">xerox-document-security-bypass(19661)</ref>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_003.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_003.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/12783" source="BID" patch="1">12783</ref>
      <ref url="http://secunia.com/advisories/14556" source="SECUNIA" patch="1" adv="1">14556</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0255" source="VUPEN">ADV-2005-0255</ref>
      <ref url="http://www.osvdb.org/14659" source="OSVDB">14659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="document_centre_220">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_230">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_240">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_255">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_265">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_332">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_340">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_420">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_425">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_426">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_430">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_432">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_440">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_460">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_470">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_480">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_490">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_535">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_545">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="document_centre_555">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1937" published="2005-06-14" name="CVE-2005-1937" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=296850" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=296850</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10633" source="OVAL">oval:org.mitre.oval:def:10633</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-51.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-51.html</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://www.debian.org/security/2005/dsa-777" source="DEBIAN">DSA-777</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101952-1" source="SUNALERT">101952</ref>
      <ref url="http://secunia.com/advisories/15601" source="SECUNIA">15601</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:759" source="OVAL" sig="1">oval:org.mitre.oval:def:759</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:637" source="OVAL" sig="1">oval:org.mitre.oval:def:637</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100007" source="OVAL" sig="1">oval:org.mitre.oval:def:100007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1938" reject="1" published="2005-06-30" name="CVE-2005-1938" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1250.  Reason: This candidate is a duplicate of CVE-2005-1250.  Notes: this duplicate occurred as a result of multiple independent discoveries and insufficient coordination by the vendor and CNA.  All CVE users should reference CVE-2005-1250 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1939" published="2005-12-31" name="CVE-2005-1939" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/22969" source="XF">whatsup-smallbusiness-dotdot-traversal(22969)</ref>
      <ref url="http://www.securityfocus.com/bid/15291" source="BID">15291</ref>
      <ref url="http://securitytracker.com/id?1015141" source="SECTRACK">1015141</ref>
      <ref url="http://secunia.com/secunia_research/2005-14/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-14/advisory/</ref>
      <ref url="http://secunia.com/advisories/15500" source="SECUNIA" adv="1">15500</ref>
      <ref url="http://cirt.dk/advisories/cirt-40-advisory.pdf" source="MISC" adv="1">http://cirt.dk/advisories/cirt-40-advisory.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="whatsup_small_business">
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1941" published="2005-06-08" name="CVE-2005-1941" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-05</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=93558" source="MISC" patch="1" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=93558</ref>
      <ref url="http://securitytracker.com/id?1014153" source="SECTRACK">1014153</ref>
      <ref url="http://secunia.com/advisories/15632" source="SECUNIA">15632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silvercity" name="silvercity">
        <vers num="0.9.5_r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1942" published="2005-06-10" name="CVE-2005-1942" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco switches that support 802.1x security allow remote attackers to bypass port security and gain access to the VLAN via spoofed Cisco Discovery Protocol (CDP) messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20939" source="XF" adv="1">cisco-callmanager-voice-gain-access(20939)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Jun/1014135.html" source="SECTRACK" adv="1">1014135</ref>
      <ref url="http://www.fishnetsecurity.com/csirt/disclosure/cisco/Cisco+802.1x+Advisory.pdf" source="MISC" adv="1">http://www.fishnetsecurity.com/csirt/disclosure/cisco/Cisco+802.1x+Advisory.pdf</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sn-20050608-8021x.shtml" source="CISCO">20050608 Cisco 802.1x Voice-Enabled Interfaces Allow Anonymous Voice VLAN Access</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111842833009771&amp;w=2" source="BUGTRAQ" adv="1">20050610 Voice VLAN Access/Abuse Possible on Cisco voice-enabled, 802.1x-secured Interfaces Vulnerability Discovery: FishNet Security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1943" published="2005-06-08" name="CVE-2005-1943" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13900" source="BID">13900</ref>
      <ref url="http://www.securityfocus.com/bid/13898" source="BID">13898</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111826992711703&amp;w=2" source="BUGTRAQ" adv="1">20050608 2 SQL injection in Loki download manager v2.0</ref>
      <ref url="http://securitytracker.com/id?1014147" source="SECTRACK">1014147</ref>
      <ref url="http://secunia.com/advisories/15633" source="SECUNIA">15633</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1944" published="2005-06-09" name="CVE-2005-1944" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15635" source="SECUNIA">15635</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111833993822553&amp;w=2" source="BUGTRAQ">20050609 xmysqladmin insecure temporary file creation</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=93792" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=93792</ref>
      <ref url="http://www.zataz.net/adviso/xmysqladmin-05292005.txt" source="MISC">http://www.zataz.net/adviso/xmysqladmin-05292005.txt</ref>
      <ref url="http://securitytracker.com/id?1014172" source="SECTRACK">1014172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmysqladmin" name="xmysqladmin">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1945" published="2005-06-09" name="CVE-2005-1945" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00078-06072005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00078-06072005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111833601302752&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050609 Invision Community Blog Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/15626" source="SECUNIA">15626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_community_blog">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1946" published="2005-06-09" name="CVE-2005-1946" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00078-06072005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00078-06072005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111833601302752&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050609 Invision Community Blog Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/15626" source="SECUNIA">15626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_community_blog">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1947" published="2005-06-09" name="CVE-2005-1947" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00079-06092005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00079-06092005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111834146710329&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050609 Invision Gallery Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_gallery">
        <vers num="1.0.1" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1948" published="2005-06-09" name="CVE-2005-1948" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00079-06092005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00079-06092005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111834146710329&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050609 Invision Gallery Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/13907" source="BID">13907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_gallery">
        <vers num="1.0.1" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1949" published="2005-06-16" name="CVE-2005-1949" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868460811287&amp;w=2" source="BUGTRAQ" adv="1">20050610 Re: Arbitrary code execution in eping plugin</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111835539312985&amp;w=2" source="BUGTRAQ" adv="1">20050609 Arbitrary code execution in eping plugin</ref>
      <ref url="http://secunia.com/advisories/15678" source="SECUNIA">15678</ref>
      <ref url="http://e107plugins.co.uk/news.php" source="CONFIRM">http://e107plugins.co.uk/news.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1950" published="2005-06-09" name="CVE-2005-1950" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13930" source="BID">13930</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111842893001406&amp;w=2" source="BUGTRAQ" adv="1">20050609 Webhints v1.03 Remote Command Execution</ref>
      <ref url="http://securitytracker.com/id?1014173" source="SECTRACK">1014173</ref>
      <ref url="http://secunia.com/advisories/15652" source="SECUNIA">15652</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darryl_burgdorf" name="webhints">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1951" published="2005-06-16" name="CVE-2005-1951" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13979" source="BID">13979</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111842744205117&amp;w=2" source="BUGTRAQ" adv="1">20050610 osCommere HTTP Response Splitting</ref>
      <ref url="http://secunia.com/advisories/15670" source="SECUNIA">15670</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111936255011735&amp;w=2" source="BUGTRAQ">20050616 RE: osCommere HTTP Response Splitting (Solution)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="oscommerce">
        <vers num="2.1" />
        <vers num="2.2_cvs" />
        <vers num="2.2_ms1" />
        <vers num="2.2_ms2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1952" published="2005-06-16" name="CVE-2005-1952" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequence in the URL, which results in an incorrect directory depth count.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=59378&amp;release_id=334036" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=59378&amp;release_id=334036</ref>
      <ref url="http://secunia.com/advisories/15663" source="SECUNIA">15663</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111852830111316&amp;w=2" source="BUGTRAQ" adv="1">20050611 Multiple vulnerabilities in Pico Server (pServ) v3.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pico_server" name="pico_server">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1953" published="2005-06-11" name="CVE-2005-1953" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=59378&amp;release_id=334036" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?group_id=59378&amp;release_id=334036</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111852830111316&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050611 Multiple vulnerabilities in Pico Server (pServ) v3.3</ref>
      <ref url="http://secunia.com/advisories/15663" source="SECUNIA">15663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pico_server" name="pico_server">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1954" published="2005-06-16" name="CVE-2005-1954" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">singapore 0.9.11 allows remote attackers to obtain sensitive information via a direct request to (1) admin.class.php, (2) any .tpl.php file in templates/admin_default/, or (3) any .tpl.php file in templates/default/, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868634003167&amp;w=2" source="BUGTRAQ" adv="1">20050612 singapore v0.9.11 cross site scripting and path disclosure</ref>
      <ref url="http://securitytracker.com/id?1014186" source="SECTRACK">1014186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="singapore" name="singapore">
        <vers num="0.9.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1955" published="2005-06-12" name="CVE-2005-1955" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13938" source="BID">13938</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868634003167&amp;w=2" source="BUGTRAQ" adv="1">20050612 singapore v0.9.11 cross site scripting and path disclosure</ref>
      <ref url="http://securitytracker.com/id?1014186" source="SECTRACK">1014186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="singapore" name="singapore">
        <vers num="0.9.11_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1956" published="2005-06-12" name="CVE-2005-1956" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868578006615&amp;w=2" source="BUGTRAQ" adv="1">20050612 File Upload Manager Sploits</ref>
      <ref url="http://www.osvdb.org/20257" source="OSVDB">20257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="file_upload_manager" name="file_upload_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1957" published="2005-06-12" name="CVE-2005-1957" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/20258" source="OSVDB">20258</ref>
      <ref url="http://www.osvdb.org/17435" source="OSVDB">17435</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868578006615&amp;w=2" source="BUGTRAQ" adv="1">20050612 File Upload Manager Sploits</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-06/0116.html" source="BUGTRAQ">20050615 Re: File Upload Manager Sploits</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adam_mmedici" name="file_upload_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-1958" reject="1" published="2005-06-07" name="CVE-2005-1958" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1855.  Reason: This candidate is a duplicate of CVE-2005-1855.  Notes: All CVE users should reference CVE-2005-1855 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <config />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-1959" published="2005-06-12" name="CVE-2005-1959" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014175" source="SECTRACK" adv="1">1014175</ref>
      <ref url="http://www.securityfocus.com/bid/13937" source="BID">13937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jammail" name="jammail">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1960" published="2005-06-08" name="CVE-2005-1960" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15582" source="SECUNIA" patch="1" adv="1">15582</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-06/0057.html" source="BUGTRAQ" adv="1">20050607 remote command execution in 'tattle'</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1961" published="2005-06-07" name="CVE-2005-1961" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in ObjectWeb Consortium C-JDBC before 1.3.1 allows local users to bypass intended access restrictions and obtain the cache results from another user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014118" source="SECTRACK" patch="1" adv="1">1014118</ref>
      <ref url="http://secunia.com/advisories/15627" source="SECUNIA" patch="1" adv="1">15627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="objectweb" name="consortium_c-jdbc">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1962" published="2005-06-16" name="CVE-2005-1962" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://forum.cerberusweb.com/showthread.php?threadid=5162&amp;goto=newpost" source="CONFIRM">http://forum.cerberusweb.com/showthread.php?threadid=5162&amp;goto=newpost</ref>
      <ref url="http://echo.or.id/adv/adv15-theday-2005.txt" source="MISC">http://echo.or.id/adv/adv15-theday-2005.txt</ref>
      <ref url="http://securitytracker.com/id?1014128" source="SECTRACK">1014128</ref>
      <ref url="http://secunia.com/advisories/15641" source="SECUNIA">15641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerberus" name="cerberus_helpdesk">
        <vers num="0.97.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1963" published="2005-06-16" name="CVE-2005-1963" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://forum.cerberusweb.com/showthread.php?threadid=5162&amp;goto=newpost" source="CONFIRM">http://forum.cerberusweb.com/showthread.php?threadid=5162&amp;goto=newpost</ref>
      <ref url="http://echo.or.id/adv/adv15-theday-2005.txt" source="MISC">http://echo.or.id/adv/adv15-theday-2005.txt</ref>
      <ref url="http://www.wgmdev.com/jira/browse/CERB-170" source="CONFIRM">http://www.wgmdev.com/jira/browse/CERB-170</ref>
      <ref url="http://securitytracker.com/id?1014128" source="SECTRACK">1014128</ref>
      <ref url="http://secunia.com/advisories/15641" source="SECUNIA">15641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerberus" name="cerberus_helpdesk">
        <vers num="0.97.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1964" published="2005-06-09" name="CVE-2005-1964" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in utilit.php for Ovidentia Portal allows remote attackers to execute arbitrary PHP code via the babInstallPath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014149" source="SECTRACK" adv="1">1014149</ref>
      <ref url="http://secunia.com/advisories/15658" source="SECUNIA">15658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cantico" name="ovidentia">
        <vers num="fx" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1965" published="2005-06-16" name="CVE-2005-1965" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20973" source="XF">siteframe-localpath-file-include(20973)</ref>
      <ref url="http://www.securityfocus.com/bid/13928" source="BID">13928</ref>
      <ref url="http://www.osvdb.org/17246" source="OSVDB">17246</ref>
      <ref url="http://securitytracker.com/id?1014150" source="SECTRACK">1014150</ref>
      <ref url="http://secunia.com/advisories/15657" source="SECUNIA" adv="1">15657</ref>
      <ref url="http://list.broadpool.com/pipermail/siteframe-announce/2005-June/000020.html" source="MLIST">[Siteframe-Announce] 20060621 WARNING: Security Vulnerability identified in Siteframe 3.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glen_campbell" name="siteframe">
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.4" />
        <vers num="3.1.6" />
        <vers num="3.1.8_beta" />
        <vers num="3.1.9" />
        <vers num="3.2_p5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1966" published="2005-06-10" name="CVE-2005-1966" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13934" source="BID" adv="1">13934</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868460811287&amp;w=2" source="BUGTRAQ" adv="1">20050610 Re: Arbitrary code execution in eping plugin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1967" published="2005-06-16" name="CVE-2005-1967" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014129" source="SECTRACK">1014129</ref>
      <ref url="http://echo.or.id/adv/adv16-theday-2005.txt" source="MISC">http://echo.or.id/adv/adv16-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart_ecommerce">
        <vers prev="1" num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1968" published="2005-06-08" name="CVE-2005-1968" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014129" source="SECTRACK" adv="1">1014129</ref>
      <ref url="http://echo.or.id/adv/adv16-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv16-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1969" published="2005-06-07" name="CVE-2005-1969" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a "&lt;!--" (HTML comment) in a session.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rgod.altervista.org/pragma.html" source="MISC" adv="1">http://www.rgod.altervista.org/pragma.html</ref>
      <ref url="http://securitytracker.com/id?1014127" source="SECTRACK" adv="1">1014127</ref>
      <ref url="http://secunia.com/advisories/15642" source="SECUNIA">15642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pragma_systems" name="pragma_telnetserver">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1970" published="2005-06-16" name="CVE-2005-1970" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13933" source="BID" patch="1">13933</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2005.06.10.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2005.06.10.html</ref>
      <ref url="http://securitytracker.com/id?1014178" source="SECTRACK">1014178</ref>
      <ref url="http://secunia.com/advisories/15673" source="SECUNIA">15673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="10.0" />
        <vers num="10.5" />
        <vers num="11.0" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1971" published="2005-06-16" name="CVE-2005-1971" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.interactivephp.com/misc/CHANGELOG.html" source="CONFIRM">http://www.interactivephp.com/misc/CHANGELOG.html</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00081-06132005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00081-06132005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interactivephp" name="fusionbb">
        <vers num="11_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1972" published="2005-06-13" name="CVE-2005-1972" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by the insertUser function, or (2) the bb_session_id value in a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.interactivephp.com/misc/CHANGELOG.html" source="CONFIRM" patch="1" adv="1">http://www.interactivephp.com/misc/CHANGELOG.html</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00081-06132005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00081-06132005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interactivephp" name="fusionbb">
        <vers num="11_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1973" published="2005-06-16" name="CVE-2005-1973" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101748-1" source="SUNALERT" adv="1">101748</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112870351003598&amp;w=2" source="HP">HPSBUX01214</ref>
      <ref url="http://www.securityfocus.com/bid/13958" source="BID">13958</ref>
      <ref url="http://www.securityfocus.com/bid/13945" source="BID">13945</ref>
      <ref url="http://securityreason.com/securityalert/61" source="SREASON">61</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112870351003598&amp;w=2" source="HP">SSRT051003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="j2se">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":sdk" />
        <vers num="5.0_update1" edition="" />
        <vers num="5.0_update1" edition=":sdk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1974" published="2005-06-16" name="CVE-2005-1974" modified="2011-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to themselves and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/2150" source="VUPEN" adv="1">ADV-2005-2150</ref>
      <ref url="http://www.securityfocus.com/bid/13958" source="BID">13958</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_32_java2.html" source="SUSE">SUSE-SA:2005:032</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101799-1" source="SUNALERT">101799</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101749-1" source="SUNALERT" adv="1">101749</ref>
      <ref url="http://securitytracker.com/id?1015643" source="SECTRACK">1015643</ref>
      <ref url="http://securityreason.com/securityalert/56" source="SREASON">56</ref>
      <ref url="http://secunia.com/advisories/17272" source="SECUNIA" adv="1">17272</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html" source="CONFIRM">http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html</ref>
      <ref url="http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=7638" source="CONFIRM">http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=7638</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112992075412844&amp;w=2" source="HP">HPSBMA01234</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112992075412844&amp;w=2" source="HP">SSRT051052</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861772130119&amp;w=2" source="HP">HPSBUX01215</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861772130119&amp;w=2" source="HP">HPSBUX01215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="j2se">
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":sdk" />
        <vers num="1.4.2_01" edition="" />
        <vers num="1.4.2_01" edition=":sdk" />
        <vers num="1.4.2_02" edition="" />
        <vers num="1.4.2_02" edition=":sdk" />
        <vers num="1.4.2_03" edition="" />
        <vers num="1.4.2_03" edition=":sdk" />
        <vers num="1.4.2_04" edition="" />
        <vers num="1.4.2_04" edition=":sdk" />
        <vers num="1.4.2_05" edition="" />
        <vers num="1.4.2_05" edition=":sdk" />
        <vers num="1.4.2_06" edition="" />
        <vers num="1.4.2_06" edition=":sdk" />
        <vers num="1.4.2_07" edition="" />
        <vers num="1.4.2_07" edition=":sdk" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":sdk" />
        <vers num="5.0_update1" edition="" />
        <vers num="5.0_update1" edition=":sdk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1975" published="2005-06-16" name="CVE-2005-1975" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13960" source="BID">13960</ref>
      <ref url="http://www.hackisknowledge.org/Advisories/Annuaire%201Two%20v1.0/Annuaire%201Two%20v1.0.html" source="MISC">http://www.hackisknowledge.org/Advisories/Annuaire%201Two%20v1.0/Annuaire%201Two%20v1.0.html</ref>
      <ref url="http://securitytracker.com/id?1014187" source="SECTRACK">1014187</ref>
      <ref url="http://www.securityfocus.com/bid/13961" source="BID">13961</ref>
      <ref url="http://www.securityfocus.com/bid/13612" source="BID">13612</ref>
      <ref url="http://secunia.com/advisories/15708" source="SECUNIA">15708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="annuaire" name="1two">
        <vers num="1.0" />
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1976" published="2005-12-31" name="CVE-2005-1976" modified="2008-09-05" discovered="2005-06-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14005" source="BID" patch="1">14005</ref>
      <ref url="http://www.osvdb.org/17456" source="OSVDB" patch="1">17456</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm</ref>
      <ref url="http://secunia.com/advisories/15763" source="SECUNIA" patch="1" adv="1">15763</ref>
      <ref url="http://securitytracker.com/id?1014251" source="SECTRACK">1014251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netmail">
        <vers num="3.5.2" edition="a" />
        <vers num="3.5.2" edition="b" />
        <vers num="3.5.2" edition="c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1978" published="2005-10-12" name="CVE-2005-1978" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT">TA05-284A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/950516" source="CERT-VN">VU#950516</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx" source="MS" patch="1" adv="1">MS05-051</ref>
      <ref url="http://www.securityfocus.com/bid/15057" source="BID">15057</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://secunia.com/advisories/17509" source="SECUNIA">17509</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://secunia.com/advisories/17161" source="SECUNIA">17161</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:816" source="OVAL" sig="1">oval:org.mitre.oval:def:816</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:576" source="OVAL" sig="1">oval:org.mitre.oval:def:576</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1499" source="OVAL" sig="1">oval:org.mitre.oval:def:1499</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1466" source="OVAL" sig="1">oval:org.mitre.oval:def:1466</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1269" source="OVAL" sig="1">oval:org.mitre.oval:def:1269</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1261" source="OVAL" sig="1">oval:org.mitre.oval:def:1261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="r2" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1979" published="2005-10-12" name="CVE-2005-1979" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx" source="MS" patch="1" adv="1">MS05-051</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=320&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20051011 Microsoft Distributed Transaction Controller TIP DoS Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/15058" source="BID">15058</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://securitytracker.com/id?1015037" source="SECTRACK">1015037</ref>
      <ref url="http://secunia.com/advisories/17509" source="SECUNIA">17509</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://secunia.com/advisories/17161" source="SECUNIA">17161</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:686" source="OVAL" sig="1">oval:org.mitre.oval:def:686</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1550" source="OVAL" sig="1">oval:org.mitre.oval:def:1550</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1513" source="OVAL" sig="1">oval:org.mitre.oval:def:1513</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1338" source="OVAL" sig="1">oval:org.mitre.oval:def:1338</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1283" source="OVAL" sig="1">oval:org.mitre.oval:def:1283</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1134" source="OVAL" sig="1">oval:org.mitre.oval:def:1134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="r2" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1980" published="2005-10-12" name="CVE-2005-1980" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx" source="MS" patch="1" adv="1">MS05-051</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=319&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20051011 Microsoft Distributed Transaction Controller Packet Relay DoS Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/15059" source="BID">15059</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://securitytracker.com/id?1015037" source="SECTRACK">1015037</ref>
      <ref url="http://secunia.com/advisories/17509" source="SECUNIA">17509</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://secunia.com/advisories/17161" source="SECUNIA">17161</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1413" source="OVAL" sig="1">oval:org.mitre.oval:def:1413</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1325" source="OVAL" sig="1">oval:org.mitre.oval:def:1325</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1253" source="OVAL" sig="1">oval:org.mitre.oval:def:1253</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1203" source="OVAL" sig="1">oval:org.mitre.oval:def:1203</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1182" source="OVAL" sig="1">oval:org.mitre.oval:def:1182</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1136" source="OVAL" sig="1">oval:org.mitre.oval:def:1136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="r2" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1981" published="2005-08-10" name="CVE-2005-1981" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/610133" source="CERT-VN">VU#610133</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-042.mspx" source="MS" patch="1">MS05-042</ref>
      <ref url="http://secunia.com/advisories/16368/" source="SECUNIA" patch="1" adv="1">16368</ref>
      <ref url="http://securitytracker.com/id?1014642" source="SECTRACK">1014642</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100105" source="OVAL" sig="1">oval:org.mitre.oval:def:100105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100103" source="OVAL" sig="1">oval:org.mitre.oval:def:100103</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100101" source="OVAL" sig="1">oval:org.mitre.oval:def:100101</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100099" source="OVAL" sig="1">oval:org.mitre.oval:def:100099</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100097" source="OVAL" sig="1">oval:org.mitre.oval:def:100097</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100095" source="OVAL" sig="1">oval:org.mitre.oval:def:100095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1982" published="2005-08-10" name="CVE-2005-1982" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/477341" source="CERT-VN">VU#477341</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-042.mspx" source="MS" patch="1">MS05-042</ref>
      <ref url="http://secunia.com/advisories/16368/" source="SECUNIA" patch="1" adv="1">16368</ref>
      <ref url="http://www.securityfocus.com/bid/14520" source="BID">14520</ref>
      <ref url="http://securitytracker.com/id?1014642" source="SECTRACK">1014642</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100106" source="OVAL" sig="1">oval:org.mitre.oval:def:100106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100104" source="OVAL" sig="1">oval:org.mitre.oval:def:100104</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100102" source="OVAL" sig="1">oval:org.mitre.oval:def:100102</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100100" source="OVAL" sig="1">oval:org.mitre.oval:def:100100</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100098" source="OVAL" sig="1">oval:org.mitre.oval:def:100098</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100096" source="OVAL" sig="1">oval:org.mitre.oval:def:100096</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1983" published="2005-08-10" name="CVE-2005-1983" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html" source="CERT" patch="1">TA05-221A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/998653" source="CERT-VN">VU#998653</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-039.mspx" source="MS" patch="1">MS05-039</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1354" source="VUPEN">ADV-2005-1354</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21602" source="XF">win-plugandplay-bo(21602)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/202" source="ISS">20050809 Windows Plug and Play Remote Compromise</ref>
      <ref url="http://www.securityfocus.com/bid/14513" source="BID">14513</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5YP0E00GKW.html" source="MISC">http://www.securiteam.com/windowsntfocus/5YP0E00GKW.html</ref>
      <ref url="http://www.osvdb.org/18605" source="OSVDB">18605</ref>
      <ref url="http://www.hsc.fr/ressources/presentations/null_sessions/" source="MISC">http://www.hsc.fr/ressources/presentations/null_sessions/</ref>
      <ref url="http://www.frsirt.com/english/alerts/20050814.ZotobA.php" source="MISC">http://www.frsirt.com/english/alerts/20050814.ZotobA.php</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-266.shtml" source="CIAC">P-266</ref>
      <ref url="http://securitytracker.com/id?1014640" source="SECTRACK">1014640</ref>
      <ref url="http://secunia.com/advisories/16372" source="SECUNIA">16372</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0384.html" source="FULLDISC">20050811 Windows 2000 universal exploit for MS05-039</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:783" source="OVAL" sig="1">oval:org.mitre.oval:def:783</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:497" source="OVAL" sig="1">oval:org.mitre.oval:def:497</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:474" source="OVAL" sig="1">oval:org.mitre.oval:def:474</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:267" source="OVAL" sig="1">oval:org.mitre.oval:def:267</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:160" source="OVAL" sig="1">oval:org.mitre.oval:def:160</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100073" source="OVAL" sig="1">oval:org.mitre.oval:def:100073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1984" published="2005-08-10" name="CVE-2005-1984" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html" source="CERT" patch="1">TA05-221A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/220821" source="CERT-VN">VU#220821</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-043.mspx" source="MS" patch="1">MS05-043</ref>
      <ref url="http://secunia.com/advisories/16356/" source="SECUNIA" patch="1" adv="1">16356</ref>
      <ref url="http://www.securityfocus.com/bid/14514" source="BID">14514</ref>
      <ref url="http://securitytracker.com/id?1014638" source="SECTRACK">1014638</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:256" source="OVAL" sig="1">oval:org.mitre.oval:def:256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1405" source="OVAL" sig="1">oval:org.mitre.oval:def:1405</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1045" source="OVAL" sig="1">oval:org.mitre.oval:def:1045</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100077" source="OVAL" sig="1">oval:org.mitre.oval:def:100077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1985" published="2005-10-13" name="CVE-2005-1985" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-046.mspx" source="MS" patch="1" adv="1">MS05-046</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21700" source="XF">win-csnw-bo(21700)</ref>
      <ref url="http://www.securityfocus.com/bid/15066" source="BID">15066</ref>
      <ref url="http://www.osvdb.org/19922" source="OSVDB">19922</ref>
      <ref url="http://securitytracker.com/id?1015041" source="SECTRACK">1015041</ref>
      <ref url="http://secunia.com/advisories/17165" source="SECUNIA">17165</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:910" source="OVAL" sig="1">oval:org.mitre.oval:def:910</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1544" source="OVAL" sig="1">oval:org.mitre.oval:def:1544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1536" source="OVAL" sig="1">oval:org.mitre.oval:def:1536</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1210" source="OVAL" sig="1">oval:org.mitre.oval:def:1210</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1106" source="OVAL" sig="1">oval:org.mitre.oval:def:1106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
        <vers num="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1987" published="2005-10-13" name="CVE-2005-1987" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT" adv="1">TA05-284A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/883460" source="CERT-VN" adv="1">VU#883460</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-048.mspx" source="MS" patch="1" adv="1">MS05-048</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q907245" source="MSKB">Q907245</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112915118302012&amp;w=2" source="BUGTRAQ">20051012 [SEC-1 Advisory] Collaboration Data Objects Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22495" source="XF">win-cdo-bo(22495)</ref>
      <ref url="http://www.securityfocus.com/bid/15067" source="BID">15067</ref>
      <ref url="http://www.osvdb.org/19905" source="OSVDB">19905</ref>
      <ref url="http://securitytracker.com/id?1015039" source="SECTRACK">1015039</ref>
      <ref url="http://securitytracker.com/id?1015038" source="SECTRACK">1015038</ref>
      <ref url="http://secunia.com/advisories/17167" source="SECUNIA">17167</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0289.html" source="FULLDISC">20051012 [SEC-1 Advisory] Collaboration Data Objects Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:848" source="OVAL" sig="1">oval:org.mitre.oval:def:848</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:581" source="OVAL" sig="1">oval:org.mitre.oval:def:581</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1515" source="OVAL" sig="1">oval:org.mitre.oval:def:1515</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1420" source="OVAL" sig="1">oval:org.mitre.oval:def:1420</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1406" source="OVAL" sig="1">oval:org.mitre.oval:def:1406</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1201" source="OVAL" sig="1">oval:org.mitre.oval:def:1201</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1130" source="OVAL" sig="1">oval:org.mitre.oval:def:1130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="r2" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1988" published="2005-08-10" name="CVE-2005-1988" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html" source="CERT" patch="1">TA05-221A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/965206" source="CERT-VN" patch="1">VU#965206</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-038.mspx" source="MS" patch="1">MS05-038</ref>
      <ref url="http://secunia.com/advisories/16373/" source="SECUNIA" patch="1" adv="1">16373</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1353" source="VUPEN">ADV-2005-1353</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:390" source="OVAL" sig="1">oval:org.mitre.oval:def:390</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1335" source="OVAL" sig="1">oval:org.mitre.oval:def:1335</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1216" source="OVAL" sig="1">oval:org.mitre.oval:def:1216</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1140" source="OVAL" sig="1">oval:org.mitre.oval:def:1140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1989" published="2005-08-10" name="CVE-2005-1989" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-038.mspx" source="MS" patch="1">MS05-038</ref>
      <ref url="http://secunia.com/advisories/16373/" source="SECUNIA" patch="1" adv="1">16373</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1353" source="VUPEN">ADV-2005-1353</ref>
      <ref url="http://www.securityfocus.com/bid/14512" source="BID">14512</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:888" source="OVAL" sig="1">oval:org.mitre.oval:def:888</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:790" source="OVAL" sig="1">oval:org.mitre.oval:def:790</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:697" source="OVAL" sig="1">oval:org.mitre.oval:def:697</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1319" source="OVAL" sig="1">oval:org.mitre.oval:def:1319</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100082" source="OVAL" sig="1">oval:org.mitre.oval:def:100082</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100081" source="OVAL" sig="1">oval:org.mitre.oval:def:100081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1990" published="2005-08-10" name="CVE-2005-1990" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html" source="CERT" patch="1">TA05-221A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/959049" source="CERT-VN">VU#959049</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-038.mspx" source="MS" patch="1">MS05-038</ref>
      <ref url="http://secunia.com/advisories/16373/" source="SECUNIA" patch="1" adv="1">16373</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1353" source="VUPEN">ADV-2005-1353</ref>
      <ref url="http://www.securityfocus.com/bid/14511" source="BID">14511</ref>
      <ref url="http://securitytracker.com/id?1014643" source="SECTRACK">1014643</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1337" source="OVAL" sig="1">oval:org.mitre.oval:def:1337</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1235" source="OVAL" sig="1">oval:org.mitre.oval:def:1235</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1221" source="OVAL" sig="1">oval:org.mitre.oval:def:1221</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1061" source="OVAL" sig="1">oval:org.mitre.oval:def:1061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100082" source="OVAL" sig="1">oval:org.mitre.oval:def:100082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-1992" published="2005-06-20" name="CVE-2005-1992" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/684913" source="CERT-VN">VU#684913</ref>
      <ref url="http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-core/5237" source="CONFIRM" patch="1">http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-core/5237</ref>
      <ref url="http://www2.ruby-lang.org/en/20050701.html" source="CONFIRM">http://www2.ruby-lang.org/en/20050701.html</ref>
      <ref url="http://www.securityfocus.com/bid/14016" source="BID">14016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10819" source="OVAL">oval:org.mitre.oval:def:10819</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=315064" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=315064</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-543.html" source="REDHAT">RHSA-2005:543</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-748" source="DEBIAN">DSA-748</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-312.shtml" source="CIAC">P-312</ref>
      <ref url="http://www.auscert.org.au/5509" source="AUSCERT">ESB-2005.0732</ref>
      <ref url="http://secunia.com/advisories/16920/" source="SECUNIA">16920</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html" source="APPLE">APPLE-SA-2005-09-22</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yukihiro_matsumoto" name="ruby">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-1993" published="2005-06-20" name="CVE-2005-1993" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/402741" source="BUGTRAQ" patch="1" adv="1">20050620 Sudo version 1.6.8p9 now available, fixes security issue.</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161116" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161116</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2659" source="VUPEN">ADV-2005-2659</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0821" source="VUPEN">ADV-2005-0821</ref>
      <ref url="http://www.securityfocus.com/bid/13993" source="BID">13993</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11341" source="OVAL">oval:org.mitre.oval:def:11341</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21080" source="XF">sudo-pathname-race-condition(21080)</ref>
      <ref url="http://www.sudo.ws/sudo/alerts/path_race.html" source="CONFIRM">http://www.sudo.ws/sudo/alerts/path_race.html</ref>
      <ref url="http://www.securityfocus.com/bid/15647" source="BID">15647</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425974/100/0/threaded" source="FEDORA">FLSA:162750</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-535.html" source="REDHAT">RHSA-2005:535</ref>
      <ref url="http://www.osvdb.org/17396" source="OSVDB">17396</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.debian.org/security/2005/dsa-735" source="DEBIAN">DSA-735</ref>
      <ref url="http://secunia.com/advisories/17813" source="SECUNIA">17813</ref>
      <ref url="http://secunia.com/advisories/15744" source="SECUNIA">15744</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=302847" source="APPLE">APPLE-SA-2005-11-29</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1242" source="OVAL" sig="1">oval:org.mitre.oval:def:1242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.3.1" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.3_p1" />
        <vers num="1.6.3_p2" />
        <vers num="1.6.3_p3" />
        <vers num="1.6.3_p4" />
        <vers num="1.6.3_p5" />
        <vers num="1.6.3_p6" />
        <vers num="1.6.3_p7" />
        <vers num="1.6.4" />
        <vers num="1.6.4_p1" />
        <vers num="1.6.4_p2" />
        <vers num="1.6.5" />
        <vers num="1.6.5_p1" />
        <vers num="1.6.5_p2" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.7_p5" />
        <vers num="1.6.8" />
        <vers num="1.6.8_p1" />
        <vers num="1.6.8_p7" />
        <vers num="1.6.8_p8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1994" published="2005-06-14" name="CVE-2005-1994" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Finjan SurfinGate 7.0SP2 and SP3 allows remote attackers to download blocked files via hex-encoded characters in a filename, as demonstrated using "%2e".</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21010" source="XF">finjan-surfingate-security-bypass(21010)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0778" source="VUPEN">ADV-2005-0778</ref>
      <ref url="http://www.osvdb.org/17324" source="OSVDB">17324</ref>
      <ref url="http://secunia.com/advisories/15711" source="SECUNIA" adv="1">15711</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111877410528692&amp;w=2" source="BUGTRAQ">20050614 URL-Encoding Problem in Finjan SurfinGate</ref>
    </refs>
    <vuln_soft>
      <prod vendor="finjan_software" name="surfingate">
        <vers num="7.0_sp2" />
        <vers num="7.0_sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1995" published="2005-06-15" name="CVE-2005-1995" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17376" source="OSVDB" patch="1">17376</ref>
      <ref url="http://www.osvdb.org/17348" source="OSVDB" patch="1">17348</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21019" source="XF">bitrix-site-path-disclosure(21019)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885652331100&amp;w=2" source="BUGTRAQ">20050615 Vulnerability: Bitrix Web Server Paths</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitrix" name="bitrix_site_manager">
        <vers num="4.0.0" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1996" published="2005-06-15" name="CVE-2005-1996" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17341" source="OSVDB" patch="1">17341</ref>
      <ref url="http://www.bitrixsoft.com/support/forum/read.php?FID=10&amp;TID=1872" source="CONFIRM" patch="1">http://www.bitrixsoft.com/support/forum/read.php?FID=10&amp;TID=1872</ref>
      <ref url="http://www.bitrixsoft.com/sitemanager/versions.php?module=main" source="CONFIRM" patch="1">http://www.bitrixsoft.com/sitemanager/versions.php?module=main</ref>
      <ref url="http://secunia.com/advisories/15726" source="SECUNIA" patch="1" adv="1">15726</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21018" source="XF">bitrix-serverdocumentroot-file-include(21018)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0779" source="VUPEN" adv="1">ADV-2005-0779</ref>
      <ref url="http://www.securityfocus.com/bid/13965" source="BID">13965</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885605913761&amp;w=2" source="BUGTRAQ">20050615 Vulnerability: Bitrix Php inclusion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitrix" name="bitrix_site_manager">
        <vers num="4.0.0" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1997" published="2005-06-15" name="CVE-2005-1997" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17344" source="OSVDB">17344</ref>
      <ref url="http://secunia.com/advisories/15727" source="SECUNIA" adv="1">15727</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885559100231&amp;w=2" source="BUGTRAQ">20050615 Vulnerability: McGallery v 1.1 Mysql DB including</ref>
      <ref url="http://securitytracker.com/id?1014215" source="SECTRACK">1014215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcgallery" name="mcgallery">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1998" published="2005-06-15" name="CVE-2005-1998" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17343" source="OSVDB">17343</ref>
      <ref url="http://secunia.com/advisories/15727" source="SECUNIA" adv="1">15727</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885505600482&amp;w=2" source="BUGTRAQ">20050615 Vulnerability: McGallery v 1.1  files reading on disk</ref>
      <ref url="http://www.securityfocus.com/bid/13963" source="BID">13963</ref>
      <ref url="http://securitytracker.com/id?1014215" source="SECTRACK">1014215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcgallery" name="mcgallery">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-1999" published="2005-06-15" name="CVE-2005-1999" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phparena.net/pafiledb_patch/" source="CONFIRM" patch="1">http://www.phparena.net/pafiledb_patch/</ref>
      <ref url="http://www.phparena.net/" source="CONFIRM" patch="1">http://www.phparena.net/</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00082-06142005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00082-06142005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885787217807&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050615 Multiple paFileDB Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2000" published="2005-06-15" name="CVE-2005-2000" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phparena.net/pafiledb_patch/" source="CONFIRM" patch="1">http://www.phparena.net/pafiledb_patch/</ref>
      <ref url="http://www.phparena.net/" source="CONFIRM" patch="1">http://www.phparena.net/</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00082-06142005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00082-06142005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885787217807&amp;w=2" source="BUGTRAQ" patch="1">20050615 Multiple paFileDB Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="1.1.3" />
        <vers num="2.1.1" />
        <vers num="3.0" />
        <vers num="3.0_beta_3.1" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2001" published="2005-06-15" name="CVE-2005-2001" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phparena.net/pafiledb_patch/" source="CONFIRM" patch="1">http://www.phparena.net/pafiledb_patch/</ref>
      <ref url="http://www.phparena.net/" source="CONFIRM" patch="1">http://www.phparena.net/</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00082-06142005" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00082-06142005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885787217807&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050615 Multiple paFileDB Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="1.1.3" />
        <vers num="2.1.1" />
        <vers num="3.0" />
        <vers num="3.0_beta_3.1" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2002" published="2005-06-15" name="CVE-2005-2002" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15710" source="SECUNIA" patch="1" adv="1">15710</ref>
      <ref url="http://www.securityfocus.com/bid/13966" source="BID">13966</ref>
      <ref url="http://www.osvdb.org/17323" source="OSVDB">17323</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885974124936&amp;w=2" source="BUGTRAQ">20050615 Mambo 4.5.2.2 SQL Injection in UPDATE statement</ref>
      <ref url="http://mamboforge.net/frs/download.php/6153/CHANGELOG" source="CONFIRM" adv="1">http://mamboforge.net/frs/download.php/6153/CHANGELOG</ref>
      <ref url="http://securitytracker.com/id?1014222" source="SECTRACK">1014222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo">
        <vers num="4.5.0.2" />
        <vers num="4.5.1.3" />
        <vers num="4.5.1a" edition="a" />
        <vers num="4.5.2" />
        <vers num="4.5.2.2" />
        <vers num="4.5_1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2003" published="2005-06-16" name="CVE-2005-2003" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15732" source="SECUNIA" patch="1" adv="1">15732</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893777504821&amp;w=2" source="BUGTRAQ" adv="1">20050616 M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_php_board" name="ultimate_php_board">
        <vers num="1.9.6_gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2004" published="2005-06-17" name="CVE-2005-2004" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ref parameter to login.php, (2) id or (3) page parameter to viewtopic.php, id parameter to (4) profile.php, (5) newpost.php, (6) email.php, (7) icq.php, or (8) aol.php, (9) t_id parameter to newpost.php, (10) ref parameter to getpass.php, or (11) sText parameter to search.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15732" source="SECUNIA" patch="1" adv="1">15732</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893777504821&amp;w=2" source="BUGTRAQ" adv="1">20050616 M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_php_board" name="ultimate_php_board">
        <vers num="1.8" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2005" published="2005-06-16" name="CVE-2005-2005" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15732" source="SECUNIA" patch="1" adv="1">15732</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893777504821&amp;w=2" source="BUGTRAQ" adv="1">20050616 M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_php_board" name="ultimate_php_board">
        <vers num="1.8" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2006" published="2005-06-17" name="CVE-2005-2006" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00597967" source="HP">SSRT061108</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0497" source="VUPEN">ADV-2006-0497</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0815" source="VUPEN">ADV-2005-0815</ref>
      <ref url="http://secunia.com/advisories/15746" source="SECUNIA" adv="1">15746</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111911095424496&amp;w=2" source="BUGTRAQ" adv="1">20050617 JBOSS 3.2.2-3.2.7 / 4.0.2 installation path disclosure / config disclosure / version fingerprinting</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00597967" source="HP">SSRT061108</ref>
      <ref url="http://www.securityfocus.com/bid/13985" source="BID">13985</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440641/100/100/threaded" source="BUGTRAQ">20060720 Cisco MARS &lt; 4.2.1 remote compromise</ref>
      <ref url="http://securitytracker.com/id?1015605" source="SECTRACK">1015605</ref>
      <ref url="http://securityreason.com/securityalert/439" source="SREASON">439</ref>
      <ref url="http://secunia.com/advisories/18789" source="SECUNIA">18789</ref>
      <ref url="http://secunia.com/advisories/17559" source="SECUNIA">17559</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0424.html" source="FULLDISC">20060720 Cisco MARS &lt; 4.2.1 remote compromise</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jboss" name="jboss">
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2007" published="2005-06-19" name="CVE-2005-2007" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory-012005.php" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory-012005.php</ref>
      <ref url="http://secunia.com/advisories/15752" source="SECUNIA" patch="1" adv="1">15752</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034618.html" source="FULLDISC" patch="1" adv="1">20050619 Advisory 01/2005: Fileupload/download vulnerability in Trac</ref>
      <ref url="http://svn.edgewall.com/repos/trac/tags/trac-0.8.4/ChangeLog" source="CONFIRM">http://svn.edgewall.com/repos/trac/tags/trac-0.8.4/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edgewall_software" name="trac">
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2008" published="2005-06-17" name="CVE-2005-2008" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://yaws.hyber.org/yaws-1.55_to_1.56.patch" source="CONFIRM" patch="1" adv="1">http://yaws.hyber.org/yaws-1.55_to_1.56.patch</ref>
      <ref url="http://secunia.com/advisories/15740" source="SECUNIA" patch="1" adv="1">15740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111927717726371&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050617 Source Code Disclosure in Yaws Webserver &lt;1.56</ref>
      <ref url="http://www.osvdb.org/17375" source="OSVDB" adv="1">17375</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yaws" name="webserver">
        <vers num="1.50" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2009" published="2005-06-20" name="CVE-2005-2009" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0818" source="VUPEN">ADV-2005-0818</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928552304897&amp;w=2" source="BUGTRAQ" adv="1">20050620 [ECHO_ADV_18$2005] Multiple SQL INJECTION in Ublog Reload 1.0.5</ref>
      <ref url="http://echo.or.id/adv/adv18-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv18-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ublog" name="reload">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2010" published="2005-06-20" name="CVE-2005-2010" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0818" source="VUPEN">ADV-2005-0818</ref>
      <ref url="http://www.securityfocus.com/bid/13994" source="BID">13994</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928552304897&amp;w=2" source="BUGTRAQ" adv="1">20050620 [ECHO_ADV_18$2005] Multiple SQL INJECTION in Ublog Reload 1.0.5</ref>
      <ref url="http://echo.or.id/adv/adv18-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv18-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uapplication" name="ublog_reload">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2011" published="2005-06-20" name="CVE-2005-2011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00083-06202005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00083-06202005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928841328681&amp;w=2" source="BUGTRAQ" adv="1">20050620 paFaq Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafaq">
        <vers num="1.0_beta_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2012" published="2005-06-20" name="CVE-2005-2012" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00083-06202005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00083-06202005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928841328681&amp;w=2" source="BUGTRAQ" adv="1">20050620 paFaq Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafaq">
        <vers num="1.0_beta_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2013" published="2005-06-20" name="CVE-2005-2013" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00083-06202005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00083-06202005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928841328681&amp;w=2" source="BUGTRAQ" adv="1">20050620 paFaq Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafaq">
        <vers num="1.0_beta_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2014" published="2005-06-20" name="CVE-2005-2014" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928841328681&amp;w=2" source="BUGTRAQ" adv="1">20050620 paFaq Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafaq">
        <vers num="1.0_beta_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2017" published="2005-08-30" name="CVE-2005-2017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/security/Content/2005.08.24.html" source="CONFIRM" adv="1">http://www.symantec.com/avcenter/security/Content/2005.08.24.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=298&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050829 Symantec AntiVirus 9 Corporate Edition Local Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="9.0.1.1000" edition="" />
        <vers num="9.0.1.1000" edition=":corporate" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2019" published="2005-07-05" name="CVE-2005-2019" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while performing table lookups, which can cause the cache results to be corrupted during multiple concurrent lookups, allowing remote attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:13.ipfw.asc" source="FREEBSD" adv="1">FreeBSD-SA-05:13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2020" published="2005-09-08" name="CVE-2005-2020" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the web server for 3Com Network Supervisor 5.0.2 allows remote attackers to read arbitrary files via ".." sequences in the URL to TCP port 21700.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=300&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" patch="1" adv="1">20050902 3Com Network Supervisor Directory Traversal Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014836" source="SECTRACK" patch="1" adv="1">1014836</ref>
      <ref url="http://secunia.com/advisories/16639" source="SECUNIA" patch="1" adv="1">16639</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1611" source="VUPEN">ADV-2005-1611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3c15100d">
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2021" published="2005-06-20" name="CVE-2005-2021" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13996" source="BID" adv="1">13996</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.2_stable_48" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2022" published="2005-06-17" name="CVE-2005-2022" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101770-1" source="SUNALERT" patch="1" adv="1">101770</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0816" source="VUPEN">ADV-2005-0816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="iplanet_messaging_server">
        <vers num="5.2" />
      </prod>
      <prod vendor="sun" name="one_messaging_server">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2023" published="2005-06-17" name="CVE-2005-2023" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_sr.html" source="SUSE" patch="1" adv="1">SUSE-SR:2005:016</ref>
      <ref url="http://lists.gnupg.org/pipermail/gpa-dev/2005-June/002291.html" source="MLIST">[gpa-dev] 20050603 Re: S/MIME signing fails on a SUSE 9.3 system</ref>
      <ref url="http://lists.gnupg.org/pipermail/gpa-dev/2005-June/002294.html" source="MLIST">[gpa-dev] 20050603 Re: S/MIME signing fails on a SUSE 9.3 system</ref>
      <ref url="http://lists.gnupg.org/pipermail/gpa-dev/2005-June/002291.html" source="MLIST">[gpa-dev] 20050603 Re: S/MIME signing fails on a SUSE 9.3 system</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2024" published="2005-06-17" name="CVE-2005-2024" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain "unusual HTML messages" or (2) "certain malformed headers" such as Content-Type.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13984" source="BID" patch="1" adv="1">13984</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=7520323&amp;forum_id=4259" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/mailarchive/forum.php?thread_id=7520323&amp;forum_id=4259</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200506-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-17</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=95492" source="MISC" patch="1" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=95492</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_35_razor_agents.html" source="SUSE">SUSE-SA:2005:035</ref>
      <ref url="http://www.debian.org/security/2005/dsa-738" source="DEBIAN">DSA-738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vipul" name="razor-agents">
        <vers num="2.70" />
        <vers num="2.71" />
        <vers num="2.72" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2025" published="2005-06-20" name="CVE-2005-2025" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13992" source="BID" patch="1" adv="1">13992</ref>
      <ref url="http://www.nta-monitor.com/news/vpn-flaws/cisco/VPN-Concentrator/index.htm" source="MISC" patch="1" adv="1">http://www.nta-monitor.com/news/vpn-flaws/cisco/VPN-Concentrator/index.htm</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0822" source="VUPEN">ADV-2005-0822</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3020_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="2.0" />
        <vers num="2.5.2.a" />
        <vers num="2.5.2.b" />
        <vers num="2.5.2.c" />
        <vers num="2.5.2.d" />
        <vers num="2.5.2.f" />
        <vers num="3.0" />
        <vers num="3.0.3.a" />
        <vers num="3.0.3.b" />
        <vers num="3.0.4" />
        <vers num="3.1(rel)" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.4" />
        <vers num="3.5(rel)" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.6.1" />
        <vers num="3.6.7" />
        <vers num="3.6.7d" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.5.b" />
        <vers num="4.1" />
        <vers num="4.1.5.b" />
        <vers num="4.1.7.a" />
        <vers num="4.1.7.b" />
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="3.6.3" />
        <vers num="3.6.5" />
        <vers num="3.6.7" />
        <vers num="3.6.7.a" />
        <vers num="3.6.7.b" />
        <vers num="3.6.7.c" />
        <vers num="3.6.7.d" />
        <vers num="3.6.7.f" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2026" published="2005-06-16" name="CVE-2005-2026" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.enterasys.com/support/relnotes/VH-4802-2050509-patch-rel.pdf" source="CONFIRM" patch="1" adv="1">http://www.enterasys.com/support/relnotes/VH-4802-2050509-patch-rel.pdf</ref>
      <ref url="http://secunia.com/advisories/15757" source="SECUNIA" patch="1" adv="1">15757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enterasys" name="vertical_horizon-2402s">
        <vers num="2.05.00" />
        <vers num="2.05.08.01" />
        <vers num="2.05.09.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2027" published="2005-06-16" name="CVE-2005-2027" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.enterasys.com/support/relnotes/VH-4802-2050509-patch-rel.pdf" source="CONFIRM" patch="1" adv="1">http://www.enterasys.com/support/relnotes/VH-4802-2050509-patch-rel.pdf</ref>
      <ref url="http://secunia.com/advisories/15757" source="SECUNIA" patch="1" adv="1">15757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enterasys" name="vertical_horizon-2402s">
        <vers num="2.05.00" />
        <vers num="2.05.08.01" />
        <vers num="2.05.09.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2028" published="2005-06-21" name="CVE-2005-2028" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14015" source="BID" adv="1">14015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111938068428037&amp;w=2" source="BUGTRAQ" adv="1">20050621 MercuryBoard  1.1.4 SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard_message_board">
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2029" published="2005-06-17" name="CVE-2005-2029" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=335719" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=335719</ref>
      <ref url="http://secunia.com/advisories/15736" source="SECUNIA" patch="1" adv="1">15736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amarok" name="web_frontend">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2030" published="2005-06-16" name="CVE-2005-2030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13975" source="BID">13975</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893777504821&amp;w=2" source="BUGTRAQ" adv="1">20050616 M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_php_board" name="ultimate_php_board">
        <vers num="1.8" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2031" published="2005-06-16" name="CVE-2005-2031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid parameter to viewforum.php, (4) username parameter to newtopic.php, the (5) secid or (6) artid parameter to sections.php, (7) siteid parameter to index.php, or (8) sid parameter to friend.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014214" source="SECTRACK">1014214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="socialmpn" name="socialmpn">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2032" published="2005-06-16" name="CVE-2005-2032" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101768-1" source="SUNALERT" patch="1" adv="1">101768</ref>
      <ref url="http://secunia.com/advisories/15723" source="SECUNIA" patch="1" adv="1">15723</ref>
      <ref url="http://www.securityfocus.com/bid/13968" source="BID">13968</ref>
      <ref url="http://securitytracker.com/id?1014218" source="SECTRACK">1014218</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2033" published="2005-06-20" name="CVE-2005-2033" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0825" source="VUPEN">ADV-2005-0825</ref>
      <ref url="http://www.securityfocus.com/bid/14000" source="BID">14000</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111936111630489&amp;w=2" source="BUGTRAQ" adv="1">20050620 [Hat-Squad] i-Gallery directory traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blue-collar_productions" name="i-gallery">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2034" published="2005-06-20" name="CVE-2005-2034" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0825" source="VUPEN">ADV-2005-0825</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111936111630489&amp;w=2" source="BUGTRAQ" adv="1">20050620 [Hat-Squad] i-Gallery directory traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blue-collar_productions" name="i-gallery">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2035" published="2005-06-16" name="CVE-2005-2035" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17349" source="OSVDB">17349</ref>
      <ref url="http://securitytracker.com/id?1014221" source="SECTRACK">1014221</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Jun/0205.html" source="FULLDISC" adv="1">20050616 CoolCafe Chat SQL injection</ref>
      <ref url="http://exploitlabs.com/files/advisories/EXPL-A-2005-009-coolcafe.txt" source="MISC" adv="1">http://exploitlabs.com/files/advisories/EXPL-A-2005-009-coolcafe.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cool_cafe_chat" name="cool_cafe_chat">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2036" published="2005-06-16" name="CVE-2005-2036" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nickname value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17350" source="OSVDB">17350</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Jun/0205.html" source="FULLDISC">20050616 CoolCafe Chat SQL injection</ref>
      <ref url="http://exploitlabs.com/files/advisories/EXPL-A-2005-009-coolcafe.txt" source="MISC">http://exploitlabs.com/files/advisories/EXPL-A-2005-009-coolcafe.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cool_cafe_chat" name="cool_cafe_chat">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2037" published="2005-06-21" name="CVE-2005-2037" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Fortibus CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via (1) the username or password to logon.asp, (2) WeeklyNotesDisplay.asp, or (3) the Search page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0827" source="VUPEN">ADV-2005-0827</ref>
      <ref url="http://securitytracker.com/id?1014242" source="SECTRACK">1014242</ref>
      <ref url="http://secunia.com/advisories/15762" source="SECUNIA" adv="1">15762</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2038" published="2005-06-20" name="CVE-2005-2038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the "My info" page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014242" source="SECTRACK">1014242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fortibus" name="fortibus_cms">
        <vers num="4.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2039" published="2005-06-19" name="CVE-2005-2039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17392" source="OSVDB" patch="1">17392</ref>
      <ref url="http://secunia.com/advisories/15754" source="SECUNIA" patch="1" adv="1">15754</ref>
      <ref url="http://nanoblogger.sourceforge.net/downloads/nanoblogger-3.2.3.tar.gz" source="CONFIRM" patch="1">http://nanoblogger.sourceforge.net/downloads/nanoblogger-3.2.3.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nanoblogger" name="nanoblogger">
        <vers num="3.1" />
        <vers prev="1" num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2040" published="2005-06-20" name="CVE-2005-2040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15718" source="SECUNIA" patch="1" adv="1">15718</ref>
      <ref url="http://www.pdc.kth.se/heimdal/advisory/2005-06-20/" source="CONFIRM" adv="1">http://www.pdc.kth.se/heimdal/advisory/2005-06-20/</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_40_heimdal.html" source="SUSE">SUSE-SA:2005:040</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-24.xml" source="GENTOO">GLSA-200506-24</ref>
      <ref url="http://www.debian.org/security/2005/dsa-758" source="DEBIAN">DSA-758</ref>
    </refs>
    <vuln_soft>
      <prod vendor="telnetd" name="telnetd">
        <vers num="0.3f" />
        <vers num="0.4a" />
        <vers num="0.4b" />
        <vers num="0.4c" />
        <vers num="0.4d" />
        <vers num="0.4e" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2041" published="2005-06-15" name="CVE-2005-2041" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/exploits/5TP0C1FG1I.html" source="MISC">http://www.securiteam.com/exploits/5TP0C1FG1I.html</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0614a%5D.txt" source="MISC" adv="1">http://www.digitalmunition.com/DMA%5B2005-0614a%5D.txt</ref>
      <ref url="http://secunia.com/advisories/15700" source="SECUNIA">15700</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21000" source="XF">virobot-addschup-bo(21000)</ref>
      <ref url="http://www.securityfocus.com/bid/12964" source="BID">12964</ref>
      <ref url="http://www.osvdb.org/17320" source="OSVDB">17320</ref>
      <ref url="http://www.globalhauri.com/html/download/down_unixpatch.html" source="CONFIRM">http://www.globalhauri.com/html/download/down_unixpatch.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111880273631392&amp;w=2" source="FULLDISC">20050615 DMA[2005-0614a] - 'Global Hauri ViRobot Server cookie overflow'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hauri" name="virobot_linux_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2042" published="2005-06-16" name="CVE-2005-2042" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13986" source="BID" patch="1">13986</ref>
      <ref url="http://www.broken-notebook.com/spell_checker/index.php" source="CONFIRM" patch="1" adv="1">http://www.broken-notebook.com/spell_checker/index.php</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=335556" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=335556</ref>
      <ref url="http://secunia.com/advisories/15737" source="SECUNIA" patch="1" adv="1">15737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ajax-spell" name="ajax-spell">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2043" published="2005-06-17" name="CVE-2005-2043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13983" source="BID" patch="1">13983</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=335710" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=335710</ref>
      <ref url="http://secunia.com/advisories/15735" source="SECUNIA" patch="1" adv="1">15735</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xampp" name="apache_distribution">
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.10a" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2044" published="2005-06-16" name="CVE-2005-2044" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13972" source="BID" patch="1">13972</ref>
      <ref url="http://lostmon.blogspot.com/2005/06/atutor-multiple-variable-cross-site.html" source="MISC" patch="1" adv="1">http://lostmon.blogspot.com/2005/06/atutor-multiple-variable-cross-site.html</ref>
      <ref url="http://www.osvdb.org/17359" source="OSVDB">17359</ref>
      <ref url="http://www.osvdb.org/17358" source="OSVDB">17358</ref>
      <ref url="http://www.osvdb.org/17357" source="OSVDB">17357</ref>
      <ref url="http://www.osvdb.org/17356" source="OSVDB">17356</ref>
      <ref url="http://www.osvdb.org/17355" source="OSVDB">17355</ref>
      <ref url="http://www.osvdb.org/17354" source="OSVDB">17354</ref>
      <ref url="http://www.osvdb.org/17353" source="OSVDB">17353</ref>
      <ref url="http://www.osvdb.org/17352" source="OSVDB">17352</ref>
      <ref url="http://www.osvdb.org/17351" source="OSVDB">17351</ref>
      <ref url="http://securitytracker.com/id?1014216" source="SECTRACK">1014216</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adaptive_technology_resource_centre" name="atutor">
        <vers num="1.4.3" />
        <vers num="1.5_rc_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2045" published="2005-06-22" name="CVE-2005-2045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to default.asp, (2) iData parameter to detail.asp, (3) iMem parameter to members.asp, (4) iCat parameter to cat.asp, (5) offset parameter to members_listing_approval.asp, or (6) iChannel parameter to channels_edit.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2" source="BUGTRAQ" adv="1">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref>
      <ref url="http://echo.or.id/adv/adv19-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv19-theday-2005.txt</ref>
      <ref url="http://www.osvdb.org/17599" source="OSVDB">17599</ref>
      <ref url="http://www.osvdb.org/17598" source="OSVDB">17598</ref>
      <ref url="http://www.osvdb.org/17597" source="OSVDB">17597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duware" name="duportal_pro">
        <vers num="3.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2046" published="2005-06-22" name="CVE-2005-2046" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2" source="BUGTRAQ" adv="1">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref>
      <ref url="http://echo.or.id/adv/adv19-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv19-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duware" name="duamazon_pro">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2047" published="2005-06-22" name="CVE-2005-2047" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iPro parameter to detail.asp, (3) iSub parameter to sub.asp, (4) iCat parameter to catEdit.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2" source="BUGTRAQ" adv="1">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref>
      <ref url="http://echo.or.id/adv/adv19-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv19-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duware" name="dupaypal_pro">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2048" published="2005-06-22" name="CVE-2005-2048" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp.  NOTE: vectors 1 and 3 were later reported to affect version 3.0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/30668" source="XF">duforum-messages-forums-sql-injection(30668)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/453330/100/0/threaded" source="BUGTRAQ">20061202 [Aria-Security Team] DuWare DuForum SQL Injection Vuln</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2" source="BUGTRAQ" adv="1">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref>
      <ref url="http://echo.or.id/adv/adv19-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv19-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duware" name="duforum">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2049" published="2005-06-22" name="CVE-2005-2049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2" source="BUGTRAQ" adv="1">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref>
      <ref url="http://echo.or.id/adv/adv19-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv19-theday-2005.txt</ref>
      <ref url="http://www.securityfocus.com/bid/14036" source="BID">14036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duware" name="duclassmate">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2050" published="2005-06-28" name="CVE-2005-2050" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server's process space.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21093" source="XF" patch="1">tor-information-disclosure(21093)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-18</ref>
      <ref url="http://secunia.com/advisories/15764/" source="SECUNIA" patch="1" adv="1">15764</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=96320" source="MISC" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=96320</ref>
      <ref url="http://archives.seul.org/or/announce/Jun-2005/msg00001.html" source="MISC" patch="1">http://archives.seul.org/or/announce/Jun-2005/msg00001.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.9" />
        <vers num="0.0.9.1" />
        <vers num="0.0.9.2" />
        <vers num="0.0.9.3" />
        <vers num="0.0.9.4" />
        <vers num="0.0.9.5" />
        <vers num="0.0.9.6" />
        <vers num="0.0.9.7" />
        <vers num="0.0.9.8" />
        <vers num="0.0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2051" published="2005-06-28" name="CVE-2005-2051" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://seer.support.veritas.com/docs/276606.htm" source="CONFIRM" patch="1" adv="1">http://seer.support.veritas.com/docs/276606.htm</ref>
      <ref url="http://secunia.com/advisories/15789" source="SECUNIA">15789</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111954711532252&amp;w=2" source="BUGTRAQ">20050623 Buffer overflow vulnerability in VERITAS Software Backup Exec Web Administration Console (BEWAC)</ref>
      <ref url="http://www.securityfocus.com/bid/14025" source="BID">14025</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-232.shtml" source="CIAC">P-232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="10.0" />
        <vers num="10.0_rev.5484" />
        <vers num="9.0" />
        <vers num="9.0_rev.4367" />
        <vers num="9.0_rev.4454" />
        <vers num="9.1" />
        <vers num="9.1_rev.4691" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2052" published="2005-06-28" name="CVE-2005-2052" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in vidplin.dll in RealPlayer 10 and 10.5 (6.0.12.1040 through 1069), RealOne Player v1 and v2, RealPlayer 8 and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an .avi file with a modified strf structure value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://service.real.com/help/faq/security/050623_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/050623_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111955853611840&amp;w=2" source="BUGTRAQ" patch="1">20050623 eEye Advisory - EEYEB-200505 - RealPlayer AVI Processing Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="" edition=":enterprise" />
        <vers num="10.0" />
        <vers num="10.5_6.0.12.1040" />
        <vers num="10.5_6.0.12.1069" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2053" published="2005-06-28" name="CVE-2005-2053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the path in an error message.  NOTE: a followup suggests that this may be a directory traversal or file inclusion vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111990004028512&amp;w=2" source="BUGTRAQ">20050626 Re: [ECHO_ADV_20$2005] Full path disclosure JAF CMS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111954840611126&amp;w=2" source="BUGTRAQ">20050623 [ECHO_ADV_20$2005] Full path disclosure JAF CMS</ref>
      <ref url="http://echo.or.id/adv/adv20-theday-2005.txt" source="MISC" adv="1">http://echo.or.id/adv/adv20-theday-2005.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="salims_softhouse" name="jaf_cms">
        <vers num="1.0" edition="final" />
        <vers num="1.5" />
        <vers num="2.0" edition="beta" />
        <vers num="2.0" edition="final" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.5" />
        <vers num="3.0" edition="rc" />
        <vers num="3.0" edition="rc2" />
        <vers num="3.0" edition="rc_fixed" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2054" published="2005-06-29" name="CVE-2005-2054" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unknown vulnerability in RealPlayer 10 and 10.5 (6.0.12.1040-1069) and RealOne Player v1 and v2 allows remote attackers to overwrite arbitrary files or execute arbitrary ActiveX controls via a crafted MP3 file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://service.real.com/help/faq/security/050623_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/050623_player/EN/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" />
        <vers num="10.5_6.0.12.1040_1069" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2055" published="2005-06-29" name="CVE-2005-2055" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settings of earlier Internet Explorer browsers".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://service.real.com/help/faq/security/050623_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/050623_player/EN/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="" edition=":enterprise" />
        <vers num="10.0" />
        <vers num="10.5_6.0.12.1040_1069" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2056" published="2005-06-29" name="CVE-2005-2056" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows remote attackers to cause a denial of service (application crash) via a crafted Quantum archive.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200506-23.xml" source="GENTOO" patch="1" adv="1">GLSA-200506-23</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=337279" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=337279</ref>
      <ref url="http://www.securityfocus.com/bid/14058" source="BID">14058</ref>
      <ref url="http://secunia.com/advisories/15811" source="SECUNIA">15811</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_38_clamav.html" source="SUSE">SUSE-SA:2005:038</ref>
      <ref url="http://www.debian.org/security/2005/dsa-737" source="DEBIAN">DSA-737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2057" published="2005-06-29" name="CVE-2005-2057" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to showprofile.php, (8) fpart or (9) page parameter to showflat.php, or (10) like parameter to showmembers.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351" source="MISC" patch="1">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.3" />
        <vers num="6.3.1" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.3" />
        <vers num="6.4.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2058" published="2005-06-29" name="CVE-2005-2058" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351" source="MISC" patch="1">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.3" />
        <vers num="6.3.1" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.3" />
        <vers num="6.4.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2059" published="2005-06-29" name="CVE-2005-2059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351" source="MISC" patch="1">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.3" />
        <vers num="6.3.1" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.3" />
        <vers num="6.4.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2060" published="2005-06-29" name="CVE-2005-2060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351" source="MISC" patch="1">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.3" />
        <vers num="6.3.1" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.3" />
        <vers num="6.4.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2061" published="2005-06-29" name="CVE-2005-2061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351" source="MISC" patch="1">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.3" />
        <vers num="6.3.1" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.3" />
        <vers num="6.4.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2062" published="2005-06-29" name="CVE-2005-2062" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1096" source="VUPEN">ADV-2007-1096</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963341429906&amp;w=2" source="BUGTRAQ" adv="1">20050624 [ECHO_ADV_21$2005] MUltiple Vulnarable In ActiveBuyAndSell</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33183" source="XF">activebuyandsell-buyersend-sql-injection(33183)</ref>
      <ref url="http://www.securityfocus.com/bid/23110" source="BID">23110</ref>
      <ref url="http://www.milw0rm.com/exploits/3550" source="MILW0RM">3550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_web_softwares" name="activebuyandsell">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2063" published="2005-06-29" name="CVE-2005-2063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963341429906&amp;w=2" source="BUGTRAQ" adv="1">20050624 [ECHO_ADV_21$2005] MUltiple Vulnarable In ActiveBuyAndSell</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_web_softwares" name="activebuyandsell">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2064" published="2005-06-29" name="CVE-2005-2064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14062" source="BID">14062</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111989223906484&amp;w=2" source="BUGTRAQ" adv="1">20050626 M4DR007-07SA (security advisory): Multiple vulnerabilities in ASP Nuke 0.80</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-nuke" name="asp-nuke">
        <vers num="0.80" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2065" published="2005-06-29" name="CVE-2005-2065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14063" source="BID">14063</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111989223906484&amp;w=2" source="BUGTRAQ" adv="1">20050626 M4DR007-07SA (security advisory): Multiple vulnerabilities in ASP Nuke 0.80</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-nuke" name="asp-nuke">
        <vers num="0.80" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2066" published="2005-06-29" name="CVE-2005-2066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14064" source="BID">14064</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111989223906484&amp;w=2" source="BUGTRAQ" adv="1">20050626 M4DR007-07SA (security advisory): Multiple vulnerabilities in ASP Nuke 0.80</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111999188612055&amp;w=2" source="BUGTRAQ">20050627 SQL Injection Exploit for ASPNuke &lt;= 0.80</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-nuke" name="asp-nuke">
        <vers num="0.80" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2067" published="2005-06-29" name="CVE-2005-2067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111989828622112&amp;w=2" source="BUGTRAQ">20050627 aspnuke is vulnerable to sql injection</ref>
      <ref url="http://www.securityfocus.com/bid/18215" source="BID">18215</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/ASPNuke-0601-sql.txt" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/ASPNuke-0601-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-nuke" name="asp-nuke">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2068" published="2005-07-05" name="CVE-2005-2068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an already established session.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc" source="FREEBSD">FreeBSD-SA-05:15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.10" />
        <vers num="4.11" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.6.2" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2069" published="2005-06-30" name="CVE-2005-2069" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openldap.org/its/index.cgi/Incoming?id=3791" source="MISC" patch="1" adv="1">http://www.openldap.org/its/index.cgi/Incoming?id=3791</ref>
      <ref url="http://bugzilla.padl.com/show_bug.cgi?id=210" source="MISC" patch="1" adv="1">http://bugzilla.padl.com/show_bug.cgi?id=210</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161990" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161990</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21245" source="XF">ldap-tls-information-disclosure(21245)</ref>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:121" source="MANDRIVA">MDKSA-2005:121</ref>
      <ref url="http://www.ubuntu.com/usn/usn-152-1" source="UBUNTU">USN-152-1</ref>
      <ref url="http://www.securityfocus.com/bid/14126" source="BID">14126</ref>
      <ref url="http://www.securityfocus.com/bid/14125" source="BID">14125</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-767.html" source="REDHAT">RHSA-2005:767</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-751.html" source="REDHAT">RHSA-2005:751</ref>
      <ref url="http://www.osvdb.org/17692" source="OSVDB">17692</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-13.xml" source="GENTOO">GLSA-2005-07-13</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm</ref>
      <ref url="http://secunia.com/advisories/21520" source="SECUNIA">21520</ref>
      <ref url="http://secunia.com/advisories/17845" source="SECUNIA">17845</ref>
      <ref url="http://secunia.com/advisories/17233" source="SECUNIA">17233</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9445" source="OVAL">oval:org.mitre.oval:def:9445</ref>
      <ref url="http://bugzilla.padl.com/show_bug.cgi?id=211" source="MISC">http://bugzilla.padl.com/show_bug.cgi?id=211</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=96767" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=96767</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0060.html" source="FULLDISC">20050704 pam_ldap/nss_ldap password leak in a master+slave+start_tls LDAP setup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openldap" name="openldap">
        <vers num="" />
      </prod>
      <prod vendor="padl_software" name="nss_ldap">
        <vers num="" />
      </prod>
      <prod vendor="padl_software" name="pam_ldap">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2070" published="2005-06-29" name="CVE-2005-2070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14047" source="BID">14047</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0197.html" source="BUGTRAQ" adv="1">20050623 long sendmail timeouts let attacker prevent milter quiesce</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_38_clamav.html" source="SUSE">SUSE-SA:2005:038</ref>
      <ref url="http://www.debian.org/security/2005/dsa-737" source="DEBIAN">DSA-737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="8.10" />
        <vers num="8.10.1" />
        <vers num="8.10.2" />
        <vers num="8.11.0" />
        <vers num="8.11.1" />
        <vers num="8.11.2" />
        <vers num="8.11.3" />
        <vers num="8.11.4" />
        <vers num="8.11.5" />
        <vers num="8.11.6" />
        <vers num="8.11.7" />
        <vers num="8.12" edition="beta10" />
        <vers num="8.12" edition="beta12" />
        <vers num="8.12" edition="beta16" />
        <vers num="8.12" edition="beta5" />
        <vers num="8.12" edition="beta7" />
        <vers num="8.12.0" />
        <vers num="8.12.1" />
        <vers num="8.12.10" />
        <vers num="8.12.11" />
        <vers num="8.12.2" />
        <vers num="8.12.3" />
        <vers num="8.12.4" />
        <vers num="8.12.5" />
        <vers num="8.12.6" />
        <vers num="8.12.7" />
        <vers num="8.12.8" />
        <vers num="8.12.9" />
        <vers num="8.8.8" />
        <vers num="8.9.0" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
        <vers num="8.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2071" published="2005-06-29" name="CVE-2005-2071" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/2564" source="VUPEN" adv="1">ADV-2005-2564</ref>
      <ref url="http://www.securityfocus.com/bid/14049" source="BID">14049</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102060-1" source="SUNALERT">102060</ref>
      <ref url="http://securitytracker.com/id?1015261" source="SECTRACK">1015261</ref>
      <ref url="http://secunia.com/advisories/17708" source="SECUNIA" adv="1">17708</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111964580023012&amp;w=2" source="BUGTRAQ">20050624 Re: Solaris 10 /usr/sbin/traceroute vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963809801731&amp;w=2" source="BUGTRAQ">20050624 Re: [Full-disclosure] Solaris 10 /usr/sbin/traceroute vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963068714114&amp;w=2" source="BUGTRAQ">20050624 Solaris 10 /usr/sbin/traceroute vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2072" published="2005-06-29" name="CVE-2005-2072" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0908" source="VUPEN" adv="1">ADV-2005-0908</ref>
      <ref url="http://www.securityfocus.com/bid/14074" source="BID">14074</ref>
      <ref url="http://www.opensolaris.org/jive/thread.jspa?messageID=3497" source="CONFIRM">http://www.opensolaris.org/jive/thread.jspa?messageID=3497</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101794-1" source="SUNALERT">101794</ref>
      <ref url="http://securitytracker.com/id?1014537" source="SECTRACK">1014537</ref>
      <ref url="http://secunia.com/advisories/15841" source="SECUNIA" adv="1">15841</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034738.html" source="FULLDISC">20050628 Solaris 9/10 ld.so fun</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034731.html" source="FULLDISC">20050628 Solaris 9/10 ld.so fun</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034730.html" source="FULLDISC">20050628 Solaris 9/10 ld.so fun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2073" published="2005-06-29" name="CVE-2005-2073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY73104&amp;apar=only" source="AIXAPAR" patch="1" adv="1">IY73104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.1.8a" />
        <vers num="8.1.9" />
        <vers num="8.2.0" />
        <vers num="8.2.1" />
        <vers num="8.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2074" published="2005-06-29" name="CVE-2005-2074" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.0.105 allows remote attackers to inject arbitrary web script or HTML via a news or article post, possibly involving the (1) news_body, (2) article_description, or (3) article_body parameters to submit.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15830" source="SECUNIA" patch="1" adv="1">15830</ref>
      <ref url="http://dark-assassins.com/forum/viewtopic.php?t=145" source="MISC" patch="1">http://dark-assassins.com/forum/viewtopic.php?t=145</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0888" source="VUPEN">ADV-2005-0888</ref>
      <ref url="http://www.securityfocus.com/bid/14066" source="BID">14066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="6.0.105" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2075" published="2005-06-29" name="CVE-2005-2075" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15830" source="SECUNIA" patch="1" adv="1">15830</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0888" source="VUPEN">ADV-2005-0888</ref>
      <ref url="http://dark-assassins.com/forum/viewtopic.php?t=142" source="MISC">http://dark-assassins.com/forum/viewtopic.php?t=142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2076" published="2005-06-29" name="CVE-2005-2076" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14032" source="BID" patch="1">14032</ref>
      <ref url="http://www.securityfocus.com/advisories/8734" source="HP" patch="1" adv="1">SSRT5955</ref>
      <ref url="http://securitytracker.com/id?1014267" source="SECTRACK" patch="1">1014267</ref>
      <ref url="http://secunia.com/advisories/15790" source="SECUNIA" patch="1" adv="1">15790</ref>
      <ref url="http://www.securityfocus.com/advisories/8734" source="HP">SSRT5955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="version_control_repository_manager">
        <vers num="1.0.1288.1" />
        <vers num="1.0.2241.0" />
        <vers num="1.0.2289.0" />
        <vers num="1.0.2345.0" />
        <vers num="1.0.3085.0" />
        <vers num="1.0.3086.0" />
        <vers num="2.0.0.50" />
        <vers num="2.0.1.30" />
        <vers num="2.1.1.710" />
        <vers num="2.1.1.720" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2077" published="2005-06-29" name="CVE-2005-2077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14080" source="BID">14080</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419597/100/0/threaded" source="BUGTRAQ">20051215 Bug in HC</ref>
      <ref url="http://securitytracker.com/id?1016456" source="SECTRACK">1016456</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111997456519685&amp;w=2" source="BUGTRAQ">20050628 Cross-Site Scripting (CSS)  in Hosting Controller All Version and hot fix it hehe ;)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="1.1" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4b" />
        <vers num="6.1" />
        <vers num="6.1_hotfix_1.4" />
        <vers num="6.1_hotfix_1.7" />
        <vers num="6.1_hotfix_1.9" />
        <vers num="6.1_hotfix_2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2078" published="2005-06-29" name="CVE-2005-2078" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14079" source="BID">14079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sofotex" name="bisonftp">
        <vers num="v4r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2079" published="2005-08-02" name="CVE-2005-2079" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-180A.html" source="CERT" patch="1" adv="1">TA05-180A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/352625" source="CERT-VN" patch="1" adv="1">VU#352625</ref>
      <ref url="http://seer.support.veritas.com/docs/277429.htm" source="CONFIRM" patch="1">http://seer.support.veritas.com/docs/277429.htm</ref>
      <ref url="http://seer.support.veritas.com/docs/276607.htm" source="CONFIRM" patch="1" adv="1">http://seer.support.veritas.com/docs/276607.htm</ref>
      <ref url="http://secunia.com/advisories/15789" source="SECUNIA" patch="1" adv="1">15789</ref>
      <ref url="http://www.securityfocus.com/bid/14023" source="BID">14023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="10.0_rev.5484" />
        <vers num="9.0_rev.4367" />
        <vers num="9.0_rev.4454" />
        <vers num="9.1_rev.4691" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2080" published="2005-06-29" name="CVE-2005-2080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://seer.support.veritas.com/docs/277429.htm" source="CONFIRM" patch="1">http://seer.support.veritas.com/docs/277429.htm</ref>
      <ref url="http://seer.support.veritas.com/docs/276608.htm" source="CONFIRM" patch="1" adv="1">http://seer.support.veritas.com/docs/276608.htm</ref>
      <ref url="http://secunia.com/advisories/15789" source="SECUNIA" patch="1" adv="1">15789</ref>
      <ref url="http://www.securityfocus.com/bid/14026" source="BID">14026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="10.0" />
        <vers num="9.0" />
        <vers num="9.0.4019" />
        <vers num="9.0.4170" />
        <vers num="9.0.4172" />
        <vers num="9.0.4174" />
        <vers num="9.0.4202" />
        <vers num="9.1" />
        <vers num="9.1.1067.2" />
        <vers num="9.1.1067.3" />
        <vers num="9.1.1127.1" />
        <vers num="9.1.1151.1" />
        <vers num="9.1.1152" />
        <vers num="9.1.1152.4" />
        <vers num="9.1.1154" />
        <vers num="9.1.306" />
        <vers num="9.1.307" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2081" published="2005-07-05" name="CVE-2005-2081" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21115" source="XF" patch="1">asterisk-manager-interface-bo(21115)</ref>
      <ref url="http://www.portcullis-security.com/advisory/advisory-05-013.txt" source="MISC" adv="1">http://www.portcullis-security.com/advisory/advisory-05-013.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111946399501080&amp;w=2" source="BUGTRAQ" adv="1">20050622 Portcullis Security Advisory 05-013 - VoIP - Asterisk Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digium" name="asterisk">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2082" published="2005-07-05" name="CVE-2005-2082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cgi-club.com/imTRBBS/" source="CONFIRM">http://www.cgi-club.com/imTRBBS/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006605026261&amp;w=2" source="BUGTRAQ" adv="1">20050629 Original imTRBBS(ver1.02) and prior remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi-club" name="imtrset">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2083" published="2005-07-05" name="CVE-2005-2083" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21169" source="XF" patch="1">emailserver-list-dos(21169)</ref>
      <ref url="http://securitytracker.com/alerts/2005/Jun/1014301.html" source="SECTRACK" patch="1">1014301</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111988945819448&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050627 Denial of Service Vulnerability in True North Software, Inc. IA eMailServer Corporate Edition Version: 5.2.2. Build: 1051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="truenorth_software" name="ia_emailserver">
        <vers num="corporate_5.2.2_build_1051" />
        <vers num="corporate_5.2.3_build_1056" />
        <vers num="corporate_5.3.1" />
        <vers num="corporate_5.3.2" />
        <vers num="corporate_5.3.3" />
        <vers num="corporate_5.3.4_build_2018" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2084" published="2005-07-05" name="CVE-2005-2084" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111998009409469&amp;w=2" source="BUGTRAQ" adv="1">20050627 XSS IN Community forum</ref>
    </refs>
    <vuln_soft>
      <prod vendor="telligent_systems" name="community_server_forums">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2085" published="2005-07-05" name="CVE-2005-2085" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111998161006731&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050628 Multiple buffer overflows exist in Infradig Systems Inframail Advantage Server Edition 6.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infradig_systems" name="inframail_advantage">
        <vers num="server_6.0" />
        <vers num="server_6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2086" published="2005-07-05" name="CVE-2005-2086" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=302011" source="CONFIRM" patch="1">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=302011</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111999905917019&amp;w=2" source="BUGTRAQ" adv="1">20050628 Security Advisory - phpBB 2.0.15 PHP-code injection bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2087" published="2005-07-05" name="CVE-2005-2087" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-193A.html" source="CERT">TA05-193A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/959049" source="CERT-VN">VU#959049</ref>
      <ref url="http://www.kb.cert.org/vuls/id/939605" source="CERT-VN">VU#939605</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21193" source="XF">ie-javaprxydll-execute-code(21193)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0935" source="VUPEN" adv="1">ADV-2005-0935</ref>
      <ref url="http://www.securityfocus.com/bid/14087" source="BID">14087</ref>
      <ref url="http://www.securityfocus.com/archive/1/404055" source="BUGTRAQ">20050702 Microsoft Internet Explorer </ref>
      <ref url="http://www.osvdb.org/17680" source="OSVDB">17680</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-037.mspx" source="MS">MS05-037</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/903144.mspx" source="MISC">http://www.microsoft.com/technet/security/advisory/903144.mspx</ref>
      <ref url="http://www.auscert.org.au/render.html?it=5225" source="AUSCERT">ESB-2005.0489</ref>
      <ref url="http://securitytracker.com/id?1014329" source="SECTRACK">1014329</ref>
      <ref url="http://secunia.com/advisories/15891" source="SECUNIA" adv="1">15891</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006764714946&amp;w=2" source="BUGTRAQ" adv="1">20050629 SEC-CONSULT SA-20050629-0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:793" source="OVAL" sig="1">oval:org.mitre.oval:def:793</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1518" source="OVAL" sig="1">oval:org.mitre.oval:def:1518</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1506" source="OVAL" sig="1">oval:org.mitre.oval:def:1506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1326" source="OVAL" sig="1">oval:org.mitre.oval:def:1326</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":mac_os" />
        <vers num="5.2.3" edition="" />
        <vers num="5.2.3" edition=":macintosh" />
        <vers num="5.5" edition="preview" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6" edition="windows_server_2003_sp1" />
        <vers num="6.0" />
        <vers num="6.0.2900.2180" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2088" published="2005-07-05" name="CVE-2005-2088" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828" source="HP">SSRT051128</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828" source="HP">SSRT051128</ref>
      <ref url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf" source="MISC">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4680" source="VUPEN">ADV-2006-4680</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1018" source="VUPEN">ADV-2006-1018</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0789" source="VUPEN">ADV-2006-0789</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2659" source="VUPEN">ADV-2005-2659</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2140" source="VUPEN">ADV-2005-2140</ref>
      <ref url="http://www.ubuntu.com/usn/usn-160-2" source="UBUNTU">USN-160-2</ref>
      <ref url="http://www.securityfocus.com/bid/15647" source="BID">15647</ref>
      <ref url="http://www.securityfocus.com/bid/14106" source="BID">14106</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded" source="HP">HPSBUX02074</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded" source="HP">HPSBUX02074</ref>
      <ref url="http://www.securiteam.com/securityreviews/5GP0220G0U.html" source="MISC">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-582.html" source="REDHAT">RHSA-2005:582</ref>
      <ref url="http://www.debian.org/security/2005/dsa-805" source="DEBIAN">DSA-805</ref>
      <ref url="http://www.debian.org/security/2005/dsa-803" source="DEBIAN">DSA-803</ref>
      <ref url="http://www.apache.org/dist/httpd/CHANGES_2.0" source="CONFIRM">http://www.apache.org/dist/httpd/CHANGES_2.0</ref>
      <ref url="http://www.apache.org/dist/httpd/CHANGES_1.3" source="CONFIRM">http://www.apache.org/dist/httpd/CHANGES_1.3</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK16139&amp;apar=only" source="AIXAPAR">PK16139</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK13959&amp;apar=only" source="AIXAPAR">PK13959</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1" source="SUNALERT">102198</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1" source="SUNALERT">102197</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2005&amp;m=slackware-security.600000" source="SLACKWARE">SSA:2005-310-04</ref>
      <ref url="http://securitytracker.com/id?1014323" source="SECTRACK">1014323</ref>
      <ref url="http://secunia.com/advisories/19317" source="SECUNIA">19317</ref>
      <ref url="http://secunia.com/advisories/19185" source="SECUNIA">19185</ref>
      <ref url="http://secunia.com/advisories/19073" source="SECUNIA">19073</ref>
      <ref url="http://secunia.com/advisories/19072" source="SECUNIA">19072</ref>
      <ref url="http://secunia.com/advisories/17813" source="SECUNIA">17813</ref>
      <ref url="http://secunia.com/advisories/17487" source="SECUNIA">17487</ref>
      <ref url="http://secunia.com/advisories/17319" source="SECUNIA">17319</ref>
      <ref url="http://secunia.com/advisories/14530" source="SECUNIA">14530</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html" source="BUGTRAQ">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11452" source="OVAL">oval:org.mitre.oval:def:11452</ref>
      <ref url="http://marc2.theaimsgroup.com/?l=apache-httpd-announce&amp;m=112931556417329&amp;w=3" source="MLIST">[apache-httpd-announce] 20051014 Apache HTTP Server 2.0.55 Released</ref>
      <ref url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html" source="TRUSTIX">TSLSA-2005-0059</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=302847" source="APPLE">APPLE-SA-2005-11-29</ref>
      <ref url="https://secure-support.novell.com/KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html" source="CONFIRM">https://secure-support.novell.com/KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_46_apache.html" source="SUSE">SUSE-SA:2005:046</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:130" source="MANDRIVA">MDKSA-2005:130</ref>
      <ref url="http://securityreason.com/securityalert/604" source="SREASON">604</ref>
      <ref url="http://secunia.com/advisories/23074" source="SECUNIA">23074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:840" source="OVAL" sig="1">oval:org.mitre.oval:def:840</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1629" source="OVAL" sig="1">oval:org.mitre.oval:def:1629</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1526" source="OVAL" sig="1">oval:org.mitre.oval:def:1526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1237" source="OVAL" sig="1">oval:org.mitre.oval:def:1237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.29" />
        <vers num="1.3.30" />
        <vers num="1.3.31" />
        <vers num="1.3.32" />
        <vers num="1.3.33" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.50" />
        <vers num="2.0.51" />
        <vers num="2.0.52" />
        <vers num="2.0.53" />
        <vers num="2.0.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2089" published="2005-07-05" name="CVE-2005-2089" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf" source="MISC">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref>
      <ref url="http://www.securiteam.com/securityreviews/5GP0220G0U.html" source="MISC">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html" source="BUGTRAQ">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42899" source="XF">microsoft-iis-hrs(42899)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2090" published="2005-07-05" name="CVE-2005-2090" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf" source="MISC">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0233" source="VUPEN">ADV-2009-0233</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1979/references" source="VUPEN">ADV-2008-1979</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0065" source="VUPEN">ADV-2008-0065</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3087" source="VUPEN">ADV-2007-3087</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded" source="BUGTRAQ">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded" source="BUGTRAQ">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</ref>
      <ref url="http://www.securiteam.com/securityreviews/5GP0220G0U.html" source="MISC">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</ref>
      <ref url="http://secunia.com/advisories/33668" source="SECUNIA">33668</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html" source="BUGTRAQ">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10499" source="OVAL">oval:org.mitre.oval:def:10499</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" source="CONFIRM">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/bid/13873" source="BID">13873</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485938/100/0/threaded" source="BUGTRAQ">20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0360.html" source="REDHAT">RHSA-2007:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0327.html" source="REDHAT">RHSA-2007:0327</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200703e.html" source="CONFIRM">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200703e.html</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1" source="SUNALERT">239312</ref>
      <ref url="http://securitytracker.com/id?1014365" source="SECTRACK">1014365</ref>
      <ref url="http://secunia.com/advisories/30908" source="SECUNIA">30908</ref>
      <ref url="http://secunia.com/advisories/30899" source="SECUNIA">30899</ref>
      <ref url="http://secunia.com/advisories/29242" source="SECUNIA">29242</ref>
      <ref url="http://secunia.com/advisories/28365" source="SECUNIA">28365</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA">27037</ref>
      <ref url="http://secunia.com/advisories/26660" source="SECUNIA">26660</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2008/000003.html" source="MLIST">[Security-announce] 20080107 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html" source="SUSE">SUSE-SR:2008:005</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">HPSBUX02262</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="coyote_http_connector">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="apache" name="tomcat">
        <vers num="4.1.24" />
        <vers num="5.0.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2091" published="2005-07-05" name="CVE-2005-2091" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf" source="MISC">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref>
      <ref url="http://www.securiteam.com/securityreviews/5GP0220G0U.html" source="MISC">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html" source="BUGTRAQ">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42898" source="XF">ibm-websphere-hrs(42898)</ref>
      <ref url="http://securitytracker.com/id?1014367" source="SECTRACK">1014367</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.0" />
        <vers num="5.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2092" published="2005-07-05" name="CVE-2005-2092" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf" source="MISC">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref>
      <ref url="http://www.securiteam.com/securityreviews/5GP0220G0U.html" source="MISC">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html" source="BUGTRAQ">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42901" source="XF">bea-weblogic-hrs(42901)</ref>
      <ref url="http://securitytracker.com/id?1014366" source="SECTRACK">1014366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2093" published="2005-07-05" name="CVE-2005-2093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Application Server to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf" source="MISC">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref>
      <ref url="http://www.securiteam.com/securityreviews/5GP0220G0U.html" source="MISC">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html" source="BUGTRAQ">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42902" source="XF">oracle-applicationserver-hrs(42902)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2094" published="2005-07-05" name="CVE-2005-2094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes SunONE to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf" source="MISC">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref>
      <ref url="http://www.securiteam.com/securityreviews/5GP0220G0U.html" source="MISC">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html" source="BUGTRAQ">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42903" source="XF">sun-sunone-hrs(42903)</ref>
      <ref url="http://securitytracker.com/id?1014369" source="SECTRACK">1014369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_web_server">
        <vers num="6.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2095" published="2005-07-13" name="CVE-2005-2095" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-756" source="DEBIAN" patch="1" adv="1">DSA-756</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163047" source="FEDORA">FLSA:163047</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21359" source="XF">squirrelmail-set-post-variable(21359)</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2005-07-13" source="CONFIRM">http://www.squirrelmail.org/security/issue/2005-07-13</ref>
      <ref url="http://www.securityfocus.com/bid/14254" source="BID">14254</ref>
      <ref url="http://www.securityfocus.com/archive/1/405202" source="BUGTRAQ">20050714 SquirrelMail Arbitrary Variable Overwriting Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/405200" source="BUGTRAQ">20050714 [SM-ANNOUNCE] Patch available for CAN-2005-2095</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-595.html" source="REDHAT">RHSA-2005:595</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00090-07142005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00090-07142005</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10500" source="OVAL">oval:org.mitre.oval:def:10500</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
        <vers num="1.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2096" published="2005-07-06" name="CVE-2005-2096" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/680620" source="CERT-VN" adv="1">VU#680620</ref>
      <ref url="http://www.securityfocus.com/bid/14162" source="BID" patch="1">14162</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-569.html" source="REDHAT" patch="1" adv="1">RHSA-2005:569</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200509-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200509-18</ref>
      <ref url="http://www.debian.org/security/2005/dsa-797" source="DEBIAN" patch="1" adv="1">DSA-797</ref>
      <ref url="http://www.debian.org/security/2005/dsa-740" source="DEBIAN" patch="1" adv="1">DSA-740</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101989-1" source="SUNALERT" patch="1" adv="1">101989</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200507-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200507-05</ref>
      <ref url="http://secunia.com/advisories/15949" source="SECUNIA" patch="1" adv="1">15949</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162680" source="FEDORA" adv="1">FLSA:162680</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162391" source="MISC" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162391</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1267" source="VUPEN">ADV-2007-1267</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0144" source="VUPEN">ADV-2006-0144</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0978" source="VUPEN">ADV-2005-0978</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-148-1" source="UBUNTU" adv="1">USN-148-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421411/100/0/threaded" source="HP">HPSBUX02090</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0629.html" source="REDHAT">RHSA-2008:0629</ref>
      <ref url="http://support.apple.com/kb/HT3298" source="CONFIRM">http://support.apple.com/kb/HT3298</ref>
      <ref url="http://securitytracker.com/id?1014398" source="SECTRACK" adv="1">1014398</ref>
      <ref url="http://secunia.com/advisories/31492" source="SECUNIA">31492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11500" source="OVAL">oval:org.mitre.oval:def:11500</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE" adv="1">APPLE-SA-2005-08-17</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2008/Nov/msg00001.html" source="APPLE">APPLE-SA-2008-11-13</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:16.zlib.asc" source="FREEBSD">FreeBSD-SA-05:16.zlib</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24064" source="XF">hpux-secure-shell-dos(24064)</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-9916286-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-9916286-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-3616065-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-3616065-patch.html</ref>
      <ref url="http://www.ubuntulinux.org/usn/usn-151-3" source="UBUNTU">USN-151-3</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482950/100/0/threaded" source="BUGTRAQ">20071029 Windows binary of "Virtual Floppy Drive 2.1" contains vulnerable zlib (CAN-2005-2096)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482949/100/0/threaded" source="BUGTRAQ">20071029 Re: Windows binary of "GSview 4.8" contain vulnerable zlib (CAN-2005-2096)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482601/100/0/threaded" source="BUGTRAQ">20071021 Re: Windows binary of "GSview 4.8" contain vulnerable zlib (CAN-2005-2096)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482571/100/0/threaded" source="BUGTRAQ">20071020 Re: Windows binary of "GSview 4.8" contain vulnerable zlib (CAN-2005-2096)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482505/100/0/threaded" source="BUGTRAQ">20071018 Official Windows binaries of "curl" contain vulnerable zlib 1.2.2 (CAN-2005-2096)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482503/100/0/threaded" source="BUGTRAQ">20071018 Windows binary of "GSview 4.8" contain vulnerable zlib (CAN-2005-2096)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded" source="BUGTRAQ">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421411/100/0/threaded" source="HP">HPSBUX02090</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:070" source="MANDRIVA">MDKSA-2006:070</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:196" source="MANDRIVA">MDKSA-2005:196</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:112" source="MANDRAKE">MDKSA-2005:112</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1026" source="DEBIAN">DSA-1026</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-016.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-016.htm</ref>
      <ref url="http://secunia.com/advisories/24788" source="SECUNIA">24788</ref>
      <ref url="http://secunia.com/advisories/19597" source="SECUNIA">19597</ref>
      <ref url="http://secunia.com/advisories/19550" source="SECUNIA">19550</ref>
      <ref url="http://secunia.com/advisories/18507" source="SECUNIA">18507</ref>
      <ref url="http://secunia.com/advisories/18406" source="SECUNIA">18406</ref>
      <ref url="http://secunia.com/advisories/18377" source="SECUNIA">18377</ref>
      <ref url="http://secunia.com/advisories/17516" source="SECUNIA">17516</ref>
      <ref url="http://secunia.com/advisories/17326" source="SECUNIA">17326</ref>
      <ref url="http://secunia.com/advisories/17236" source="SECUNIA">17236</ref>
      <ref url="http://secunia.com/advisories/17225" source="SECUNIA">17225</ref>
      <ref url="http://secunia.com/advisories/17054" source="SECUNIA">17054</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.6/SCOSA-2006.6.txt" source="SCO">SCOSA-2006.6</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1542" source="OVAL" sig="1">oval:org.mitre.oval:def:1542</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1262" source="OVAL" sig="1">oval:org.mitre.oval:def:1262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="zlib">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2097" published="2005-08-16" name="CVE-2005-2097" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2280" source="VUPEN">ADV-2007-2280</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-163-1" source="UBUNTU" adv="1">USN-163-1</ref>
      <ref url="http://www.securityfocus.com/bid/14529" source="BID">14529</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427990/100/0/threaded" source="FEDORA">FLSA:175404</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427053/100/0/threaded" source="FEDORA">FLSA-2006:176751</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-708.html" source="REDHAT">RHSA-2005:708</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-706.html" source="REDHAT">RHSA-2005:706</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-671.html" source="REDHAT">RHSA-2005:671</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-670.html" source="REDHAT">RHSA-2005:670</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:138" source="MANDRIVA">MDKSA-2005:138</ref>
      <ref url="http://www.debian.org/security/2006/dsa-936" source="DEBIAN" adv="1">DSA-936</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1136" source="DEBIAN">DSA-1136</ref>
      <ref url="http://www.debian.org/security/2005/dsa-780" source="DEBIAN">DSA-780</ref>
      <ref url="http://secunia.com/advisories/21339" source="SECUNIA">21339</ref>
      <ref url="http://secunia.com/advisories/18407" source="SECUNIA" adv="1">18407</ref>
      <ref url="http://secunia.com/advisories/18398" source="SECUNIA" adv="1">18398</ref>
      <ref url="http://secunia.com/advisories/17277" source="SECUNIA" adv="1">17277</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10280" source="OVAL">oval:org.mitre.oval:def:10280</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt" source="SCO">SCOSA-2005.42</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1" source="SUNALERT">102972</ref>
      <ref url="http://secunia.com/advisories/25729" source="SECUNIA">25729</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kpdf">
        <vers num="" />
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="3.0" />
        <vers num="3.0_pl2" />
        <vers num="3.0_pl3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2098" published="2005-08-23" name="CVE-2005-2098" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16355/" source="SECUNIA" patch="1" adv="1">16355</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1" source="UBUNTU" adv="1">USN-169-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRAKE">MDKSA-2005:220</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9638" source="OVAL">oval:org.mitre.oval:def:9638</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5</ref>
      <ref url="http://www.securityfocus.com/bid/14521" source="BID">14521</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRAKE">MDKSA-2005:220</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2099" published="2005-08-23" name="CVE-2005-2099" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes the creation to fail, leading to a null dereference in the keyring destructor.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16355/" source="SECUNIA" patch="1" adv="1">16355</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1" source="UBUNTU" adv="1">USN-169-1</ref>
      <ref url="http://www.securityfocus.com/bid/14517" source="BID">14517</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRAKE">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://securitytracker.com/id?1014644" source="SECTRACK">1014644</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA" adv="1">17073</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9079" source="OVAL">oval:org.mitre.oval:def:9079</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2100" published="2005-10-25" name="CVE-2005-2100" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=165547" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=165547</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT" adv="1">RHSA-2005:514</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11556" source="OVAL">oval:org.mitre.oval:def:11556</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2101" published="2005-08-17" name="CVE-2005-2101" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050815-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050815-1.txt</ref>
      <ref url="http://www.securityfocus.com/bid/14561" source="BID">14561</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:159" source="MANDRAKE">MDKSA-2005:159</ref>
      <ref url="http://www.debian.org/security/2005/dsa-818" source="DEBIAN">DSA-818</ref>
      <ref url="http://securitytracker.com/id?1014675" source="SECTRACK">1014675</ref>
      <ref url="http://secunia.com/advisories/16428" source="SECUNIA">16428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.5a" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.1_alpha1" />
        <vers num="3.1_beta1" />
        <vers num="3.1_beta2" />
        <vers num="3.2" />
        <vers num="3.2.0_beta1" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2102" published="2005-08-16" name="CVE-2005-2102" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-168-1" source="UBUNTU">USN-168-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9283" source="OVAL">oval:org.mitre.oval:def:9283</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=21" source="CONFIRM">http://gaim.sourceforge.net/security/?id=21</ref>
      <ref url="http://www.securityfocus.com/bid/14531" source="BID">14531</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-627.html" source="REDHAT">RHSA-2005:627</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2103" published="2005-08-16" name="CVE-2005-2103" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-168-1" source="UBUNTU" adv="1">USN-168-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11477" source="OVAL">oval:org.mitre.oval:def:11477</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=22" source="CONFIRM">http://gaim.sourceforge.net/security/?id=22</ref>
      <ref url="http://www.securityfocus.com/bid/14531" source="BID">14531</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-627.html" source="REDHAT">RHSA-2005:627</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-589.html" source="REDHAT">RHSA-2005:589</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.76" />
        <vers num="0.77" />
        <vers num="0.78" />
        <vers num="0.79" />
        <vers num="0.80" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.82.1" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2104" published="2005-10-07" name="CVE-2005-2104" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21770" source="XF" patch="1">sysreport-race-condition(21770)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-598.html" source="REDHAT" patch="1" adv="1">RHSA-2005:598</ref>
      <ref url="http://securitytracker.com/id?1014653" source="SECTRACK" patch="1" adv="1">1014653</ref>
      <ref url="http://secunia.com/advisories/16381" source="SECUNIA" patch="1">16381</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162978" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162978</ref>
      <ref url="http://www.securityfocus.com/bid/15379" source="BID">15379</ref>
      <ref url="http://www.osvdb.org/18682" source="OSVDB">18682</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9411" source="OVAL">oval:org.mitre.oval:def:9411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00035.html" source="FEDORA">FEDORA-2005-1072</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00034.html" source="FEDORA">FEDORA-2005-1071</ref>
      <ref url="http://secunia.com/advisories/17539" source="SECUNIA">17539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="sysreport">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2105" published="2005-07-05" name="CVE-2005-2105" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21190" source="XF" patch="1">radius-authentication-bypass(21190)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Jun/1014330.html" source="SECTRACK" patch="1">1014330</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050629-aaa.shtml" source="CISCO" patch="1" adv="1">20050629 RADIUS Authentication Bypass</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5756" source="OVAL">oval:org.mitre.oval:def:5756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(2)xr" />
        <vers num="12.2(4)xr" />
        <vers num="12.2t" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xt" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yy" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zn" />
        <vers num="12.2zo" />
        <vers num="12.2zp" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xm" />
        <vers num="12.3xn" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xt" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yb" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3yl" />
        <vers num="12.3yn" />
        <vers num="12.3yq" />
        <vers num="12.3yr" />
        <vers num="12.3ys" />
        <vers num="12.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2106" published="2005-07-05" name="CVE-2005-2106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15872" source="SECUNIA" patch="1" adv="1">15872</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112015287827452&amp;w=2" source="BUGTRAQ" adv="1">20050629 [DRUPAL-SA-2005-002] Drupal 4.6.2 / 4.5.4 fixes input validation issue</ref>
      <ref url="http://www.securityfocus.com/bid/14110" source="BID">14110</ref>
      <ref url="http://www.drupal.org/security/drupal-sa-2005-002/advisory.txt" source="CONFIRM">http://www.drupal.org/security/drupal-sa-2005-002/advisory.txt</ref>
      <ref url="http://www.debian.org/security/2005/dsa-745" source="DEBIAN">DSA-745</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.5.0" />
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.5.3" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2107" published="2005-07-05" name="CVE-2005-2107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15831" source="SECUNIA" patch="1" adv="1">15831</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00085-06282005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00085-06282005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006967221438&amp;w=2" source="BUGTRAQ" adv="1">20050629 WordPress 1.5.1.2 &amp;&amp; Earlier Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2108" published="2005-07-05" name="CVE-2005-2108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15831" source="SECUNIA" patch="1" adv="1">15831</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00085-06282005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00085-06282005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006967221438&amp;w=2" source="BUGTRAQ" adv="1">20050629 WordPress 1.5.1.2 &amp;&amp; Earlier Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2109" published="2005-07-05" name="CVE-2005-2109" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15831" source="SECUNIA" patch="1" adv="1">15831</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00085-06282005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00085-06282005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006967221438&amp;w=2" source="BUGTRAQ" adv="1">20050629 WordPress 1.5.1.2 &amp;&amp; Earlier Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2110" published="2005-07-05" name="CVE-2005-2110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message.  NOTE: vector [1] was later reported to also affect WordPress 2.0.1.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15831" source="SECUNIA" patch="1" adv="1">15831</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426304/100/0/threaded" source="BUGTRAQ">20060227 WordPress 2.0.1 Multiple Vulnerabilities</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00085-06282005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00085-06282005</ref>
      <ref url="http://NeoSecurityTeam.net/advisories/Advisory-17.txt" source="MISC">http://NeoSecurityTeam.net/advisories/Advisory-17.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006967221438&amp;w=2" source="BUGTRAQ" adv="1">20050629 WordPress 1.5.1.2 &amp;&amp; Earlier Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2111" published="2005-07-05" name="CVE-2005-2111" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.badroot.org/advisories/SA0x05" source="MISC" adv="1">http://www.badroot.org/advisories/SA0x05</ref>
      <ref url="http://secunia.com/advisories/15880" source="SECUNIA" adv="1">15880</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006558125309&amp;w=2" source="BUGTRAQ" adv="1">20050629 [badroot security] Community link pro web editor: Remote command</ref>
      <ref url="http://securitytracker.com/id?1014345" source="SECTRACK">1014345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="community_link_pro_web_editor" name="community_link_pro_web_editor">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2112" published="2005-07-05" name="CVE-2005-2112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xoops.org/modules/news/article.php?storyid=2383" source="CONFIRM" patch="1">http://www.xoops.org/modules/news/article.php?storyid=2383</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00086-06292005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00086-06292005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006318512991&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050629 XOOPS 2.0.11 &amp;&amp; Earlier Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/15843" source="SECUNIA">15843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.5.1" />
        <vers num="2.0.5.2" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.9" />
        <vers num="2.0.9.2" />
        <vers num="2.0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2113" published="2005-07-05" name="CVE-2005-2113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xoops.org/modules/news/article.php?storyid=2383" source="CONFIRM" patch="1">http://www.xoops.org/modules/news/article.php?storyid=2383</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00086-06292005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00086-06292005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006318512991&amp;w=2" source="BUGTRAQ" adv="1">20050629 XOOPS 2.0.11 &amp;&amp; Earlier Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/15843" source="SECUNIA">15843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.5.1" />
        <vers num="2.0.5.2" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.9" />
        <vers num="2.0.9.2" />
        <vers num="2.0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2114" published="2005-07-05" name="CVE-2005-2114" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kurczaba.com/html/security/0506241.htm" source="MISC" adv="1">http://www.kurczaba.com/html/security/0506241.htm</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9628" source="OVAL">oval:org.mitre.oval:def:9628</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008299210033&amp;w=2" source="BUGTRAQ" adv="1">20050629 Mozilla Multiple Product JavaScript Issue</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21188" source="XF">mozilla-mult-browsers-javascript-dos(21188)</ref>
      <ref url="http://www.securiteam.com/securitynews/5OP0U00G1G.html" source="MISC">http://www.securiteam.com/securitynews/5OP0U00G1G.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://securitytracker.com/id?1014372" source="SECTRACK">1014372</ref>
      <ref url="http://securitytracker.com/id?1014349" source="SECTRACK">1014349</ref>
      <ref url="http://securitytracker.com/id?1014294" source="SECTRACK">1014294</ref>
      <ref url="http://securitytracker.com/id?1014293" source="SECTRACK">1014293</ref>
      <ref url="http://securitytracker.com/id?1014292" source="SECTRACK">1014292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="camino">
        <vers num="0.8.4" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2115" published="2005-07-05" name="CVE-2005-2115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/17649" source="OSVDB">17649</ref>
      <ref url="http://secunia.com/advisories/15868" source="SECUNIA" adv="1">15868</ref>
      <ref url="http://aluigi.altervista.org/adv/sof2ignore-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/sof2ignore-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008428126593&amp;w=2" source="BUGTRAQ">20050629 In-game /ignore crash in Soldier of Fortune II 1.03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raven_software" name="soldier_of_fortune_2">
        <vers num="1.02" />
        <vers num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-2116" reject="1" published="2005-07-05" name="CVE-2005-2116" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1921.  Reason: This candidate is a duplicate of CVE-2005-1921.  Notes: All CVE users should reference CVE-2005-1921 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <other />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2117" published="2005-10-21" name="CVE-2005-2117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT">TA05-284A</ref>
      <ref url="http://www.securityfocus.com/bid/15064" source="BID">15064</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx" source="MS">MS05-049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://secunia.com/advisories/17168" source="SECUNIA">17168</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1291" source="OVAL" sig="1">oval:org.mitre.oval:def:1291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_explorer">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2118" published="2005-10-21" name="CVE-2005-2118" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT" adv="1">TA05-284A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx" source="MS" patch="1">MS05-049</ref>
      <ref url="http://www.securityfocus.com/bid/15070" source="BID">15070</ref>
      <ref url="http://www.argeniss.com/research/MSBugPaper.pdf" source="MISC" adv="1">http://www.argeniss.com/research/MSBugPaper.pdf</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://securitytracker.com/id?1015040" source="SECTRACK">1015040</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA" adv="1">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA" adv="1">17172</ref>
      <ref url="http://secunia.com/advisories/17168" source="SECUNIA" adv="1">17168</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1192" source="OVAL" sig="1">oval:org.mitre.oval:def:1192</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1116" source="OVAL" sig="1">oval:org.mitre.oval:def:1116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2119" published="2005-10-12" name="CVE-2005-2119" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT">TA05-284A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/180868" source="CERT-VN">VU#180868</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS05-051.mspx" source="MS" patch="1" adv="1">MS05-051</ref>
      <ref url="http://www.osvdb.org/18828" source="OSVDB">18828</ref>
      <ref url="http://www.securityfocus.com/bid/15056" source="BID">15056</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20051011b.html" source="EEYE">AD20051011b</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://securitytracker.com/id?1015037" source="SECTRACK">1015037</ref>
      <ref url="http://securityreason.com/securityalert/73" source="SREASON">73</ref>
      <ref url="http://secunia.com/advisories/17509" source="SECUNIA">17509</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://secunia.com/advisories/17161" source="SECUNIA">17161</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:551" source="OVAL" sig="1">oval:org.mitre.oval:def:551</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1452" source="OVAL" sig="1">oval:org.mitre.oval:def:1452</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1071" source="OVAL" sig="1">oval:org.mitre.oval:def:1071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="r2" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2120" published="2005-10-13" name="CVE-2005-2120" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT" adv="1">TA05-284A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/214572" source="CERT-VN" adv="1">VU#214572</ref>
      <ref url="http://www.securityfocus.com/bid/15065" source="BID" patch="1">15065</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-047.mspx" source="MS" patch="1" adv="1">MS05-047</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20051011c.html" source="EEYE" patch="1" adv="1">AD20051011c</ref>
      <ref url="http://securitytracker.com/id?1015042" source="SECTRACK" patch="1">1015042</ref>
      <ref url="http://secunia.com/advisories/17166" source="SECUNIA" patch="1" adv="1">17166</ref>
      <ref url="http://www.osvdb.org/18830" source="OSVDB">18830</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://securityreason.com/securityalert/71" source="SREASON">71</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1519" source="OVAL" sig="1">oval:org.mitre.oval:def:1519</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1328" source="OVAL" sig="1">oval:org.mitre.oval:def:1328</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1244" source="OVAL" sig="1">oval:org.mitre.oval:def:1244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2122" published="2005-10-21" name="CVE-2005-2122" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT" adv="1">TA05-284A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/922708" source="CERT-VN" adv="1">VU#922708</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx" source="MS" patch="1" adv="1">MS05-049</ref>
      <ref url="http://www.securityfocus.com/bid/15069" source="BID">15069</ref>
      <ref url="http://www.argeniss.com/research/MSBugPaper.pdf" source="MISC" adv="1">http://www.argeniss.com/research/MSBugPaper.pdf</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://securitytracker.com/id?1015040" source="SECTRACK">1015040</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA" adv="1">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA" adv="1">17172</ref>
      <ref url="http://secunia.com/advisories/17168" source="SECUNIA" adv="1">17168</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:708" source="OVAL" sig="1">oval:org.mitre.oval:def:708</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1551" source="OVAL" sig="1">oval:org.mitre.oval:def:1551</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1537" source="OVAL" sig="1">oval:org.mitre.oval:def:1537</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1517" source="OVAL" sig="1">oval:org.mitre.oval:def:1517</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1488" source="OVAL" sig="1">oval:org.mitre.oval:def:1488</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1329" source="OVAL" sig="1">oval:org.mitre.oval:def:1329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2123" published="2005-11-29" name="CVE-2005-2123" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/300549" source="CERT-VN" patch="1" adv="1">VU#300549</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-312A.html" source="CERT">TA05-312A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS05-053.mspx" source="MS" patch="1" adv="1">MS05-053</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20051108b.html" source="MISC" patch="1" adv="1">http://www.eeye.com/html/research/advisories/AD20051108b.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2348" source="VUPEN">ADV-2005-2348</ref>
      <ref url="http://www.securityfocus.com/bid/15352" source="BID">15352</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf</ref>
      <ref url="http://securitytracker.com/id?1015168" source="SECTRACK">1015168</ref>
      <ref url="http://secunia.com/advisories/17498" source="SECUNIA">17498</ref>
      <ref url="http://secunia.com/advisories/17461" source="SECUNIA">17461</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:701" source="OVAL" sig="1">oval:org.mitre.oval:def:701</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1546" source="OVAL" sig="1">oval:org.mitre.oval:def:1546</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1263" source="OVAL" sig="1">oval:org.mitre.oval:def:1263</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1175" source="OVAL" sig="1">oval:org.mitre.oval:def:1175</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1063" source="OVAL" sig="1">oval:org.mitre.oval:def:1063</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="r2" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2124" published="2005-11-29" name="CVE-2005-2124" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka "Windows Metafile Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/433341" source="CERT-VN" patch="1" adv="1">VU#433341</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-312A.html" source="CERT">TA05-312A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS05-053.mspx" source="MS" patch="1" adv="1">MS05-053</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20051108b.html" source="MISC" patch="1" adv="1">http://www.eeye.com/html/research/advisories/AD20051108b.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2348" source="VUPEN">ADV-2005-2348</ref>
      <ref url="http://securitytracker.com/id?1015168" source="SECTRACK">1015168</ref>
      <ref url="http://www.securityfocus.com/bid/15356" source="BID">15356</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20051108a.html" source="MISC">http://www.eeye.com/html/research/advisories/AD20051108a.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf</ref>
      <ref url="http://securityreason.com/securityalert/161" source="SREASON">161</ref>
      <ref url="http://secunia.com/advisories/17498" source="SECUNIA">17498</ref>
      <ref url="http://secunia.com/advisories/17461" source="SECUNIA">17461</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="r2" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2126" published="2005-10-21" name="CVE-2005-2126" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/415828" source="CERT-VN" adv="1">VU#415828</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6M00I0KEAU.html" source="MISC" patch="1">http://www.securiteam.com/windowsntfocus/6M00I0KEAU.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-044.mspx" source="MS" patch="1" adv="1">MS05-044</ref>
      <ref url="http://secunia.com/advisories/17163" source="SECUNIA" patch="1" adv="1">17163</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://securitytracker.com/id?1015036" source="SECTRACK">1015036</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1416" source="OVAL" sig="1">oval:org.mitre.oval:def:1416</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1284" source="OVAL" sig="1">oval:org.mitre.oval:def:1284</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1146" source="OVAL" sig="1">oval:org.mitre.oval:def:1146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2127" published="2005-08-19" name="CVE-2005-2127" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT">TA05-284A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/959049" source="CERT-VN" adv="1">VU#959049</ref>
      <ref url="http://www.kb.cert.org/vuls/id/740372" source="CERT-VN" adv="1">VU#740372</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-220A.html" source="CERT">TA06-220A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-347A.html" source="CERT">TA05-347A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/898241" source="CERT-VN">VU#898241</ref>
      <ref url="http://www.securityfocus.com/bid/14594" source="BID" patch="1">14594</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-052.mspx" source="MS" patch="1" adv="1">MS05-052</ref>
      <ref url="http://securitytracker.com/id?1014727" source="SECTRACK" patch="1" adv="1">1014727</ref>
      <ref url="http://secunia.com/advisories/16480" source="SECUNIA" patch="1" adv="1">16480</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21895" source="XF">Win-msdss-command-execution(21895)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1450" source="VUPEN">ADV-2005-1450</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/906267.mspx" source="MISC" adv="1">http://www.microsoft.com/technet/security/advisory/906267.mspx</ref>
      <ref url="http://isc.sans.org/diary.php?date=2005-08-18" source="MISC">http://isc.sans.org/diary.php?date=2005-08-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34754" source="XF">microsoft-ie-mshtml-dos(34754)</ref>
      <ref url="http://www.securityfocus.com/bid/15061" source="BID">15061</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470690/100/0/threaded" source="BUGTRAQ">20070606 IE 6/Microsoft Html Popup Window (mshtml.dll) DoS</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://securityreason.com/securityalert/72" source="SREASON">72</ref>
      <ref url="http://secunia.com/advisories/17509" source="SECUNIA">17509</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1538" source="OVAL" sig="1">oval:org.mitre.oval:def:1538</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1535" source="OVAL" sig="1">oval:org.mitre.oval:def:1535</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1468" source="OVAL" sig="1">oval:org.mitre.oval:def:1468</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1464" source="OVAL" sig="1">oval:org.mitre.oval:def:1464</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1454" source="OVAL" sig="1">oval:org.mitre.oval:def:1454</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1155" source="OVAL" sig="1">oval:org.mitre.oval:def:1155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ati" name="catalyst_driver">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.1" edition="sp1" />
        <vers num="1.1" edition="sp2" />
        <vers num="1.1" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":" />
        <vers num="2000" edition="::korean" />
        <vers num="2000" edition="::japanese" />
        <vers num="2000" edition="::chinese" />
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="xp" edition="" />
        <vers num="xp" edition=":developer" />
        <vers num="xp" edition="sp1" />
        <vers num="xp" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="2000" />
        <vers num="2002" edition="sp1" />
        <vers num="2003" edition="sp1" />
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":enterprise" />
        <vers num="2000" edition="sr1" />
        <vers num="2000" edition="sr1:enterprise" />
        <vers num="2002" edition="" />
        <vers num="2002" edition=":professional" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp2:professional" />
        <vers num="2002" edition="sp2:standard" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":professional" />
        <vers num="2003" edition=":standard" />
        <vers num="2003" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2002" edition="gold" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":enterprise_architect" />
        <vers num="2003" edition="gold" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":academic" />
        <vers num="gold" edition=":trial" />
        <vers num="gold" edition=":enterprise_developer" />
        <vers num="gold" edition=":enterprise_architect" />
        <vers num="gold" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2128" published="2005-10-12" name="CVE-2005-2128" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html" source="CERT">TA05-284A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/995220" source="CERT-VN">VU#995220</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS05-050.mspx" source="MS" patch="1" adv="1">MS05-050</ref>
      <ref url="http://www.osvdb.org/18822" source="OSVDB">18822</ref>
      <ref url="http://www.securityfocus.com/bid/15063" source="BID">15063</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20051011a.html" source="EEYE">AD20051011a</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://secunia.com/advisories/17509" source="SECUNIA">17509</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://secunia.com/advisories/17160" source="SECUNIA">17160</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1434" source="OVAL" sig="1">oval:org.mitre.oval:def:1434</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1424" source="OVAL" sig="1">oval:org.mitre.oval:def:1424</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1267" source="OVAL" sig="1">oval:org.mitre.oval:def:1267</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1231" source="OVAL" sig="1">oval:org.mitre.oval:def:1231</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1149" source="OVAL" sig="1">oval:org.mitre.oval:def:1149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2132" published="2005-08-03" name="CVE-2005-2132" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">RPC portmapper (rpcbind) in SCO UnixWare 7.1.1 m5, 7.1.3 mp5, and 7.1.4 mp2 allows remote attackers or local users to cause a denial of service (lack of response) via multiple invalid portmap requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.31/SCOSA-2005.31.txt" source="SCO" patch="1" adv="1">SCOSA-2005.31</ref>
      <ref url="http://www.securityfocus.com/bid/14360" source="BID">14360</ref>
      <ref url="http://secunia.com/advisories/16228" source="SECUNIA">16228</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112247187722821&amp;w=2" source="BUGTRAQ">20050727 [NILESA-20050701] UnixWare 7.x RPC portmapper Dos Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1_m5" />
        <vers num="7.1.3_mp5" />
        <vers num="7.1.4_mp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2133" published="2005-07-05" name="CVE-2005-2133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1915.  Reason: This candidate is a duplicate of CVE-2005-1915.  Notes: All CVE users should reference CVE-2005-1915 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="log4sh" name="log4sh">
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2134" published="2005-07-05" name="CVE-2005-2134" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2005-002.txt.asc" source="NETBSD" adv="1">NetBSD-SA2005-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2135" published="2005-07-05" name="CVE-2005-2135" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15818" source="SECUNIA" adv="1">15818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etoshop" name="dynamic_biz_website_builder_quickweb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2136" published="2005-07-05" name="CVE-2005-2136" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15853" source="SECUNIA" patch="1" adv="1">15853</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jun/0251.html" source="BUGTRAQ" patch="1" adv="1">20050628 Access right escalation / severe permission problems on Raritan Console Servers</ref>
      <ref url="http://www.securityfocus.com/bid/14084" source="BID">14084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raritan" name="dominion">
        <vers num="sx16" />
        <vers num="sx32" />
        <vers num="sx32_2.4.6_firmware" />
        <vers num="sx4" />
        <vers num="sx8" />
        <vers num="sxa-48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2137" published="2005-07-05" name="CVE-2005-2137" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in NateOn Messenger 3.0 allows remote attackers to list arbitrary directories via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14100" source="BID">14100</ref>
      <ref url="http://www.osvdb.org/17619" source="OSVDB">17619</ref>
      <ref url="http://secunia.com/advisories/15819" source="SECUNIA" adv="1">15819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nateon" name="nateon_messenger">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2138" published="2005-07-05" name="CVE-2005-2138" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15865" source="SECUNIA" adv="1">15865</ref>
      <ref url="http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=64" source="MISC" adv="1">http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=64</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comdev" name="comdev_ecommerce">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2139" published="2005-07-05" name="CVE-2005-2139" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0930" source="VUPEN">ADV-2005-0930</ref>
      <ref url="http://www.osvdb.org/17631" source="OSVDB">17631</ref>
      <ref url="http://securitytracker.com/id?1014321" source="SECTRACK">1014321</ref>
      <ref url="http://secunia.com/advisories/15873" source="SECUNIA" adv="1">15873</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pavsta" name="pavsta_auto_site">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2140" published="2005-07-05" name="CVE-2005-2140" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14111" source="BID">14111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fsboard" name="fsboard">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2141" published="2005-07-05" name="CVE-2005-2141" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014371" source="SECTRACK" adv="1">1014371</ref>
      <ref url="http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=65" source="MISC">http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=65</ref>
      <ref url="http://addict3d.org/index.php?page=viewarticle&amp;type=security&amp;ID=4377" source="MISC">http://addict3d.org/index.php?page=viewarticle&amp;type=security&amp;ID=4377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jollybox.de" name="tcp_chat">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2142" published="2005-07-05" name="CVE-2005-2142" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a "\.."  (backslash dot dot) in an LS (LIST) command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15840" source="SECUNIA" adv="1">15840</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kmint21_software" name="golden_ftp_server">
        <vers num="2.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2143" published="2005-07-05" name="CVE-2005-2143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.freewebs.com/xxosfilexx/HungFPage.html" source="MISC">http://www.freewebs.com/xxosfilexx/HungFPage.html</ref>
      <ref url="http://securitytracker.com/id?1014352" source="SECTRACK" adv="1">1014352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2144" published="2005-07-05" name="CVE-2005-2144" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014346" source="SECTRACK" adv="1">1014346</ref>
      <ref url="http://secunia.com/advisories/15885" source="SECUNIA" adv="1">15885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prevx" name="prevx_pro_2005">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2145" published="2005-07-05" name="CVE-2005-2145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014346" source="SECTRACK">1014346</ref>
      <ref url="http://secunia.com/advisories/15885" source="SECUNIA" adv="1">15885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prevx" name="prevx_pro_2005">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2146" published="2005-07-05" name="CVE-2005-2146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ssh.com/company/newsroom/article/653/" source="CONFIRM" patch="1" adv="1">http://www.ssh.com/company/newsroom/article/653/</ref>
      <ref url="http://secunia.com/advisories/15894" source="SECUNIA" patch="1" adv="1">15894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="tectia_server">
        <vers num="4.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2147" published="2005-07-06" name="CVE-2005-2147" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13990" source="BID" patch="1">13990</ref>
      <ref url="http://www.hardened-php.net/advisory-012005.php" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory-012005.php</ref>
      <ref url="http://secunia.com/advisories/15752" source="SECUNIA" patch="1" adv="1">15752</ref>
      <ref url="http://www.debian.org/security/2005/dsa-739" source="DEBIAN">DSA-739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edgewall_software" name="trac">
        <vers num="0.7.1" />
        <vers num="0.8.1" />
        <vers num="0.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2148" published="2005-07-06" name="CVE-2005-2148" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory-042005.php" source="MISC" patch="1">http://www.hardened-php.net/advisory-042005.php</ref>
      <ref url="http://www.hardened-php.net/advisory-032005.php" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory-032005.php</ref>
      <ref url="http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch" source="CONFIRM" patch="1">http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?forum_id=10360&amp;max_rows=25&amp;style=flat&amp;viewmonth=200507&amp;viewday=1" source="MLIST" patch="1">[cacti-announce] 20050701 Cacti 0.8.6f Released</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0951" source="VUPEN">ADV-2005-0951</ref>
      <ref url="http://www.securityfocus.com/archive/1/404054" source="BUGTRAQ">20050702 Advisory 03/2005: Cacti Multiple SQL Injection Vulnerabilities [FIXED]</ref>
      <ref url="http://www.securityfocus.com/archive/1/404047/30/30/threaded" source="BUGTRAQ">20050702 Advisory 04/2005: Cacti Remote Command Execution Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21270" source="XF">cacti-request-array-command-execution(21270)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21266" source="XF">cacti-graph-post-cookie-sql-injection(21266)</ref>
      <ref url="http://www.securityfocus.com/bid/14129" source="BID">14129</ref>
      <ref url="http://www.securityfocus.com/bid/14128" source="BID">14128</ref>
      <ref url="http://www.debian.org/security/2005/dsa-764" source="DEBIAN">DSA-764</ref>
      <ref url="http://securitytracker.com/id?1014361" source="SECTRACK">1014361</ref>
      <ref url="http://secunia.com/advisories/15490" source="SECUNIA">15490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.5a" />
        <vers num="0.8.6" />
        <vers num="0.8.6a" />
        <vers num="0.8.6b" />
        <vers num="0.8.6c" />
        <vers num="0.8.6d" />
        <vers num="0.8.6e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2149" published="2005-07-06" name="CVE-2005-2149" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory-052005.php" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory-052005.php</ref>
      <ref url="http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch" source="CONFIRM" patch="1">http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?forum_id=10360&amp;max_rows=25&amp;style=flat&amp;viewmonth=200507&amp;viewday=1" source="MLIST" patch="1">[cacti-announce] 20050701 Cacti 0.8.6f Released</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0951" source="VUPEN">ADV-2005-0951</ref>
      <ref url="http://www.securityfocus.com/archive/1/404040" source="BUGTRAQ">20050702 Advisory 05/2005: Cacti Authentification/Addslashes Bypass Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/14130" source="BID">14130</ref>
      <ref url="http://www.debian.org/security/2005/dsa-764" source="DEBIAN">DSA-764</ref>
      <ref url="http://securitytracker.com/id?1014361" source="SECTRACK">1014361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.5a" />
        <vers num="0.8.6" />
        <vers num="0.8.6a" />
        <vers num="0.8.6b" />
        <vers num="0.8.6c" />
        <vers num="0.8.6d" />
        <vers num="0.8.6e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2150" published="2005-07-11" name="CVE-2005-2150" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hsc.fr/ressources/presentations/null_sessions/" source="MISC">http://www.hsc.fr/ressources/presentations/null_sessions/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076409813099&amp;w=2" source="BUGTRAQ" adv="1">20050707 NULL sessions vulnerabilities using alternate named pipes</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21288" source="XF">win-pipe-null-eventlog-information-disclosure(21288)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21286" source="XF">win-name-pipe-null-information-disclosure(21286)</ref>
      <ref url="http://www.securityfocus.com/bid/14178" source="BID">14178</ref>
      <ref url="http://www.securityfocus.com/bid/14177" source="BID">14177</ref>
      <ref url="http://securitytracker.com/id?1014417" source="SECTRACK">1014417</ref>
      <ref url="http://secunia.com/advisories/14189" source="SECUNIA">14189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2151" published="2005-07-06" name="CVE-2005-2151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.courier-mta.org/?changelog.html" source="MISC">http://www.courier-mta.org/?changelog.html</ref>
      <ref url="http://secunia.com/advisories/15901" source="SECUNIA" adv="1">15901</ref>
    </refs>
    <vuln_soft>
      <prod vendor="double_precision_incorporated" name="courier_mail_server">
        <vers num="0.46" />
        <vers num="0.47" />
        <vers num="0.48" />
        <vers num="0.48.1" />
        <vers num="0.48.2" />
        <vers num="0.49.0" />
        <vers num="0.50.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2152" published="2005-07-06" name="CVE-2005-2152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory-062005.php" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory-062005.php</ref>
      <ref url="http://www.geeklog.net/article.php/geeklog-1.3.11sr1" source="CONFIRM" patch="1" adv="1">http://www.geeklog.net/article.php/geeklog-1.3.11sr1</ref>
      <ref url="http://securitytracker.com/id?1014381" source="SECTRACK">1014381</ref>
      <ref url="http://secunia.com/advisories/15914" source="SECUNIA">15914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geeklog" name="geeklog">
        <vers num="1.3.10" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.7_sr1" />
        <vers num="1.3.7_sr2" />
        <vers num="1.3.7_sr3" />
        <vers num="1.3.7_sr4" />
        <vers num="1.3.7_sr5" />
        <vers num="1.3.8" />
        <vers num="1.3.8_1" />
        <vers num="1.3.8_1_sr1" />
        <vers num="1.3.8_1_sr2" />
        <vers num="1.3.8_1_sr3" />
        <vers num="1.3.8_1_sr4" />
        <vers num="1.3.8_1_sr5" />
        <vers num="1.3.8_1_sr6" />
        <vers num="1.3.9_sr1" />
        <vers num="1.3.9_sr2" />
        <vers num="1.3.9_sr3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2153" published="2005-07-06" name="CVE-2005-2153" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14127" source="BID">14127</ref>
      <ref url="http://securitytracker.com/id?1014373" source="SECTRACK">1014373</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jul/0009.html" source="BUGTRAQ" adv="1">20050701 [SECURITY ALERT] osTicket bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket_sts">
        <vers num="1.2" />
        <vers num="1.2.7" />
        <vers num="1.3_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2154" published="2005-07-06" name="CVE-2005-2154" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14127" source="BID">14127</ref>
      <ref url="http://securitytracker.com/id?1014373" source="SECTRACK">1014373</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jul/0009.html" source="BUGTRAQ" adv="1">20050701 [SECURITY ALERT] osTicket bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket_sts">
        <vers num="1.2" />
        <vers num="1.2.7" />
        <vers num="1.3_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2155" published="2005-07-06" name="CVE-2005-2155" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15893" source="SECUNIA" adv="1">15893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyphpcalendar" name="easyphpcalendar">
        <vers num="6.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2156" published="2005-07-06" name="CVE-2005-2156" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14133" source="BID" patch="1">14133</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=66322&amp;release_id=339317" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=66322&amp;release_id=339317</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnews" name="phpnews">
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2157" published="2005-07-06" name="CVE-2005-2157" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0954" source="VUPEN">ADV-2005-0954</ref>
      <ref url="http://securitytracker.com/id?1014355" source="SECTRACK">1014355</ref>
      <ref url="http://secunia.com/advisories/15910" source="SECUNIA" adv="1">15910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nabocorp" name="nabopoll">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2158" published="2005-07-06" name="CVE-2005-2158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.illegalaccess.org/java/jboss.php" source="MISC" patch="1" adv="1">http://www.illegalaccess.org/java/jboss.php</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112051548512338&amp;w=2" source="BUGTRAQ" adv="1">20050703 JBoss jBPM 2.0: Remote code execution and classloader covert channel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jboss" name="jbpm">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2159" published="2005-07-06" name="CVE-2005-2159" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14138" source="BID">14138</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112051398718830&amp;w=2" source="BUGTRAQ" adv="1">20050704 PlanetFileServer v2.0.1.3 - Denial Of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="planetdns" name="planetfileserver">
        <vers num="2.0.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2160" published="2005-07-06" name="CVE-2005-2160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112060187204457&amp;w=2" source="BUGTRAQ" adv="1">20050705 Imail Cookie Vulnerability (unhashed)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2161" published="2005-07-06" name="CVE-2005-2161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitylab.ru/55612.html" source="MISC">http://www.securitylab.ru/55612.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112059951605939&amp;w=2" source="BUGTRAQ">20050705 XSS in nested tag in phpbb 2.0.16</ref>
      <ref url="http://www.debian.org/security/2005/dsa-768" source="DEBIAN">DSA-768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2162" published="2005-07-06" name="CVE-2005-2162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soulblack.com.ar/repo/papers/advisory/myguestbook_advisory.txt" source="MISC">http://www.soulblack.com.ar/repo/papers/advisory/myguestbook_advisory.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112059876828730&amp;w=2" source="BUGTRAQ" adv="1">20050705 MyGuestbook Remote File Inclusion.</ref>
      <ref url="http://securitytracker.com/id?1014387" source="SECTRACK">1014387</ref>
      <ref url="http://secunia.com/advisories/15927" source="SECUNIA">15927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="levcgi.com" name="myguestbook">
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2163" published="2005-07-06" name="CVE-2005-2163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15928" source="SECUNIA" patch="1" adv="1">15928</ref>
      <ref url="http://www.badroot.org/advisories/SA0x07" source="MISC" adv="1">http://www.badroot.org/advisories/SA0x07</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112059745606348&amp;w=2" source="BUGTRAQ" adv="1">20050705 Re: [badroot security] AutoIndex PHP Script: XSS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autoindex" name="php_script">
        <vers num="1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2164" published="2005-07-06" name="CVE-2005-2164" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=339047" source="MISC" patch="1">http://sourceforge.net/project/shownotes.php?release_id=339047</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112060007704577&amp;w=2" source="BUGTRAQ" adv="1">20050705 [covide] possible sql injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="covide_groupware-crm" name="covide">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2165" published="2005-07-06" name="CVE-2005-2165" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zone-h.org/advisories/read/id=7765" source="MISC" adv="1">http://zone-h.org/advisories/read/id=7765</ref>
      <ref url="http://securitytracker.com/id?1014375" source="SECTRACK">1014375</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globalnotescript" name="globalnotescript">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2166" published="2005-07-06" name="CVE-2005-2166" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15902" source="SECUNIA" adv="1">15902</ref>
      <ref url="http://dark-assassins.com/forum/viewtopic.php?t=90" source="MISC" adv="1">http://dark-assassins.com/forum/viewtopic.php?t=90</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frozenplague.net" name="plague_news_system">
        <vers num="0.4" />
        <vers num="0.4rc3" />
        <vers num="0.4rc4" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2167" published="2005-07-06" name="CVE-2005-2167" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15902" source="SECUNIA" adv="1">15902</ref>
      <ref url="http://dark-assassins.com/forum/viewtopic.php?t=90" source="MISC" adv="1">http://dark-assassins.com/forum/viewtopic.php?t=90</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frozenplague.net" name="plague_news_system">
        <vers num="0.4" />
        <vers num="0.4rc3" />
        <vers num="0.4rc4" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2168" published="2005-07-06" name="CVE-2005-2168" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15902" source="SECUNIA" adv="1">15902</ref>
      <ref url="http://dark-assassins.com/forum/viewtopic.php?t=90" source="MISC" adv="1">http://dark-assassins.com/forum/viewtopic.php?t=90</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frozenplague.net" name="plague_news_system">
        <vers num="0.4" />
        <vers num="0.4rc3" />
        <vers num="0.4rc4" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2169" published="2005-07-06" name="CVE-2005-2169" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in source.php in Quick &amp; Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014376" source="SECTRACK">1014376</ref>
      <ref url="http://secunia.com/advisories/15900" source="SECUNIA" adv="1">15900</ref>
      <ref url="http://guff.szub.net/2005/07/04/quick-and-dirty-security/" source="CONFIRM" adv="1">http://guff.szub.net/2005/07/04/quick-and-dirty-security/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaf_oseo" name="quick_and_dirty_phpsource_printer">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2170" published="2005-07-11" name="CVE-2005-2170" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14194" source="BID" patch="1">14194</ref>
      <ref url="http://www-1.ibm.com/support/entdocview.wss?uid=swg21210334" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/entdocview.wss?uid=swg21210334</ref>
      <ref url="http://secunia.com/advisories/15953" source="SECUNIA" patch="1" adv="1">15953</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1018" source="VUPEN">ADV-2005-1018</ref>
      <ref url="http://www.corsaire.com/advisories/c041127-001.txt" source="MISC" adv="1">http://www.corsaire.com/advisories/c041127-001.txt</ref>
      <ref url="http://securitytracker.com/id?1014424" source="SECTRACK">1014424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_management_framework">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2173" published="2005-07-08" name="CVE-2005-2173" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=293159" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=293159</ref>
      <ref url="http://www.bugzilla.org/security/2.18.1/" source="CONFIRM" patch="1" adv="1">http://www.bugzilla.org/security/2.18.1/</ref>
      <ref url="http://securitytracker.com/id?1014428" source="SECTRACK">1014428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.18" edition="rc3" />
        <vers num="2.18.1" />
        <vers num="2.19" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
        <vers num="2.19.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2174" published="2005-07-08" name="CVE-2005-2174" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=293159" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=293159</ref>
      <ref url="http://www.bugzilla.org/security/2.18.1/" source="CONFIRM" patch="1" adv="1">http://www.bugzilla.org/security/2.18.1/</ref>
      <ref url="http://securitytracker.com/id?1014428" source="SECTRACK">1014428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.18" edition="rc3" />
        <vers num="2.18.1" />
        <vers num="2.19" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
        <vers num="2.19.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2175" published="2005-07-09" name="CVE-2005-2175" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014440" source="SECTRACK">1014440</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-07/0075.html" source="BUGTRAQ" adv="1">20050706 Cross site scripting in Lotus Notes web mail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2176" published="2005-07-09" name="CVE-2005-2176" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0994" source="VUPEN">ADV-2005-0994</ref>
      <ref url="http://www.securityfocus.com/bid/14171" source="BID">14171</ref>
      <ref url="http://secunia.com/advisories/15962" source="SECUNIA" adv="1">15962</ref>
      <ref url="http://www.osvdb.org/17821" source="OSVDB">17821</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972438.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972438.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972433.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972433.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972340.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972340.htm</ref>
      <ref url="http://securitytracker.com/id?1014439" source="SECTRACK">1014439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netmail">
        <vers num="3.0.1" />
        <vers num="3.0.3a" edition="a" />
        <vers num="3.0.3a" edition="b" />
        <vers num="3.1" edition="f" />
        <vers num="3.10" edition="a" />
        <vers num="3.10" edition="b" />
        <vers num="3.10" edition="c" />
        <vers num="3.10" edition="d" />
        <vers num="3.10" edition="e" />
        <vers num="3.10" edition="f" />
        <vers num="3.10" edition="g" />
        <vers num="3.10" edition="h" />
        <vers num="3.5.2" edition="a" />
        <vers num="3.5.2" edition="b" />
        <vers num="3.5.2" edition="c" />
        <vers num="3.5.2" edition="c1" />
        <vers num="3.5.2" edition="e-ftfl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2177" published="2005-07-11" name="CVE-2005-2177" modified="2011-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0034/" source="TRUSTIX" patch="1" adv="1">2005-0034</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=7659656&amp;forum_id=12455" source="MLIST" patch="1">[net-snmp-announce] 20050701 Multiple new Net-SNMP releases to fix a security related bug</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1883" source="VUPEN" adv="1">ADV-2007-1883</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4677" source="VUPEN" adv="1">ADV-2006-4677</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4502" source="VUPEN" adv="1">ADV-2006-4502</ref>
      <ref url="http://www.vmware.com/download/esx/esx-254-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-254-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-213-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-213-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-202-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-202-200610-patch.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-190-1" source="UBUNTU">USN-190-1</ref>
      <ref url="http://www.securityfocus.com/bid/21256" source="BID">21256</ref>
      <ref url="http://www.securityfocus.com/bid/14168" source="BID">14168</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded" source="BUGTRAQ">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-720.html" source="REDHAT">RHSA-2005:720</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-395.html" source="REDHAT">RHSA-2005:395</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-373.html" source="REDHAT">RHSA-2005:373</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_13_sr.html" source="SUSE">SUSE-SR:2007:013</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_12_sr.html" source="SUSE">SUSE-SR:2007:012</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_24_sr.html" source="SUSE">SUSE-SR:2005:024</ref>
      <ref url="http://www.net-snmp.org/about/ChangeLog.html" source="MISC">http://www.net-snmp.org/about/ChangeLog.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:025" source="MANDRIVA">MDKSA-2006:025</ref>
      <ref url="http://www.debian.org/security/2005/dsa-873" source="DEBIAN">DSA-873</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-225.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-225.pdf</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102725-1" source="SUNALERT">102725</ref>
      <ref url="http://securitytracker.com/id?1017273" source="SECTRACK">1017273</ref>
      <ref url="http://secunia.com/advisories/25787" source="SECUNIA" adv="1">25787</ref>
      <ref url="http://secunia.com/advisories/25432" source="SECUNIA" adv="1">25432</ref>
      <ref url="http://secunia.com/advisories/25373" source="SECUNIA" adv="1">25373</ref>
      <ref url="http://secunia.com/advisories/23058" source="SECUNIA" adv="1">23058</ref>
      <ref url="http://secunia.com/advisories/22875" source="SECUNIA" adv="1">22875</ref>
      <ref url="http://secunia.com/advisories/18635" source="SECUNIA" adv="1">18635</ref>
      <ref url="http://secunia.com/advisories/17343" source="SECUNIA" adv="1">17343</ref>
      <ref url="http://secunia.com/advisories/17282" source="SECUNIA" adv="1">17282</ref>
      <ref url="http://secunia.com/advisories/17217" source="SECUNIA" adv="1">17217</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA" adv="1">17135</ref>
      <ref url="http://secunia.com/advisories/17007" source="SECUNIA" adv="1">17007</ref>
      <ref url="http://secunia.com/advisories/16999" source="SECUNIA" adv="1">16999</ref>
      <ref url="http://secunia.com/advisories/15930" source="SECUNIA" adv="1">15930</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9986" source="OVAL">oval:org.mitre.oval:def:9986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net-snmp" name="net-snmp">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4_pre2" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
        <vers num="5.1.3" />
        <vers num="5.2" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2178" published="2005-07-11" name="CVE-2005-2178" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter.  NOTE: it is unclear which product or vendor this program is associated with, if any.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.badroot.org/advisories/SA0x06" source="MISC" adv="1">http://www.badroot.org/advisories/SA0x06</ref>
      <ref url="http://securitytracker.com/id?1014393" source="SECTRACK">1014393</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112059815028059&amp;w=2" source="BUGTRAQ" adv="1">20050705 [badroot security] probe.cgi: Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="probe.cgi" name="probe.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2179" published="2005-07-11" name="CVE-2005-2179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory-072005.php" source="MISC" adv="1">http://www.hardened-php.net/advisory-072005.php</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112067013827970&amp;w=2" source="BUGTRAQ" adv="1">20050706 Advisory 07/2005: Jaws Multiple Remote Code Execution Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1014395" source="SECTRACK">1014395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jaws" name="jaws">
        <vers num="0.5.0" />
        <vers num="0.5.0_beta1" />
        <vers num="0.5.0_beta2" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2180" published="2005-07-11" name="CVE-2005-2180" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112066901231154&amp;w=2" source="BUGTRAQ" adv="1">20050706 GNATS - gen-index</ref>
      <ref url="http://www.pi3.int.pl/adv/gnats.txt" source="MISC">http://www.pi3.int.pl/adv/gnats.txt</ref>
      <ref url="http://secunia.com/advisories/15963" source="SECUNIA">15963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnats">
        <vers num="4.0" />
        <vers num="4.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2181" published="2005-07-11" name="CVE-2005-2181" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21260" source="XF">sip-notify-message-spoof(21260)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Jul/1014406.html" source="SECTRACK">1014406</ref>
      <ref url="http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt" source="MISC" adv="1">http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112067698624686&amp;w=2" source="BUGTRAQ" adv="1">20050706 VoIP-Phones: Weakness in proccessing SIP-Notify-Messages</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="7940_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="7960_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2182" published="2005-07-11" name="CVE-2005-2182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21260" source="XF">sip-notify-message-spoof(21260)</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Jul/1014407.html" source="SECTRACK">1014407</ref>
      <ref url="http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt" source="MISC" adv="1">http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112067698624686&amp;w=2" source="BUGTRAQ" adv="1">20050706 VoIP-Phones: Weakness in proccessing SIP-Notify-Messages</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grandstream" name="budgetone">
        <vers num="100" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2183" published="2005-07-11" name="CVE-2005-2183" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15951" source="SECUNIA" adv="1">15951</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112067694016410&amp;w=2" source="BUGTRAQ" adv="1">20050706 PHPXMAIL - Authentication Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpxmail" name="phpxmail">
        <vers num="0.7" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2184" published="2005-07-11" name="CVE-2005-2184" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112069267700034&amp;w=2" source="BUGTRAQ" adv="1">20050706 eRoom Multiple Security Issues</ref>
      <ref url="http://secunia.com/advisories/15940" source="SECUNIA">15940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="eroom">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2185" published="2005-07-11" name="CVE-2005-2185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112069267700034&amp;w=2" source="BUGTRAQ" adv="1">20050706 eRoom Multiple Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="eroom">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2186" published="2005-07-11" name="CVE-2005-2186" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076813804503&amp;w=2" source="BUGTRAQ">20050706 Re: Re: McAfee Intrushield IPS Abuse</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112066594312876&amp;w=2" source="BUGTRAQ" adv="1">20050706 McAfee Intrushield IPS Abuse</ref>
      <ref url="http://securitytracker.com/id?1014422" source="SECTRACK">1014422</ref>
      <ref url="http://secunia.com/advisories/15961" source="SECUNIA">15961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="intrushield_security_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2187" published="2005-07-11" name="CVE-2005-2187" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076813804503&amp;w=2" source="BUGTRAQ">20050706 Re: Re: McAfee Intrushield IPS Abuse</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112066594312876&amp;w=2" source="BUGTRAQ" adv="1">20050706 McAfee Intrushield IPS Abuse</ref>
      <ref url="http://securitytracker.com/id?1014422" source="SECTRACK">1014422</ref>
      <ref url="http://secunia.com/advisories/15961" source="SECUNIA">15961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="intrushield_security_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2188" published="2005-07-11" name="CVE-2005-2188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076813804503&amp;w=2" source="BUGTRAQ">20050706 Re: Re: McAfee Intrushield IPS Abuse</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112066594312876&amp;w=2" source="BUGTRAQ" adv="1">20050706 McAfee Intrushield IPS Abuse</ref>
      <ref url="http://securitytracker.com/id?1014422" source="SECTRACK">1014422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="intrushield_security_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2189" published="2005-07-11" name="CVE-2005-2189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112075990621765&amp;w=2" source="BUGTRAQ" adv="1">20050707 Multiple vulnerabilities in Lantronix SLC console server</ref>
      <ref url="http://secunia.com/advisories/15979" source="SECUNIA">15979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lantronix" name="securelinx">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2190" published="2005-07-11" name="CVE-2005-2190" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112077057001064&amp;w=2" source="BUGTRAQ" adv="1">20050707 [Bday release] Comersus shopping cart has multiple Sql injection</ref>
      <ref url="http://securitytracker.com/id?1014419" source="SECTRACK">1014419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2191" published="2005-07-11" name="CVE-2005-2191" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112077057001064&amp;w=2" source="BUGTRAQ" adv="1">20050707 [Bday release] Comersus shopping cart has multiple Sql injection</ref>
      <ref url="http://www.securityfocus.com/bid/15251" source="BID">15251</ref>
      <ref url="http://securitytracker.com/id?1014419" source="SECTRACK">1014419</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/backoffice_mult_exp.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/backoffice_mult_exp.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2192" published="2005-07-11" name="CVE-2005-2192" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15954" source="SECUNIA">15954</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112075901100640&amp;w=2" source="BUGTRAQ" adv="1">20050707 SimplePHPBlog 0.4.0 &lt;= Remote Password Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_palmo" name="simple_php_blog">
        <vers num="0.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2193" published="2005-07-11" name="CVE-2005-2193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory-082005.php" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory-082005.php</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112084384928950&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050707 Advisory 08/2005: PunBB SQL Injection Vulnerability</ref>
      <ref url="http://www.punbb.org/" source="MISC">http://www.punbb.org/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0_alpha" />
        <vers num="1.0_beta1" />
        <vers num="1.0_beta2" />
        <vers num="1.0_beta3" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2194" published="2005-12-31" name="CVE-2005-2194" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related to source routing or loose source routing.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/Security-announce/2005/Jul/msg00000.html" source="APPLE">APPLE-SA-2005-07-12</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=301948" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=301948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2195" published="2005-07-18" name="CVE-2005-2195" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secway.org/Advisory/AD20050713.txt" source="MISC" patch="1" adv="1">http://secway.org/Advisory/AD20050713.txt</ref>
      <ref url="http://securitytracker.com/id?1014474" source="SECTRACK">1014474</ref>
      <ref url="http://secunia.com/advisories/16056" source="SECUNIA">16056</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112126999514361&amp;w=2" source="BUGTRAQ">20050713 APPLE Darwin Streaming Server Web Admin Remote Denial of Serivce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2196" published="2005-07-19" name="CVE-2005-2196" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14321" source="BID">14321</ref>
      <ref url="http://securitytracker.com/id?1014522" source="SECTRACK">1014522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="airport_card">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2197" published="2005-07-11" name="CVE-2005-2197" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014438" source="SECTRACK" adv="1">1014438</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=112098888903080&amp;w=2" source="FULLDISC" adv="1">20050710 ID Board 1.1.3 SQL Injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/14204" source="BID">14204</ref>
      <ref url="http://secunia.com/advisories/15976" source="SECUNIA">15976</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_board" name="id_board">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2198" published="2005-07-11" name="CVE-2005-2198" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://spid.adnx.net/index_en.html#log" source="CONFIRM">http://spid.adnx.net/index_en.html#log</ref>
      <ref url="http://securitytracker.com/id?1014437" source="SECTRACK">1014437</ref>
      <ref url="http://secunia.com/advisories/16022" source="SECUNIA" adv="1">16022</ref>
      <ref url="http://www.securityfocus.com/bid/14208" source="BID">14208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spid" name="spid">
        <vers num="1.0.1" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2199" published="2005-07-11" name="CVE-2005-2199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14209" source="BID">14209</ref>
      <ref url="http://securitytracker.com/id?1014436" source="SECTRACK">1014436</ref>
      <ref url="http://secunia.com/advisories/16011" source="SECUNIA">16011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skrypty" name="ppa_gallery">
        <vers num="0.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2200" published="2005-07-11" name="CVE-2005-2200" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf</ref>
      <ref url="http://securitytracker.com/id?1014429" source="SECTRACK" patch="1">1014429</ref>
      <ref url="http://secunia.com/advisories/15970" source="SECUNIA" patch="1" adv="1">15970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_2128">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_2636">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_3545">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2201" published="2005-07-11" name="CVE-2005-2201" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf</ref>
      <ref url="http://securitytracker.com/id?1014429" source="SECTRACK" patch="1">1014429</ref>
      <ref url="http://secunia.com/advisories/15970" source="SECUNIA" patch="1" adv="1">15970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_2128">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_2636">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_3545">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2202" published="2005-07-11" name="CVE-2005-2202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf</ref>
      <ref url="http://securitytracker.com/id?1014429" source="SECTRACK" patch="1">1014429</ref>
      <ref url="http://secunia.com/advisories/15970" source="SECUNIA" patch="1" adv="1">15970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_2128">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_2636">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
      <prod vendor="xerox" name="workcentre_3545">
        <vers num="0.001.04.044" edition="" />
        <vers num="0.001.04.044" edition=":pro_color" />
        <vers num="0.001.04.504" edition="" />
        <vers num="0.001.04.504" edition=":pro_color" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2203" published="2005-07-11" name="CVE-2005-2203" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://unix.freshmeat.net/projects/phpwishlist/?branch_id=53897&amp;release_id=200925" source="CONFIRM" patch="1">http://unix.freshmeat.net/projects/phpwishlist/?branch_id=53897&amp;release_id=200925</ref>
      <ref url="http://securitytracker.com/id?1014432" source="SECTRACK" patch="1">1014432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwishlist" name="phpwishlist">
        <vers num="0.1.10" />
        <vers num="0.1.11" />
        <vers num="0.1.12" />
        <vers num="0.1.13" />
        <vers num="0.1.14" />
        <vers num="0.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2204" published="2005-07-11" name="CVE-2005-2204" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/1040" source="VUPEN">ADV-2005-1040</ref>
      <ref url="http://securitytracker.com/id?1014433" source="SECTRACK">1014433</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112110963416714&amp;w=2" source="BUGTRAQ">20050711 Re: SiteMinder Multiple Vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112084050624959&amp;w=2" source="BUGTRAQ" adv="1">20050708 SiteMinder Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21305" source="XF">ca-siteminder-smpwservicescgi-xss(21305)</ref>
      <ref url="http://www.osvdb.org/17810" source="OSVDB">17810</ref>
      <ref url="http://www.osvdb.org/17809" source="OSVDB">17809</ref>
      <ref url="http://secunia.com/advisories/15956" source="SECUNIA">15956</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="etrust_siteminder">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2205" published="2005-07-11" name="CVE-2005-2205" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14182" source="BID">14182</ref>
      <ref url="http://www.osvdb.org/17784" source="OSVDB">17784</ref>
      <ref url="http://securitytracker.com/id?1014426" source="SECTRACK" adv="1">1014426</ref>
      <ref url="http://secunia.com/advisories/15981" source="SECUNIA" adv="1">15981</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jul/0097.html" source="BUGTRAQ" adv="1">20050705 PNG&amp;#402;J&amp;#402;E&amp;#402;&amp;#8220;&amp;#402;^+&amp;#8212;p&amp;#402;&amp;#402;O&amp;#8240;&amp;#402;X&amp;#402;N&amp;#402;&amp;#352;&amp;#402;v&amp;#402;g remote commands execution vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pngren" name="pngren">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2206" published="2005-07-11" name="CVE-2005-2206" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014418" source="SECTRACK" adv="1">1014418</ref>
      <ref url="http://digitalparadox.org/viewadvisories.ah?view=42" source="MISC" adv="1">http://digitalparadox.org/viewadvisories.ah?view=42</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elemental_software" name="cartwiz">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2207" published="2005-07-11" name="CVE-2005-2207" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014418" source="SECTRACK" adv="1">1014418</ref>
      <ref url="http://digitalparadox.org/viewadvisories.ah?view=42" source="MISC" adv="1">http://digitalparadox.org/viewadvisories.ah?view=42</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elemental_software" name="cartwiz">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2208" published="2005-07-11" name="CVE-2005-2208" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15933" source="SECUNIA">15933</ref>
      <ref url="http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=66" source="MISC">http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=66</ref>
      <ref url="http://securitytracker.com/id?1014412" source="SECTRACK">1014412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="privashare" name="privashare">
        <vers num="1.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2209" published="2005-07-11" name="CVE-2005-2209" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014409" source="SECTRACK" adv="1">1014409</ref>
      <ref url="http://secunia.com/advisories/15995" source="SECUNIA">15995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="capturix" name="scanshare">
        <vers num="1.06_build_50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2210" published="2005-07-11" name="CVE-2005-2210" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ihsteam.com/download/ihsexpl/dlm.c" source="MISC">http://www.ihsteam.com/download/ihsexpl/dlm.c</ref>
      <ref url="http://securitytracker.com/id?1014404" source="SECTRACK">1014404</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tonec_inc." name="internet_download_manager">
        <vers num="4.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2211" published="2005-07-11" name="CVE-2005-2211" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.sukria.net/packages/backup-manager/" source="CONFIRM" patch="1">http://www.sukria.net/packages/backup-manager/</ref>
      <ref url="http://secunia.com/advisories/15989" source="SECUNIA" patch="1" adv="1">15989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sukria" name="backup_manager">
        <vers num="0.5.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2212" published="2005-07-11" name="CVE-2005-2212" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.sukria.net/packages/backup-manager/" source="CONFIRM" patch="1">http://www.sukria.net/packages/backup-manager/</ref>
      <ref url="http://secunia.com/advisories/15989" source="SECUNIA" patch="1" adv="1">15989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sukria" name="backup_manager">
        <vers num="0.5.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2213" published="2005-07-11" name="CVE-2005-2213" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15987" source="SECUNIA" adv="1">15987</ref>
      <ref url="http://nbenoit.tuxfamily.org/projects/mmsrip/ChangeLog" source="CONFIRM">http://nbenoit.tuxfamily.org/projects/mmsrip/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mms_ripper" name="mms_ripper">
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.6.0" />
        <vers num="0.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2214" published="2005-07-11" name="CVE-2005-2214" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15955" source="SECUNIA">15955</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305142" source="MISC" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305142</ref>
      <ref url="http://www.securityfocus.com/bid/14173" source="BID">14173</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="apt-setup">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2215" published="2005-07-12" name="CVE-2005-2215" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x before 1.4.6 and 1.5 before 1.5beta3 allows remote attackers to inject arbitrary web script or HTML via a parameter in the page move template, a different vulnerability than CVE-2005-1888.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14181" source="BID" patch="1">14181</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=340290" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=340290</ref>
      <ref url="http://secunia.com/advisories/15950" source="SECUNIA" patch="1" adv="1">15950</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.5" />
        <vers num="1.4_beta6" />
        <vers num="1.5_alpha1" />
        <vers num="1.5_alpha2" />
        <vers num="1.5_beta1" />
        <vers num="1.5_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2216" published="2005-07-12" name="CVE-2005-2216" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014397" source="SECTRACK">1014397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photogal" name="photogal_photo_gallery">
        <vers prev="1" num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2217" published="2005-07-12" name="CVE-2005-2217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014396" source="SECTRACK">1014396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="craig_dansie" name="dansie_shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2218" published="2005-07-26" name="CVE-2005-2218" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden devices available to attackers, who can then bypass restrictions on a jailed process.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:17.devfs.asc" source="FREEBSD">FreeBSD-SA-05:17</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21451" source="XF">freebsd-devfs-gain-privileges(21451)</ref>
      <ref url="http://www.securityfocus.com/bid/14334" source="BID">14334</ref>
      <ref url="http://www.osvdb.org/18123" source="OSVDB">18123</ref>
      <ref url="http://securitytracker.com/id?1014536" source="SECTRACK">1014536</ref>
      <ref url="http://secunia.com/advisories/16145" source="SECUNIA">16145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
        <vers num="5.4" edition="releng" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2219" published="2005-07-12" name="CVE-2005-2219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014443" source="SECTRACK">1014443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="6.1_hotfix_2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2220" published="2005-07-12" name="CVE-2005-2220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp.  NOTE: the vendor has disputed this issue, saying that "Dragonfly Commerce does not allow for editing prices nor does it allow for viewing information about clients stored in the database except by the store owner and authorized staff as appointed in the store administration."  However, SecurityTracker claims that they have been able to confirm the problem.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.digitalparadox.org/viewadvisories.ah?view=46" source="MISC">http://www.digitalparadox.org/viewadvisories.ah?view=46</ref>
      <ref url="http://securitytracker.com/id?1014451" source="SECTRACK" adv="1">1014451</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112121930328341&amp;w=2" source="BUGTRAQ">20050712 Dragonfly Shopping Cart Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="incredible_interactive" name="dragonfly_commerce">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2221" published="2005-07-12" name="CVE-2005-2221" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6) key_mp, (7) searchtype, or (8) psearch parameters to dc_forum_Postslist.asp.  NOTE: the vendor has disputed this issue, saying that the error messages arise from invalid category and product numbers.  Assuming that this is the case, the issue still satisfies the CVE definition of "exposure."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.digitalparadox.org/viewadvisories.ah?view=46" source="MISC">http://www.digitalparadox.org/viewadvisories.ah?view=46</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112121930328341&amp;w=2" source="BUGTRAQ">20050712 Dragonfly Shopping Cart Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="incredible_interactive" name="dragonfly_commerce">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2222" published="2005-07-12" name="CVE-2005-2222" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014427" source="SECTRACK" patch="1">1014427</ref>
      <ref url="http://www.mailenable.com/professionalhistory.asp" source="CONFIRM">http://www.mailenable.com/professionalhistory.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2223" published="2005-07-12" name="CVE-2005-2223" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014427" source="SECTRACK" patch="1">1014427</ref>
      <ref url="http://www.mailenable.com/standardhistory.asp" source="CONFIRM">http://www.mailenable.com/standardhistory.asp</ref>
      <ref url="http://www.mailenable.com/professionalhistory.asp" source="CONFIRM">http://www.mailenable.com/professionalhistory.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
      </prod>
      <prod vendor="mailenable" name="mailenable_standard">
        <vers num="1.701" />
        <vers num="1.702" />
        <vers num="1.703" />
        <vers num="1.704" />
        <vers num="1.71" />
        <vers num="1.72" />
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2224" published="2005-07-12" name="CVE-2005-2224" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.spidynamics.com/spilabs/advisories/aspRCP.html" source="MISC" adv="1">http://www.spidynamics.com/spilabs/advisories/aspRCP.html</ref>
      <ref url="http://secunia.com/advisories/16005" source="SECUNIA" adv="1">16005</ref>
      <ref url="http://www.securityfocus.com/bid/14217" source="BID">14217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2225" published="2005-07-12" name="CVE-2005-2225" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation.  NOTE: it has been reported that Gaim is also affected, so this may be an issue in the protocol or MSN servers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.messenger-blog.com/?p=146" source="MISC" adv="1">http://www.messenger-blog.com/?p=146</ref>
      <ref url="http://www.digitalparadox.org/viewadvisories.ah?view=45" source="MISC" adv="1">http://www.digitalparadox.org/viewadvisories.ah?view=45</ref>
      <ref url="http://securitytracker.com/id?1014444" source="SECTRACK" adv="1">1014444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="msn_messenger_service">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2226" published="2005-07-12" name="CVE-2005-2226" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14225" source="BID" patch="1">14225</ref>
      <ref url="http://support.microsoft.com/default.aspx/kb/900930" source="MSKB" patch="1">900930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2227" published="2005-07-12" name="CVE-2005-2227" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\MAILSRV\Admin key, which allows local users to gain administrator privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14212" source="BID">14212</ref>
      <ref url="http://securitytracker.com/id?1014450" source="SECTRACK">1014450</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112120030308592&amp;w=2" source="BUGTRAQ" adv="1">20050712 SoftiaCom MailServer - Local Password Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softiacom" name="wmailserver">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2228" published="2005-07-12" name="CVE-2005-2228" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14207" source="BID">14207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bdc_enterprises" name="web_wiz_forums">
        <vers num="7.9" />
        <vers num="7.91" />
        <vers num="8.0_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2229" published="2005-07-12" name="CVE-2005-2229" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014449" source="SECTRACK">1014449</ref>
      <ref url="http://secunia.com/advisories/15983" source="SECUNIA">15983</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112110868021563&amp;w=2" source="BUGTRAQ">20050711 blogtorrent remote/local user password disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blog_torrent" name="blog_torrent">
        <vers prev="1" num="0.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2230" published="2005-07-12" name="CVE-2005-2230" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15977" source="SECUNIA" adv="1">15977</ref>
      <ref url="http://www.zataz.net/adviso/elmo-06272005.txt" source="MISC">http://www.zataz.net/adviso/elmo-06272005.txt</ref>
      <ref url="http://www.securityfocus.com/bid/14235" source="BID">14235</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elmo" name="elmo">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2_r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2231" published="2005-07-12" name="CVE-2005-2231" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16039" source="SECUNIA" adv="1">16039</ref>
      <ref url="http://www.debian.org/security/2005/dsa-761" source="DEBIAN">DSA-761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="high_availability_linux_project" name="heartbeat">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2232" published="2005-07-12" name="CVE-2005-2232" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13909" source="BID" patch="1">13909</ref>
      <ref url="http://secunia.com/advisories/15636" source="SECUNIA" patch="1" adv="1">15636</ref>
      <ref url="http://www.securityfocus.com/advisories/8816" source="CONFIRM" adv="1">http://www.securityfocus.com/advisories/8816</ref>
      <ref url="http://www.caughq.org/advisories/CAU-2005-0002.txt" source="MISC" adv="1">http://www.caughq.org/advisories/CAU-2005-0002.txt</ref>
      <ref url="http://securitytracker.com/id?1014132" source="SECTRACK">1014132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2233" published="2005-07-12" name="CVE-2005-2233" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13915" source="BID" patch="1">13915</ref>
      <ref url="http://www.security-focus.com/advisories/8684" source="CONFIRM" patch="1" adv="1">http://www.security-focus.com/advisories/8684</ref>
      <ref url="http://secunia.com/advisories/15636" source="SECUNIA" patch="1" adv="1">15636</ref>
      <ref url="http://www.caughq.org/advisories/CAU-2005-0006.txt" source="MISC" adv="1">http://www.caughq.org/advisories/CAU-2005-0006.txt</ref>
      <ref url="http://securitytracker.com/id?1014132" source="SECTRACK">1014132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.1l" />
        <vers num="5.2" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3_l" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2234" published="2005-07-12" name="CVE-2005-2234" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13914" source="BID" patch="1">13914</ref>
      <ref url="http://www.security-focus.com/advisories/8684" source="CONFIRM" patch="1" adv="1">http://www.security-focus.com/advisories/8684</ref>
      <ref url="http://secunia.com/advisories/15636" source="SECUNIA" patch="1" adv="1">15636</ref>
      <ref url="http://www.caughq.org/advisories/CAU-2005-0005.txt" source="MISC" adv="1">http://www.caughq.org/advisories/CAU-2005-0005.txt</ref>
      <ref url="http://securitytracker.com/id?1014132" source="SECTRACK">1014132</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2235" published="2005-07-12" name="CVE-2005-2235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13912" source="BID" patch="1">13912</ref>
      <ref url="http://www.security-focus.com/advisories/8819" source="CONFIRM" patch="1" adv="1">http://www.security-focus.com/advisories/8819</ref>
      <ref url="http://secunia.com/advisories/15636" source="SECUNIA" patch="1" adv="1">15636</ref>
      <ref url="http://www.caughq.org/advisories/CAU-2005-0004.txt" source="MISC" adv="1">http://www.caughq.org/advisories/CAU-2005-0004.txt</ref>
      <ref url="http://securitytracker.com/id?1014132" source="SECTRACK">1014132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.1l" />
        <vers num="5.2" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3_l" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2236" published="2005-07-12" name="CVE-2005-2236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13911" source="BID">13911</ref>
      <ref url="http://www.caughq.org/advisories/CAU-2005-0003.txt" source="MISC" adv="1">http://www.caughq.org/advisories/CAU-2005-0003.txt</ref>
      <ref url="http://securitytracker.com/id?1014132" source="SECTRACK">1014132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2237" published="2005-07-12" name="CVE-2005-2237" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13921" source="BID">13921</ref>
      <ref url="http://www.caughq.org/advisories/CAU-2005-0007.txt" source="MISC" adv="1">http://www.caughq.org/advisories/CAU-2005-0007.txt</ref>
      <ref url="http://securitytracker.com/id?1014132" source="SECTRACK">1014132</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2238" published="2005-07-12" name="CVE-2005-2238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014421" source="SECTRACK" patch="1">1014421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2239" published="2005-07-12" name="CVE-2005-2239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014413" source="SECTRACK">1014413</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oftpd" name="oftpd">
        <vers num="0.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2240" published="2005-07-12" name="CVE-2005-2240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">xpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via a symlink attack on the xpvm.trace.$user temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16040" source="SECUNIA" adv="1">16040</ref>
      <ref url="http://www.zataz.net/adviso/xpvm-06272005.txt" source="MISC">http://www.zataz.net/adviso/xpvm-06272005.txt</ref>
      <ref url="http://www.securityfocus.com/bid/14228" source="BID">14228</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1003" source="DEBIAN">DSA-1003</ref>
      <ref url="http://secunia.com/advisories/19251" source="SECUNIA">19251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpvm" name="xpvm">
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2241" published="2005-07-12" name="CVE-2005-2241" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml" source="CISCO" patch="1" adv="1">20050712 Cisco CallManager Memory Handling Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/14250" source="BID">14250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="call_manager">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2242" published="2005-07-12" name="CVE-2005-2242" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2) the CallManager (ccm.exe).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml" source="CISCO" patch="1" adv="1">20050712 Cisco CallManager Memory Handling Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/14252" source="BID">14252</ref>
      <ref url="http://www.securityfocus.com/bid/14251" source="BID">14251</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2243" published="2005-07-12" name="CVE-2005-2243" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumption) via a large number of Admin Service Tool (AST) logins that fail.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml" source="CISCO" patch="1" adv="1">20050712 Cisco CallManager Memory Handling Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/14253" source="BID">14253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="call_manager">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2244" published="2005-07-12" name="CVE-2005-2244" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml" source="CISCO" patch="1" adv="1">20050712 Cisco CallManager Memory Handling Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19053" source="XF">malloc-return-value-dos(19053)</ref>
      <ref url="http://www.securityfocus.com/bid/14255" source="BID">14255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="call_manager">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2245" published="2005-07-12" name="CVE-2005-2245" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014452" source="SECTRACK" patch="1">1014452</ref>
      <ref url="http://secunia.com/advisories/16008" source="SECUNIA" patch="1" adv="1">16008</ref>
      <ref url="http://www.securityfocus.com/bid/14215" source="BID">14215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="big-ip">
        <vers num="9.0.2" />
        <vers num="9.0.3" />
        <vers num="9.0.4" />
        <vers num="9.0.5" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2246" published="2005-07-12" name="CVE-2005-2246" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code via the (1) doc_path parameter to getpage.php or (2) set_menu parameter to lib/static/header.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014448" source="SECTRACK">1014448</ref>
      <ref url="http://www.securityfocus.com/bid/23189" source="BID">23189</ref>
      <ref url="http://www.securityfocus.com/bid/14229" source="BID">14229</ref>
      <ref url="http://www.milw0rm.com/exploits/3596" source="MILW0RM">3596</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001474.html" source="VIM">20070329 iPhotoAlbum v1.1(header.php)Remote File Include Vulnerability</ref>
      <ref url="http://secunia.com/advisories/16031" source="SECUNIA">16031</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2247" published="2005-07-12" name="CVE-2005-2247" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16028" source="SECUNIA" patch="1" adv="1">16028</ref>
      <ref url="http://moodle.org/doc/?frame=release.html" source="CONFIRM">http://moodle.org/doc/?frame=release.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.5" />
        <vers num="1.5_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2248" published="2005-07-13" name="CVE-2005-2248" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in DownloadProtect before 1.0.3 allows remote attackers to read files above the download folder.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16003" source="SECUNIA" patch="1" adv="1">16003</ref>
      <ref url="http://www.securityfocus.com/bid/14211" source="BID">14211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sven-ove_bjerkan" name="downloadprotect">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2249" published="2005-07-13" name="CVE-2005-2249" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Jinzora 2.0.1 have unknown impact and attack vectors, possibly involving a PHP file inclusion vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://freshmeat.net/projects/jinzora/?branch_id=43140&amp;release_id=200390" source="CONFIRM" patch="1">http://freshmeat.net/projects/jinzora/?branch_id=43140&amp;release_id=200390</ref>
      <ref url="http://secunia.com/advisories/15952" source="SECUNIA" adv="1">15952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jinzora" name="jinzora">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2250" published="2005-07-13" name="CVE-2005-2250" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14230" source="BID" patch="1">14230</ref>
      <ref url="http://affix.sourceforge.net/affix_212_sec.patch" source="CONFIRM" patch="1">http://affix.sourceforge.net/affix_212_sec.patch</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0712a%5D.txt" source="MISC" adv="1">http://www.digitalmunition.com/DMA%5B2005-0712a%5D.txt</ref>
      <ref url="http://www.debian.org/security/2005/dsa-762" source="DEBIAN">DSA-762</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="affix">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.3.0" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2251" published="2005-07-13" name="CVE-2005-2251" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014410" source="SECTRACK" adv="1">1014410</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29263" source="XF">phpsecurepages-secure-file-include(29263)</ref>
      <ref url="http://www.securityfocus.com/bid/14201" source="BID">14201</ref>
      <ref url="http://www.milw0rm.com/exploits/2452" source="MILW0RM">2452</ref>
      <ref url="http://secunia.com/advisories/15994" source="SECUNIA">15994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="secure_reality" name="phpsecurepages">
        <vers num="0.11_beta" />
        <vers num="0.12_beta" />
        <vers num="0.13_beta" />
        <vers num="0.14_beta" />
        <vers num="0.15_beta" />
        <vers num="0.16_beta" />
        <vers num="0.17_beta" />
        <vers num="0.18_beta" />
        <vers num="0.19_beta" />
        <vers num="0.20_beta" />
        <vers num="0.21_beta" />
        <vers num="0.22_beta" />
        <vers num="0.23_beta" />
        <vers num="0.24_beta" />
        <vers num="0.25_beta" />
        <vers num="0.26_beta" />
        <vers num="0.27_beta" />
        <vers num="0.28_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2252" published="2005-07-13" name="CVE-2005-2252" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014423" source="SECTRACK" adv="1">1014423</ref>
      <ref url="http://secunia.com/advisories/15967" source="SECUNIA">15967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gianluca_baldo" name="phpauction">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2253" published="2005-07-13" name="CVE-2005-2253" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014423" source="SECTRACK" adv="1">1014423</ref>
      <ref url="http://secunia.com/advisories/15967" source="SECUNIA">15967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gianluca_baldo" name="phpauction">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2254" published="2005-07-13" name="CVE-2005-2254" modified="2010-12-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php.  NOTE: there is evidence that viewnews.php and login.php may not be part of the PhpAuction product, so they are not included in this description.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014423" source="SECTRACK" adv="1">1014423</ref>
      <ref url="http://secunia.com/advisories/15967" source="SECUNIA" adv="1">15967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gianluca_baldo" name="phpauction">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2255" published="2005-07-13" name="CVE-2005-2255" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".."  sequences in the lan parameter to (1) index.php or (2) admin/index.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014423" source="SECTRACK" adv="1">1014423</ref>
      <ref url="http://secunia.com/advisories/15967" source="SECUNIA">15967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gianluca_baldo" name="phpauction">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2256" published="2005-07-13" name="CVE-2005-2256" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/88188a8c-eff6-11d9-8310-0001020eed82.html" source="MISC" adv="1">http://www.vuxml.org/freebsd/88188a8c-eff6-11d9-8310-0001020eed82.html</ref>
      <ref url="http://www.securityfocus.com/bid/14142" source="BID">14142</ref>
      <ref url="http://securitytracker.com/id?1014414" source="SECTRACK">1014414</ref>
      <ref url="http://secunia.com/advisories/15941" source="SECUNIA" adv="1">15941</ref>
      <ref url="http://www.debian.org/security/2005/dsa-759" source="DEBIAN">DSA-759</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=342261" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=342261</ref>
      <ref url="http://secunia.com/advisories/16116" source="SECUNIA">16116</ref>
      <ref url="http://archives.neohapsis.com/archives/dailydave/2005-q3/0010.html" source="MLIST">[Dailydave] 20050704 !!! pre-authenticated remote code inclusion vulnerability inside phppgadmin !!!</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phppgadmin" name="phppgadmin">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2257" published="2005-07-13" name="CVE-2005-2257" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15936" source="SECUNIA" patch="1" adv="1">15936</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076117708139&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050707 phpSlash account hijacking vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014415" source="SECTRACK">1014415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpslash" name="phpslash">
        <vers num="0.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2258" published="2005-07-13" name="CVE-2005-2258" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014447" source="SECTRACK">1014447</ref>
      <ref url="http://secunia.com/advisories/16009" source="SECUNIA" adv="1">16009</ref>
      <ref url="http://www.securityfocus.com/bid/14219" source="BID">14219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squitosoft" name="squito_gallery">
        <vers num="1.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2259" published="2005-07-13" name="CVE-2005-2259" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14179" source="BID">14179</ref>
      <ref url="http://securitytracker.com/id?1014411" source="SECTRACK" adv="1">1014411</ref>
      <ref url="http://secunia.com/advisories/15985" source="SECUNIA">15985</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usanet_creations" name="domain_name_auction">
        <vers num="" />
      </prod>
      <prod vendor="usanet_creations" name="makebid_auction_deluxe">
        <vers num="3.30" />
      </prod>
      <prod vendor="usanet_creations" name="makebid_auction_standard">
        <vers num="" />
      </prod>
      <prod vendor="usanet_creations" name="makebid_reverse_auction">
        <vers num="" />
      </prod>
      <prod vendor="usanet_creations" name="standard_classified_ads">
        <vers num="" />
      </prod>
      <prod vendor="usanet_creations" name="usanet_shopping_mall">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2260" published="2005-07-13" name="CVE-2005-2260" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-45.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-45.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10132" source="OVAL">oval:org.mitre.oval:def:10132</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html" source="MISC">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://secunia.com/advisories/16059" source="SECUNIA">16059</ref>
      <ref url="http://secunia.com/advisories/16044" source="SECUNIA">16044</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=289940" source="MISC">http://bugzilla.mozilla.org/show_bug.cgi?id=289940</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:742" source="OVAL" sig="1">oval:org.mitre.oval:def:742</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1226" source="OVAL" sig="1">oval:org.mitre.oval:def:1226</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100013" source="OVAL" sig="1">oval:org.mitre.oval:def:100013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2261" published="2005-07-13" name="CVE-2005-2261" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-46.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-46.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=292591" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=292591</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=292589" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=292589</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10947" source="OVAL">oval:org.mitre.oval:def:10947</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html" source="MISC">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/16059" source="SECUNIA">16059</ref>
      <ref url="http://secunia.com/advisories/16044" source="SECUNIA">16044</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:808" source="OVAL" sig="1">oval:org.mitre.oval:def:808</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1348" source="OVAL" sig="1">oval:org.mitre.oval:def:1348</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100012" source="OVAL" sig="1">oval:org.mitre.oval:def:100012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2262" published="2005-07-13" name="CVE-2005-2262" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-47.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-47.html</ref>
      <ref url="http://www.mikx.de/firewalling/" source="MISC">http://www.mikx.de/firewalling/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11097" source="OVAL">oval:org.mitre.oval:def:11097</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.securiteam.com/securitynews/5ZP0E0UGAK.html" source="MISC">http://www.securiteam.com/securitynews/5ZP0E0UGAK.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html" source="MISC">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://secunia.com/advisories/16044" source="SECUNIA">16044</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100011" source="OVAL" sig="1">oval:org.mitre.oval:def:100011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2263" published="2005-07-13" name="CVE-2005-2263" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-48.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-48.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=293331" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=293331</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11629" source="OVAL">oval:org.mitre.oval:def:11629</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://secunia.com/advisories/16059" source="SECUNIA">16059</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1311" source="OVAL" sig="1">oval:org.mitre.oval:def:1311</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1281" source="OVAL" sig="1">oval:org.mitre.oval:def:1281</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100016" source="OVAL" sig="1">oval:org.mitre.oval:def:100016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100010" source="OVAL" sig="1">oval:org.mitre.oval:def:100010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2264" published="2005-07-13" name="CVE-2005-2264" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-49.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-49.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=294074" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=294074</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9887" source="OVAL">oval:org.mitre.oval:def:9887</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100009" source="OVAL" sig="1">oval:org.mitre.oval:def:100009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2265" published="2005-07-13" name="CVE-2005-2265" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-50.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-50.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=295854" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=295854</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10397" source="OVAL">oval:org.mitre.oval:def:10397</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html" source="MISC">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/16059" source="SECUNIA">16059</ref>
      <ref url="http://secunia.com/advisories/16044" source="SECUNIA">16044</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:781" source="OVAL" sig="1">oval:org.mitre.oval:def:781</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:417" source="OVAL" sig="1">oval:org.mitre.oval:def:417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100008" source="OVAL" sig="1">oval:org.mitre.oval:def:100008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2266" published="2005-07-13" name="CVE-2005-2266" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-52.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-52.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/15549" source="SECUNIA">15549</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10712" source="OVAL">oval:org.mitre.oval:def:10712</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21332" source="XF">mozilla-frame-topfocus-xss(21332)</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/15553" source="SECUNIA">15553</ref>
      <ref url="http://secunia.com/advisories/15551" source="SECUNIA">15551</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:773" source="OVAL" sig="1">oval:org.mitre.oval:def:773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1415" source="OVAL" sig="1">oval:org.mitre.oval:def:1415</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100107" source="OVAL" sig="1">oval:org.mitre.oval:def:100107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2267" published="2005-07-13" name="CVE-2005-2267" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=298255" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=298255</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-53.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-53.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11334" source="OVAL">oval:org.mitre.oval:def:11334</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://securitytracker.com/id?1014469" source="SECTRACK">1014469</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1172" source="OVAL" sig="1">oval:org.mitre.oval:def:1172</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1073" source="OVAL" sig="1">oval:org.mitre.oval:def:1073</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100006" source="OVAL" sig="1">oval:org.mitre.oval:def:100006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2268" published="2005-07-13" name="CVE-2005-2268" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-54.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-54.html</ref>
      <ref url="http://secunia.com/advisories/15489" source="SECUNIA" patch="1" adv="1">15489</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10517" source="OVAL">oval:org.mitre.oval:def:10517</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1313" source="OVAL" sig="1">oval:org.mitre.oval:def:1313</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1268" source="OVAL" sig="1">oval:org.mitre.oval:def:1268</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100005" source="OVAL" sig="1">oval:org.mitre.oval:def:100005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2269" published="2005-07-13" name="CVE-2005-2269" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-55.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-55.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=298892" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=298892</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9777" source="OVAL">oval:org.mitre.oval:def:9777</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html" source="MISC">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/16059" source="SECUNIA">16059</ref>
      <ref url="http://secunia.com/advisories/16044" source="SECUNIA">16044</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:729" source="OVAL" sig="1">oval:org.mitre.oval:def:729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1258" source="OVAL" sig="1">oval:org.mitre.oval:def:1258</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100011" source="OVAL" sig="1">oval:org.mitre.oval:def:100011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100005" source="OVAL" sig="1">oval:org.mitre.oval:def:100005</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100004" source="OVAL" sig="1">oval:org.mitre.oval:def:100004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2270" published="2005-07-13" name="CVE-2005-2270" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/652366" source="CERT-VN">VU#652366</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-56.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-56.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=296397" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=296397</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=295011" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=295011</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=294799" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=294799</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=294795" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=294795</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1075" source="VUPEN">ADV-2005-1075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11751" source="OVAL">oval:org.mitre.oval:def:11751</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202" source="FEDORA">FLSA:160202</ref>
      <ref url="http://www.securityfocus.com/bid/14242" source="BID">14242</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-601.html" source="REDHAT">RHSA-2005:601</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-587.html" source="REDHAT">RHSA-2005:587</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-586.html" source="REDHAT">RHSA-2005:586</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html" source="SUSE">SUSE-SA:2005:045</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-252.shtml" source="CIAC">P-252</ref>
      <ref url="http://securitytracker.com/id?1014470" source="SECTRACK">1014470</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/16059" source="SECUNIA">16059</ref>
      <ref url="http://secunia.com/advisories/16043" source="SECUNIA">16043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:817" source="OVAL" sig="1">oval:org.mitre.oval:def:817</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:550" source="OVAL" sig="1">oval:org.mitre.oval:def:550</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100003" source="OVAL" sig="1">oval:org.mitre.oval:def:100003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2271" published="2005-07-13" name="CVE-2005-2271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/15477" source="SECUNIA" patch="1" adv="1">15477</ref>
      <ref url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_clauss" name="icab">
        <vers num="2.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2272" published="2005-07-13" name="CVE-2005-2272" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/2659" source="VUPEN">ADV-2005-2659</ref>
      <ref url="http://secunia.com/secunia_research/2005-12/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-12/advisory/</ref>
      <ref url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21070" source="XF">mozilla-javascript-dialog-box-spoofing(21070)</ref>
      <ref url="http://www.securityfocus.com/bid/14011" source="BID">14011</ref>
      <ref url="http://www.osvdb.org/17397" source="OSVDB">17397</ref>
      <ref url="http://securitytracker.com/id?1015294" source="SECTRACK">1015294</ref>
      <ref url="http://secunia.com/advisories/17813" source="SECUNIA">17813</ref>
      <ref url="http://secunia.com/advisories/15474" source="SECUNIA">15474</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=302847" source="APPLE">APPLE-SA-2005-11-29</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2273" published="2005-07-13" name="CVE-2005-2273" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Opera 7.x and 8 before 8.01 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref>
      <ref url="http://secunia.com/secunia_research/2005-8/" source="MISC">http://secunia.com/secunia_research/2005-8/</ref>
      <ref url="http://secunia.com/advisories/15488" source="SECUNIA">15488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.11b" />
        <vers num="7.11j" />
        <vers num="7.20" />
        <vers num="7.20_beta1_build2981" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.50" />
        <vers num="7.50b1" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" />
        <vers num="8.0_final_build_1095" />
        <vers num="8_beta_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2274" published="2005-07-13" name="CVE-2005-2274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/advisory/902333.mspx" source="MISC" adv="1">http://www.microsoft.com/technet/security/advisory/902333.mspx</ref>
      <ref url="http://secunia.com/secunia_research/2005-9/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-9/advisory/</ref>
      <ref url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/15492" source="SECUNIA" adv="1">15492</ref>
      <ref url="http://secunia.com/advisories/15491" source="SECUNIA" adv="1">15491</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2276" published="2005-07-26" name="CVE-2005-2276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&amp;#X41vascript" in an IMG tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21421" source="XF" patch="1">novell-groupwise-webaccess-xss(21421)</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098301.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098301.htm</ref>
      <ref url="http://secunia.com/advisories/16098/" source="SECUNIA" patch="1" adv="1">16098</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112181451014783&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050719 [ISR] - Novell Groupwise WebAccess Cross-Site Scripting</ref>
      <ref url="http://www.securityfocus.com/bid/14310" source="BID">14310</ref>
      <ref url="http://www.osvdb.org/18064" source="OSVDB">18064</ref>
      <ref url="http://www.infobyte.com.ar/adv/ISR-11.html" source="MISC">http://www.infobyte.com.ar/adv/ISR-11.html</ref>
      <ref url="http://securitytracker.com/id?1014515" source="SECTRACK">1014515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise_webaccess">
        <vers num="6.0" edition="sp4" />
        <vers num="6.5" edition="sp1" />
        <vers num="6.5" edition="sp2" />
        <vers num="6.5" edition="sp3" />
        <vers num="6.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2277" published="2005-07-15" name="CVE-2005-2277" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0712b%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0712b].txt</ref>
      <ref url="http://www.securityfocus.com/bid/14232" source="BID">14232</ref>
      <ref url="http://www.debian.org/security/2005/dsa-762" source="DEBIAN">DSA-762</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112119962704397&amp;w=2" source="BUGTRAQ">20050712 MA[2005-0712b] - 'Nokia Affix Bluetooth btsrv/btobex poor use of system()</ref>
      <ref url="http://affix.sourceforge.net/affix_320_sec.patch" source="CONFIRM">http://affix.sourceforge.net/affix_320_sec.patch</ref>
      <ref url="http://affix.sourceforge.net/affix_212_sec.patch" source="CONFIRM">http://affix.sourceforge.net/affix_212_sec.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="affix">
        <vers num="2.1.2" />
        <vers num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2278" published="2005-07-18" name="CVE-2005-2278" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=467&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=467&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112127188609993&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050712 CORE-2005-0629: MailEnable Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2279" published="2005-07-18" name="CVE-2005-2279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco ONS 15216 Optical Add/Drop Multiplexer (OADM) running firmware 2.2.2 and earlier allows remote attackers to cause a denial of service (management plane session loss) via crafted telnet data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050713-ons.shtml" source="CISCO" patch="1" adv="1">20050713 Cisco ONS 15216 OADM Telnet Denial-of-Service Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/14246" source="BID">14246</ref>
      <ref url="http://www.osvdb.org/17863" source="OSVDB">17863</ref>
      <ref url="http://securitytracker.com/id?1014475" source="SECTRACK">1014475</ref>
      <ref url="http://secunia.com/advisories/16073" source="SECUNIA">16073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15216_optical_add_drop_multiplexer">
        <vers prev="1" num="2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2280" published="2005-07-18" name="CVE-2005-2280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Security Agent (CSA) 4.5 allows remote attackers to cause a denial of service (system crash) via a crafted IP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21344" source="XF" patch="1">csa-ip-dos(21344)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050713-csa.shtml" source="CISCO" patch="1" adv="1">20050713 Cisco Security Agent Vulnerable to Crafted IP Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="security_agent">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2281" published="2005-07-18" name="CVE-2005-2281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/491770" source="CERT-VN" patch="1">VU#491770</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BWQDQ" source="CONFIRM">http://www.kb.cert.org/vuls/id/JGEI-6BWQDQ</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esi_products" name="webeoc">
        <vers prev="1" num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2282" published="2005-07-18" name="CVE-2005-2282" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before 6.0.2 allow remote attackers to inject arbitrary web script and HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/138538" source="CERT-VN" patch="1">VU#138538</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BVST4" source="CONFIRM">http://www.kb.cert.org/vuls/id/JGEI-6BVST4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esi_products" name="webeoc">
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2283" published="2005-07-18" name="CVE-2005-2283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/956762" source="CERT-VN" patch="1">VU#956762</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BWLER" source="CONFIRM">http://www.kb.cert.org/vuls/id/JGEI-6BWLER</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esi_products" name="webeoc">
        <vers prev="1" num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2284" published="2005-07-18" name="CVE-2005-2284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/372797" source="CERT-VN" patch="1">VU#372797</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6C8Q27" source="CONFIRM">http://www.kb.cert.org/vuls/id/JGEI-6C8Q27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esi_products" name="webeoc">
        <vers prev="1" num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2285" published="2005-07-18" name="CVE-2005-2285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Usernames, Passwords, Emergency information, medical information, and system configuration.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/165290" source="CERT-VN" patch="1">VU#165290</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BWPXL" source="CONFIRM">http://www.kb.cert.org/vuls/id/JGEI-6BWPXL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esi_products" name="webeoc">
        <vers prev="1" num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2286" published="2005-07-18" name="CVE-2005-2286" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/258834" source="CERT-VN" patch="1">VU#258834</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6BWLWG" source="CONFIRM">http://www.kb.cert.org/vuls/id/JGEI-6BWLWG</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esi_products" name="webeoc">
        <vers prev="1" num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2287" published="2005-07-18" name="CVE-2005-2287" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112122500308722&amp;w=2" source="BUGTRAQ" adv="1">20050712 SoftiaCom MailServer v2.0 - Denial Of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softiacom" name="wmailserver">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2288" published="2005-07-18" name="CVE-2005-2288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPCounter 7.2 allows remote attackers to inject arbitrary web script or HTML via the EpochPrefix parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14256" source="BID">14256</ref>
      <ref url="http://securitytracker.com/id?1014478" source="SECTRACK">1014478</ref>
      <ref url="http://secunia.com/advisories/15816" source="SECUNIA" adv="1">15816</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129495128834&amp;w=2" source="BUGTRAQ" adv="1">20050713 Path Disclosure and XSS problem in PHP Counter 7.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcounter" name="phpcounter">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2289" published="2005-07-18" name="CVE-2005-2289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHPCounter 7.2 allows remote attackers to obtain sensitive information via a direct request to prelims.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014478" source="SECTRACK">1014478</ref>
      <ref url="http://secunia.com/advisories/15816" source="SECUNIA" adv="1">15816</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129495128834&amp;w=2" source="BUGTRAQ" adv="1">20050713 Path Disclosure and XSS problem in PHP Counter 7.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcounter" name="phpcounter">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2290" published="2005-07-18" name="CVE-2005-2290" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and (2) cat variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14245" source="BID">14245</ref>
      <ref url="http://securitytracker.com/id?1014480" source="SECTRACK">1014480</ref>
      <ref url="http://secunia.com/advisories/15780" source="SECUNIA">15780</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112128870110418&amp;w=2" source="BUGTRAQ" adv="1">20050713 WPS Web-Portal-System v.0.7.0 (wps_shop.cgi) remote commands</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2291" published="2005-07-18" name="CVE-2005-2291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.red-database-security.com/advisory/oracle_jdeveloper_passes_plaintext_password.html" source="MISC" patch="1" adv="1">http://www.red-database-security.com/advisory/oracle_jdeveloper_passes_plaintext_password.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129082323341&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050713 Advisory: Oracle JDeveloper passes Plaintext Password</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdeveloper">
        <vers num="10.1.2" />
        <vers num="9.0.4" />
        <vers num="9.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2292" published="2005-07-18" name="CVE-2005-2292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21342" source="XF" patch="1">jdeveloper-config-plaintext-password(21342)</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html</ref>
      <ref url="http://secunia.com/advisories/15991/" source="SECUNIA" patch="1" adv="1">15991</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_jdeveloper_plaintext_password.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_jdeveloper_plaintext_password.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129177927502&amp;w=2" source="BUGTRAQ" adv="1">20050713 Advisory: Oracle JDeveloper Plaintext Passwords</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdeveloper">
        <vers num="10.1.2" />
        <vers num="9.0.4" />
        <vers num="9.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2293" published="2005-07-18" name="CVE-2005-2293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is used, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21343" source="XF" patch="1">formsbuilder-temp-file-plaintext-password(21343)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_formsbuilder_temp_file_issue.html" source="MISC" patch="1" adv="1">http://www.red-database-security.com/advisory/oracle_formsbuilder_temp_file_issue.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html</ref>
      <ref url="http://secunia.com/advisories/15991/" source="SECUNIA" patch="1" adv="1">15991</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129452232307&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050713 Advisory: Oracle Forms Builder Password in Temp Files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="forms_builder">
        <vers num="9.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2294" published="2005-07-18" name="CVE-2005-2294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21347" source="XF" patch="1">formsbuilder-temp-file-info-disclosure(21347)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_forms_unsecure_temp_file_handling.html" source="MISC" patch="1" adv="1">http://www.red-database-security.com/advisory/oracle_forms_unsecure_temp_file_handling.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html</ref>
      <ref url="http://secunia.com/advisories/15991/" source="SECUNIA" patch="1" adv="1">15991</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129398711846&amp;w=2" source="BUGTRAQ" adv="1">20050713 Advisory: Oracle Forms Insecure Temporary File Handling</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="forms">
        <vers num="4.5" />
        <vers num="6.0" />
        <vers num="6i" />
        <vers num="9i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2295" published="2005-07-18" name="CVE-2005-2295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21361" source="XF" patch="1">netpanzer-datablock-dos(21361)</ref>
      <ref url="http://aluigi.altervista.org/adv/panzone-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/panzone-adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/14257" source="BID">14257</ref>
      <ref url="http://securitytracker.com/id?1014479" source="SECTRACK">1014479</ref>
      <ref url="http://secunia.com/advisories/16055" source="SECUNIA">16055</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129258221823&amp;w=2" source="BUGTRAQ">20050713 Endless loop in NetPanzer 0.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pyrosoft_inc" name="netpanzer">
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2296" published="2005-07-18" name="CVE-2005-2296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112137300014760&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050714 YaBBSe 1.5.5c Path disclosure problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.5c" edition="" />
        <vers num="1.5.5c" edition=":second_edition" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2297" published="2005-07-19" name="CVE-2005-2297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.sybase.com/detail?id=1036742" source="CONFIRM" patch="1" adv="1">http://www.sybase.com/detail?id=1036742</ref>
      <ref url="http://www.spidynamics.com/spilabs/advisories/sybaseEAserverOverflow.htm" source="MISC" patch="1" adv="1">http://www.spidynamics.com/spilabs/advisories/sybaseEAserverOverflow.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112146180532313&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050715 Stack-Based Buffer Overflow in Sybase EAServer 4.2.5 to 5.2</ref>
      <ref url="http://securitytracker.com/id?1014497" source="SECTRACK">1014497</ref>
      <ref url="http://secunia.com/advisories/16108" source="SECUNIA">16108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="easerver">
        <vers num="4.2.5" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2298" published="2005-07-19" name="CVE-2005-2298" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning afterwards.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112137542212322&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050714 05_07_14-bitdefender_malicious_content_bypass</ref>
      <ref url="http://securitytracker.com/id?1014495" source="SECTRACK">1014495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softwin" name="bitdefender_engine">
        <vers prev="1" num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2299" published="2005-07-19" name="CVE-2005-2299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14266" source="BID">14266</ref>
      <ref url="http://securitytracker.com/id?1014494" source="SECTRACK">1014494</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112137585701087&amp;w=2" source="BUGTRAQ">20050714 XSS in forums Simple Message Board Version 2.0 Beta 1</ref>
      <ref url="http://www.securityfocus.com/bid/14269" source="BID">14269</ref>
      <ref url="http://www.securityfocus.com/bid/14268" source="BID">14268</ref>
      <ref url="http://www.securityfocus.com/bid/14267" source="BID">14267</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2300" published="2005-07-19" name="CVE-2005-2300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zone-h.org/advisories/read/id=7808" source="MISC" adv="1">http://www.zone-h.org/advisories/read/id=7808</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112156036013818&amp;w=2" source="BUGTRAQ" adv="1">20050716 [ZH2005-16SA] Insecure temporary file creation in Skype for Linux</ref>
      <ref url="http://secunia.com/advisories/16105" source="SECUNIA">16105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skype_technologies" name="skype">
        <vers prev="1" num="1.1.0.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2301" published="2005-07-19" name="CVE-2005-2301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112155941310297&amp;w=2" source="BUGTRAQ" patch="1">20050716 PowerDNS 2.9.18 fixes two security issues affecting users of LDAP</ref>
      <ref url="http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18" source="CONFIRM">http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18</ref>
      <ref url="http://www.securityfocus.com/bid/14290" source="BID">14290</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://securitytracker.com/id?1014504" source="SECTRACK">1014504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerdns" name="powerdns">
        <vers num="2.9.0" />
        <vers num="2.9.1" />
        <vers num="2.9.10" />
        <vers num="2.9.11" />
        <vers num="2.9.12" />
        <vers num="2.9.13" />
        <vers num="2.9.14" />
        <vers num="2.9.15" />
        <vers num="2.9.16" />
        <vers num="2.9.17" />
        <vers num="2.9.2" />
        <vers num="2.9.3a" />
        <vers num="2.9.4" />
        <vers num="2.9.5" />
        <vers num="2.9.6" />
        <vers num="2.9.7" />
        <vers num="2.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2302" published="2005-07-19" name="CVE-2005-2302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112155941310297&amp;w=2" source="BUGTRAQ" patch="1">20050716 PowerDNS 2.9.18 fixes two security issues affecting users of LDAP</ref>
      <ref url="http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18" source="CONFIRM">http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://securitytracker.com/id?1014504" source="SECTRACK">1014504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerdns" name="powerdns">
        <vers num="2.9.0" />
        <vers num="2.9.1" />
        <vers num="2.9.10" />
        <vers num="2.9.11" />
        <vers num="2.9.12" />
        <vers num="2.9.13" />
        <vers num="2.9.14" />
        <vers num="2.9.15" />
        <vers num="2.9.16" />
        <vers num="2.9.17" />
        <vers num="2.9.2" />
        <vers num="2.9.3a" />
        <vers num="2.9.4" />
        <vers num="2.9.5" />
        <vers num="2.9.6" />
        <vers num="2.9.7" />
        <vers num="2.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-2303" reject="1" published="2005-07-19" name="CVE-2005-2303" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1218.  Reason: This candidate is a duplicate of CVE-2005-1218.  Notes: All CVE users should reference CVE-2005-1218 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <exception />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2304" published="2005-07-19" name="CVE-2005-2304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14288" source="BID">14288</ref>
      <ref url="http://www.securityfocus.com/archive/1/405377" source="BUGTRAQ">20050716 Internet Explorer / MSN ICC Profiles Crash PoC Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" />
      </prod>
      <prod vendor="microsoft" name="live_messenger">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2305" published="2005-07-19" name="CVE-2005-2305" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via a long message to TCP port 1071 or 1073, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14263" source="BID">14263</ref>
      <ref url="http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=72" source="MISC">http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=72</ref>
      <ref url="http://secunia.com/advisories/16070" source="SECUNIA">16070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dg" name="remote_control_server">
        <vers num="1.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2306" published="2005-07-19" name="CVE-2005-2306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb05-05.html" source="CONFIRM" patch="1">http://www.macromedia.com/devnet/security/security_zone/mpsb05-05.html</ref>
      <ref url="http://secunia.com/advisories/16081" source="SECUNIA" patch="1" adv="1">16081</ref>
      <ref url="http://securitytracker.com/id?1014489" source="SECTRACK">1014489</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="6.1" />
        <vers num="7.0" />
      </prod>
      <prod vendor="macromedia" name="jrun">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2307" published="2005-07-19" name="CVE-2005-2307" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14260" source="BID">14260</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-045.mspx" source="MS">MS05-045</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf</ref>
      <ref url="http://secunia.com/advisories/17223" source="SECUNIA">17223</ref>
      <ref url="http://secunia.com/advisories/17172" source="SECUNIA">17172</ref>
      <ref url="http://secunia.com/advisories/16065" source="SECUNIA" adv="1">16065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:786" source="OVAL" sig="1">oval:org.mitre.oval:def:786</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1532" source="OVAL" sig="1">oval:org.mitre.oval:def:1532</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1289" source="OVAL" sig="1">oval:org.mitre.oval:def:1289</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1254" source="OVAL" sig="1">oval:org.mitre.oval:def:1254</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1250" source="OVAL" sig="1">oval:org.mitre.oval:def:1250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2308" published="2005-07-19" name="CVE-2005-2308" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost.jpg, (3) oom_dos.jpg, or (4) random.jpg.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14286" source="BID">14286</ref>
      <ref url="http://www.securityfocus.com/bid/14285" source="BID">14285</ref>
      <ref url="http://www.securityfocus.com/bid/14284" source="BID">14284</ref>
      <ref url="http://www.securityfocus.com/archive/1/405298" source="BUGTRAQ">20050715 Compromising pictures of Microsoft Internet Explorer!</ref>
      <ref url="http://lcamtuf.coredump.cx/crash" source="MISC">http://lcamtuf.coredump.cx/crash</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2309" published="2005-07-19" name="CVE-2005-2309" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 8.01 allows remote attackers to cause a denial of service (CPU consumption) via a crafted JPEG image, as demonstrated using random.jpg.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/405524/30/0/threaded" source="BUGTRAQ">20050718 Re: Compromising pictures of Microsoft Internet Explorer!</ref>
      <ref url="http://www.securityfocus.com/archive/1/405298" source="BUGTRAQ">20050715 Compromising pictures of Microsoft Internet Explorer!</ref>
      <ref url="http://lcamtuf.coredump.cx/crash" source="MISC">http://lcamtuf.coredump.cx/crash</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="8.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2310" published="2005-07-19" name="CVE-2005-2310" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.winamp.com/player/version_history.php" source="CONFIRM">http://www.winamp.com/player/version_history.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1106" source="VUPEN">ADV-2005-1106</ref>
      <ref url="http://www.securityfocus.com/bid/14276" source="BID">14276</ref>
      <ref url="http://www.osvdb.org/17897" source="OSVDB">17897</ref>
      <ref url="http://securitytracker.com/id?1014483" source="SECTRACK">1014483</ref>
      <ref url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-07-14" source="MISC" adv="1">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-07-14</ref>
      <ref url="http://secunia.com/advisories/16077" source="SECUNIA" adv="1">16077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.03a" />
        <vers num="5.09" />
        <vers num="5.091" />
        <vers prev="1" num="5.093" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2311" published="2005-07-19" name="CVE-2005-2311" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SMS 1.9.2m and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) request1 or (2) request2 temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16038" source="SECUNIA" adv="1">16038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sms" name="sms">
        <vers prev="1" num="1.9.2m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2312" published="2005-07-19" name="CVE-2005-2312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">management.php in Realnode Emilda 1.2.2 and earlier allows remote attackers to perform actions as other users by modifying the user_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14244" source="BID" patch="1">14244</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=338551" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=338551</ref>
      <ref url="http://secunia.com/advisories/15857" source="SECUNIA">15857</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnode" name="emilda">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2_alpha" />
        <vers num="1.2_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2313" published="2005-07-19" name="CVE-2005-2313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Check Point SecuRemote NG with Application Intelligence R54 allows attackers to obtain credentials and gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14221" source="BID">14221</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2314" published="2005-07-19" name="CVE-2005-2314" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the password in the response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14222" source="BID" patch="1">14222</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1101" source="VUPEN">ADV-2005-1101</ref>
      <ref url="http://secunia.com/advisories/15879" source="SECUNIA" adv="1">15879</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0507-exploits/phpsftpd.txt" source="MISC" adv="1">http://packetstorm.linuxsecurity.com/0507-exploits/phpsftpd.txt</ref>
      <ref url="http://securitytracker.com/id?1014481" source="SECTRACK">1014481</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2005/07/msg00209.html" source="BUGTRAQ">20050713 PHPsFTPd - Admin password leak</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsftpd" name="phpsftpd">
        <vers num="0.2" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2315" published="2005-12-31" name="CVE-2005-2315" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to execute arbitrary code via a large number of large DNS packets with the Z and QR flags cleared.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.19.1
This vulnerability affects all versions of dnrd prior to 2.19.1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=482568" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=482568</ref>
      <ref url="http://secunia.com/advisories/16142" source="SECUNIA" patch="1" adv="1">16142</ref>
      <ref url="http://www.FreeBSD.org/ports/portaudit/e72fd82b-fa01-11d9-bc08-0001020eed82.html" source="CONFIRM">http://www.FreeBSD.org/ports/portaudit/e72fd82b-fa01-11d9-bc08-0001020eed82.html</ref>
      <ref url="http://securitytracker.com/id?1014557" source="SECTRACK">1014557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnrd" name="dnrd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.10" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2316" published="2005-12-31" name="CVE-2005-2316" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to cause a denial of service (infinite recursion) via a DNS packet that uses message compression in the QNAME and two pointers that point to each other (circular buffer).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=482568" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=482568</ref>
      <ref url="http://secunia.com/advisories/16142" source="SECUNIA" patch="1" adv="1">16142</ref>
      <ref url="http://www.FreeBSD.org/ports/portaudit/e72fd82b-fa01-11d9-bc08-0001020eed82.html" source="CONFIRM">http://www.FreeBSD.org/ports/portaudit/e72fd82b-fa01-11d9-bc08-0001020eed82.html</ref>
      <ref url="http://securitytracker.com/id?1014557" source="SECTRACK">1014557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnrd" name="dnrd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.10" />
        <vers num="2.11" />
        <vers num="2.12" />
        <vers num="2.12.1" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.15" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.17.1" />
        <vers num="2.17.2" />
        <vers num="2.18" />
        <vers num="2.19" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2317" published="2005-07-19" name="CVE-2005-2317" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC address to bypass other firewall rules or policies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://shorewall.net/News.htm#20050717" source="CONFIRM" patch="1" adv="1">http://shorewall.net/News.htm#20050717</ref>
      <ref url="http://secunia.com/advisories/16087" source="SECUNIA" patch="1" adv="1">16087</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Jul/0409.html" source="FULLDISC" patch="1" adv="1">20050718 Shorewall MACLIST Problem</ref>
      <ref url="http://www.ubuntu.com/usn/usn-197-1" source="UBUNTU">USN-197-1</ref>
      <ref url="http://www.securityfocus.com/bid/14292" source="BID">14292</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-20.xml" source="GENTOO">GLSA-200507-20</ref>
      <ref url="http://www.debian.org/security/2005/dsa-849" source="DEBIAN">DSA-849</ref>
      <ref url="http://secunia.com/advisories/17113" source="SECUNIA">17113</ref>
      <ref url="http://secunia.com/advisories/17110" source="SECUNIA">17110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shorewall" name="shorewall">
        <vers num="2.0.0" />
        <vers num="2.0.0a" />
        <vers num="2.0.0b" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.2" />
        <vers num="2.0.2a" />
        <vers num="2.0.2b" />
        <vers num="2.0.2c" />
        <vers num="2.0.2d" />
        <vers num="2.0.2e" />
        <vers num="2.0.2f" />
        <vers num="2.0.3" />
        <vers num="2.0.3a" />
        <vers num="2.0.3b" />
        <vers num="2.0.3c" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4.0" />
        <vers num="2.4.0_rc1" />
        <vers num="2.4.0_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2318" published="2005-07-19" name="CVE-2005-2318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14223" source="BID">14223</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dvbbs" name="dvbbs">
        <vers num="7.1" />
        <vers num="7.1_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2319" published="2005-07-19" name="CVE-2005-2319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14237" source="BID" patch="1">14237</ref>
      <ref url="http://www.securityfocus.com/archive/1/404948" source="BUGTRAQ" patch="1" adv="1">20050712 Advisory 10/2005: Yawp/YaWiki Remote URL Include Vulnerability</ref>
      <ref url="http://www.hardened-php.net/advisory-102005.php" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory-102005.php</ref>
      <ref url="http://phpyawp.com/yawiki/index.php?page=ChangeLog" source="CONFIRM">http://phpyawp.com/yawiki/index.php?page=ChangeLog</ref>
      <ref url="http://secunia.com/advisories/16049" source="SECUNIA">16049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yawp" name="yawp">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2320" published="2005-07-19" name="CVE-2005-2320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14072" source="BID" patch="1">14072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="0.9.11" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.19" />
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
        <vers num="0.9.24" />
        <vers num="0.9.25" />
        <vers num="0.9.26" />
        <vers num="0.9.27" />
        <vers num="0.9.28" />
        <vers num="0.9.29" />
        <vers num="0.9.30" />
        <vers num="0.9.31" />
        <vers num="0.9.32" />
        <vers num="0.9.33" />
        <vers num="0.9.34" />
        <vers num="0.9.35" />
        <vers num="0.9.36" />
        <vers num="0.9.37" />
        <vers num="0.9.38" />
        <vers num="0.9.39" />
        <vers num="0.9.40" />
        <vers num="0.9.41" />
        <vers num="0.9.42" />
        <vers num="0.9.43" />
        <vers num="0.9.44" />
        <vers num="0.9.45" />
        <vers num="0.9.50" />
        <vers num="0.9.8" />
        <vers num="1.0.0" edition="rc1" />
        <vers num="1.0.0" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2321" published="2005-07-19" name="CVE-2005-2321" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in CaLogic 1.2.2 allows remote attackers to execute arbitrary code via the CLPATH parameter to (1) cl_minical.php, (2) clmcpreload.php, (3) mcconfig.php, or (4) mcpi-demo.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16090" source="SECUNIA" patch="1" adv="1">16090</ref>
      <ref url="http://www.securityfocus.com/bid/14296" source="BID">14296</ref>
      <ref url="http://www.calogic.de/modules/newbb/viewtopic.php?topic_id=333&amp;forum=7" source="CONFIRM">http://www.calogic.de/modules/newbb/viewtopic.php?topic_id=333&amp;forum=7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calogic" name="calogic">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2322" published="2005-07-19" name="CVE-2005-2322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser_id or (2) group parameter to users.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14261" source="BID">14261</ref>
      <ref url="http://securitytracker.com/id?1014486" source="SECTRACK">1014486</ref>
      <ref url="http://securitytracker.com/id?1014485" source="SECTRACK">1014485</ref>
      <ref url="http://secunia.com/advisories/16078" source="SECUNIA" adv="1">16078</ref>
      <ref url="http://lostmon.blogspot.com/2005/07/class-1-forum-software-cross-site.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/07/class-1-forum-software-cross-site.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="class-1" name="class-1_forum">
        <vers num="0.23.2" />
        <vers num="0.24.4" />
      </prod>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2323" published="2005-07-19" name="CVE-2005-2323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014486" source="SECTRACK">1014486</ref>
      <ref url="http://securitytracker.com/id?1014485" source="SECTRACK">1014485</ref>
      <ref url="http://secunia.com/advisories/16078" source="SECUNIA" adv="1">16078</ref>
      <ref url="http://lostmon.blogspot.com/2005/07/class-1-forum-software-cross-site.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/07/class-1-forum-software-cross-site.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="class-1" name="class-1_forum">
        <vers num="0.23.2" />
        <vers num="0.24.4" />
      </prod>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2324" published="2005-07-19" name="CVE-2005-2324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the searchtype or searchterm parameters to (1) results.php or (2) categorysearch.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="2.0" />
        <vers num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2325" published="2005-07-19" name="CVE-2005-2325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Clever Copy 2.0 and 2.0a allows remote attackers to obtain the full path of the web root via a direct request to (1) ticker.php, (2) menu.php, (3) banned.php, (4) endlayout.php, (5) randomhlinesblock.php, (6) showlast.php, (7) showlast5class1.php, (8) showlast5phorum.php, (9) showlast5phorumblock.php, (10) showlastforumbb2.php, or (11) showlastforumbb2block.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="2.0" />
        <vers num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2326" published="2005-07-19" name="CVE-2005-2326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lostmon.blogspot.com/2005/07/clever-copy-calendarphp-yr-variable.html" source="MISC" adv="1">http://lostmon.blogspot.com/2005/07/clever-copy-calendarphp-yr-variable.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="2.0" />
        <vers num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2327" published="2005-07-20" name="CVE-2005-2327" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014513" source="SECTRACK">1014513</ref>
      <ref url="http://milw0rm.com/exploits/1106" source="MILW0RM">1106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.547_beta" />
        <vers num="0.548_beta" />
        <vers num="0.549_beta" />
        <vers num="0.551_beta" />
        <vers num="0.552_beta" />
        <vers num="0.553_beta" />
        <vers num="0.554_beta" />
        <vers num="0.555_beta" />
        <vers num="0.600" />
        <vers num="0.601" />
        <vers num="0.602" />
        <vers num="0.603" />
        <vers num="0.604" />
        <vers num="0.605" />
        <vers num="0.606" />
        <vers num="0.607" />
        <vers num="0.608" />
        <vers num="0.609" />
        <vers num="0.610" />
        <vers num="0.611" />
        <vers num="0.612" />
        <vers num="0.613" />
        <vers num="0.614" />
        <vers num="0.615a" />
        <vers num="0.616" />
        <vers num="0.617" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.1" />
        <vers num="5.21" />
        <vers num="5.3_beta" />
        <vers num="5.3_beta2" />
        <vers num="5.4_beta1" />
        <vers num="5.4_beta3" />
        <vers num="5.4_beta4" />
        <vers num="5.4_beta5" />
        <vers num="5.4_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2328" published="2005-07-20" name="CVE-2005-2328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14264" source="BID" patch="1">14264</ref>
      <ref url="http://laffer.sourceforge.net/cgi-bin/index.pl?page=news&amp;key=373747410" source="CONFIRM" patch="1">http://laffer.sourceforge.net/cgi-bin/index.pl?page=news&amp;key=373747410</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1235463&amp;group_id=101249&amp;atid=629313" source="MISC">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1235463&amp;group_id=101249&amp;atid=629313</ref>
    </refs>
    <vuln_soft>
      <prod vendor="laffer" name="laffer">
        <vers num="0.3.2.6" />
        <vers num="0.3.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2329" published="2005-07-20" name="CVE-2005-2329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to access the consoles of other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14300" source="BID">14300</ref>
      <ref url="http://www.securityfocus.com/archive/1/405546" source="BUGTRAQ" adv="1">20050718 MRV In-Reach console server: Port Access Control Bypass Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014517" source="SECTRACK">1014517</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2330" published="2005-07-20" name="CVE-2005-2330" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25861" source="XF">oscommerce-extrasupdate-info-disclosure(25861)</ref>
      <ref url="http://www.securityfocus.com/bid/14294" source="BID">14294</ref>
      <ref url="http://www.securityfocus.com/archive/1/431068" source="BUGTRAQ">20060414 RE: osCommerce "extras/" information/source code disclosure</ref>
      <ref url="http://www.securityfocus.com/archive/1/431012" source="BUGTRAQ">20060414 osCommerce "extras/" information/source code disclosure</ref>
      <ref url="http://www.osvdb.org/18249" source="OSVDB">18249</ref>
      <ref url="http://www.oscommerce.com/community/bugs,2835" source="MISC">http://www.oscommerce.com/community/bugs,2835</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_id=12318248" source="MISC">http://sourceforge.net/mailarchive/message.php?msg_id=12318248</ref>
      <ref url="http://securitytracker.com/id?1015944" source="SECTRACK">1015944</ref>
      <ref url="http://retrogod.altervista.org/oscommerce_22_adv.html" source="MISC">http://retrogod.altervista.org/oscommerce_22_adv.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="oscommerce">
        <vers num="2.2_ms2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2331" published="2005-07-20" name="CVE-2005-2331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in display.php in MooseGallery allows remote attackers to execute arbitrary PHP code via the type parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21388" source="XF">moosegallery-display-file-include(21388)</ref>
      <ref url="http://www.securityfocus.com/bid/14280" source="BID">14280</ref>
      <ref url="http://securitytracker.com/id?1014487" source="SECTRACK">1014487</ref>
      <ref url="http://secunia.com/advisories/16093" source="SECUNIA" adv="1">16093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moosegallery" name="moosegallery">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2332" published="2005-07-20" name="CVE-2005-2332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014510" source="SECTRACK">1014510</ref>
      <ref url="http://secunia.com/advisories/16110" source="SECUNIA" adv="1">16110</ref>
      <ref url="http://www.securityfocus.com/bid/14318" source="BID">14318</ref>
      <ref url="http://www.securityfocus.com/bid/14314" source="BID">14314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php.warpedweb.net" name="phppageprotect">
        <vers num="1.0.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2333" published="2005-07-20" name="CVE-2005-2333" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014509" source="SECTRACK">1014509</ref>
      <ref url="http://www.securityfocus.com/bid/14320" source="BID">14320</ref>
      <ref url="http://secunia.com/advisories/16051" source="SECUNIA">16051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seo-board" name="seo-board">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2334" published="2005-07-20" name="CVE-2005-2334" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014502" source="SECTRACK">1014502</ref>
      <ref url="http://www.securityfocus.com/bid/14299" source="BID">14299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="y.sak" name="y.sak">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2335" published="2005-07-27" name="CVE-2005-2335" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://www.securityfocus.com/bid/14349" source="BID" patch="1">14349</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00089.html" source="FEDORA" patch="1">FEDORA-2005-614</ref>
      <ref url="http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt" source="CONFIRM" patch="1" adv="1">http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=6617" source="CONFIRM" patch="1">http://developer.berlios.de/project/shownotes.php?release_id=6617</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1171" source="VUPEN">ADV-2005-1171</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/441856/100/200/threaded" source="BUGTRAQ">20060801 DMA[2006-0801a] - 'Apple OSX fetchmail buffer overflow'</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435197/100/0/threaded" source="BUGTRAQ">20060526 rPSA-2006-0084-1 fetchmail</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-640.html" source="REDHAT">RHSA-2005:640</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html" source="MISC">http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00088.html" source="FEDORA">FEDORA-2005-613</ref>
      <ref url="http://www.osvdb.org/18174" source="OSVDB">18174</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-774" source="DEBIAN">DSA-774</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA" adv="1">21253</ref>
      <ref url="http://secunia.com/advisories/16176" source="SECUNIA" adv="1">16176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8833" source="OVAL">oval:org.mitre.oval:def:8833</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1124" source="OVAL" sig="1">oval:org.mitre.oval:def:1124</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1038" source="OVAL" sig="1">oval:org.mitre.oval:def:1038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fetchmail" name="fetchmail">
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.5.3" />
        <vers num="4.5.4" />
        <vers num="4.5.5" />
        <vers num="4.5.6" />
        <vers num="4.5.7" />
        <vers num="4.5.8" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
        <vers num="4.6.2" />
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="4.6.5" />
        <vers num="4.6.6" />
        <vers num="4.6.7" />
        <vers num="4.6.8" />
        <vers num="4.6.9" />
        <vers num="4.7.0" />
        <vers num="4.7.1" />
        <vers num="4.7.2" />
        <vers num="4.7.3" />
        <vers num="4.7.4" />
        <vers num="4.7.5" />
        <vers num="4.7.6" />
        <vers num="4.7.7" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.1.0" />
        <vers num="5.1.4" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.0" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.4.5" />
        <vers num="5.5.0" />
        <vers num="5.5.2" />
        <vers num="5.5.3" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.6.0" />
        <vers num="5.7.0" />
        <vers num="5.7.2" />
        <vers num="5.7.4" />
        <vers num="5.8" />
        <vers num="5.8.1" />
        <vers num="5.8.11" />
        <vers num="5.8.13" />
        <vers num="5.8.14" />
        <vers num="5.8.17" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.0" />
        <vers num="5.9.10" />
        <vers num="5.9.11" />
        <vers num="5.9.13" />
        <vers num="5.9.4" />
        <vers num="5.9.5" />
        <vers num="5.9.8" />
        <vers num="6.0.0" />
        <vers num="6.1.0" />
        <vers num="6.1.3" />
        <vers num="6.2.0" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.2.4" />
        <vers num="6.2.5" />
        <vers prev="1" num="6.2.5.1" />
        <vers num="6.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2336" published="2005-09-06" name="CVE-2005-2336" modified="2008-11-11" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via "missing pages" in which the page name is not properly escaped, a different vulnerability than CVE-2005-2803.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://hikiwiki.org/en/advisory20050804.html" source="CONFIRM" patch="1" adv="1">http://hikiwiki.org/en/advisory20050804.html</ref>
      <ref url="http://jvn.jp/en/jp/JVN38138980/index.html" source="JVN">JVN#38138980</ref>
      <ref url="http://www.securityfocus.com/bid/15021" source="BID">15021</ref>
      <ref url="http://secunia.com/advisories/17075" source="SECUNIA">17075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hiki" name="hiki">
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2337" published="2005-10-07" name="CVE-2005-2337" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/160012" source="CERT-VN" adv="1">VU#160012</ref>
      <ref url="http://www.ruby-lang.org/en/20051003.html" source="CONFIRM" patch="1" adv="1">http://www.ruby-lang.org/en/20051003.html</ref>
      <ref url="http://secunia.com/advisories/16904" source="SECUNIA" patch="1" adv="1">16904</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22360" source="XF">ruby-eval-security-bypass(22360)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://www.ubuntu.com/usn/usn-195-1" source="UBUNTU">USN-195-1</ref>
      <ref url="http://www.securitytracker.com/alerts/2005/Sep/1014948.html" source="SECTRACK">1014948</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.securityfocus.com/bid/14909" source="BID">14909</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-799.html" source="REDHAT">RHSA-2005:799</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:191" source="MANDRIVA" adv="1">MDKSA-2005:191</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200510-05.xml" source="GENTOO">GLSA-200510-05</ref>
      <ref url="http://www.debian.org/security/2005/dsa-864" source="DEBIAN" adv="1">DSA-864</ref>
      <ref url="http://www.debian.org/security/2005/dsa-862" source="DEBIAN">DSA-862</ref>
      <ref url="http://www.debian.org/security/2005/dsa-860" source="DEBIAN">DSA-860</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" adv="1">20077</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA" adv="1">19130</ref>
      <ref url="http://secunia.com/advisories/17285" source="SECUNIA" adv="1">17285</ref>
      <ref url="http://secunia.com/advisories/17147" source="SECUNIA" adv="1">17147</ref>
      <ref url="http://secunia.com/advisories/17129" source="SECUNIA" adv="1">17129</ref>
      <ref url="http://secunia.com/advisories/17098" source="SECUNIA" adv="1">17098</ref>
      <ref url="http://secunia.com/advisories/17094" source="SECUNIA">17094</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10564" source="OVAL">oval:org.mitre.oval:def:10564</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE">APPLE-SA-2006-05-11</ref>
      <ref url="http://jvn.jp/jp/JVN%2362914675/index.html" source="MISC">http://jvn.jp/jp/JVN%2362914675/index.html</ref>
      <ref url="http://securityreason.com/securityalert/59" source="SREASON">59</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yukihiro_matsumoto" name="ruby">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2_pre1" />
        <vers num="1.8.2_pre2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2338" published="2005-10-26" name="CVE-2005-2338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in the forum module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/85_e.html" source="MISC" patch="1" adv="1">http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/85_e.html</ref>
      <ref url="http://secunia.com/advisories/17300" source="SECUNIA" patch="1" adv="1">17300</ref>
      <ref url="http://jvn.jp/jp/JVN%2377105349/index.html" source="JVN">JVN#77105349</ref>
      <ref url="http://www.securityfocus.com/bid/15195" source="BID">15195</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113027315412024&amp;w=2" source="BUGTRAQ">20051025 [SNS Advisory No.85] XOOPS Multiple Cross-site Scripting Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops">
        <vers prev="1" num="2.0.12_jp" />
        <vers prev="1" num="2.0.13.1" />
        <vers prev="1" num="2.2.3_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2339" published="2005-11-21" name="CVE-2005-2339" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Unicode version of msearch (unicode-msearch) 1.51(U1)-beta1, 1.51(U1), and 1.52(U1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://jvn.jp/jp/JVN%2379925E6F/index.html" source="MISC">http://jvn.jp/jp/JVN%2379925E6F/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="msearch" name="unicode_msearch">
        <vers num="1.51_u1" />
        <vers num="1.51_u1_beta1" />
        <vers num="1.52_u1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2340" published="2005-12-31" name="CVE-2005-2340" modified="2011-10-18" discovered="2005-12-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-011A.html" source="CERT" patch="1" adv="1">TA06-011A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/687201" source="CERT-VN" patch="1" adv="1">VU#687201</ref>
      <ref url="http://www.kb.cert.org/vuls/id/629845" source="CERT-VN" patch="1" adv="1">VU#629845</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24054" source="XF" patch="1">quicktime-qtif-bo(24054)</ref>
      <ref url="http://www.securityfocus.com/bid/16202" source="BID" patch="1">16202</ref>
      <ref url="http://www.osvdb.org/22335" source="OSVDB" patch="1">22335</ref>
      <ref url="http://www.osvdb.org/22334" source="OSVDB" patch="1">22334</ref>
      <ref url="http://www.osvdb.org/22333" source="OSVDB" patch="1">22333</ref>
      <ref url="http://securitytracker.com/id?1015463" source="SECTRACK" patch="1">1015463</ref>
      <ref url="http://secunia.com/advisories/18370" source="SECUNIA" patch="1" adv="1">18370</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303101" source="APPLE" patch="1">APPLE-SA-2006-01-10</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0128" source="VUPEN" adv="1">ADV-2006-0128</ref>
      <ref url="http://www.securityfocus.com/bid/16212" source="BID">16212</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421566/100/0/threaded" source="BUGTRAQ" adv="1">20060111 [EEYEB-20051220] Apple QuickTime QTIF Stack Overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421547/100/0/threaded" source="BUGTRAQ">20060111 Updated Advisories - Incorrect CVE Information</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-41-advisory.pdf" source="MISC" adv="1">http://www.cirt.dk/advisories/cirt-41-advisory.pdf</ref>
      <ref url="http://securityreason.com/securityalert/332" source="SREASON">332</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0402.html" source="FULLDISC">20060111 Updated Advisories - Incorrect CVE Information</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0398.html" source="FULLDISC" adv="1">20060111 [EEYEB-20051220] Apple QuickTime QTIF Stack Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0392.html" source="FULLDISC">20060111 [CIRT.DK] Apple QuickTime 7.0.3 and earlier - JPG/PICT Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers prev="1" num="7.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2341" published="2005-12-31" name="CVE-2005-2341" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Research in Motion (RIM) BlackBerry Attachment Service allows remote attackers to cause a denial of service (hang) via an e-mail attachment with a crafted TIFF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/570768" source="CERT-VN" adv="1">VU#570768</ref>
      <ref url="http://securitytracker.com/id?1015426" source="SECTRACK" patch="1">1015426</ref>
      <ref url="http://secunia.com/advisories/18277" source="SECUNIA" patch="1" adv="1">18277</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0011" source="VUPEN" adv="1">ADV-2006-0011</ref>
      <ref url="http://www.securityfocus.com/bid/16098" source="BID">16098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_attachment_service">
        <vers prev="1" num="4.0" />
      </prod>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2342" published="2005-12-31" name="CVE-2005-2342" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/392920" source="CERT-VN" adv="1">VU#392920</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0011" source="VUPEN">ADV-2006-0011</ref>
      <ref url="http://www.securityfocus.com/bid/16100" source="BID">16100</ref>
      <ref url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/728075/728850/728215/?nodeid=1167898" source="CONFIRM">http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/728075/728850/728215/?nodeid=1167898</ref>
      <ref url="http://securitytracker.com/id?1015427" source="SECTRACK">1015427</ref>
      <ref url="http://secunia.com/advisories/18277" source="SECUNIA">18277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers num="4.0" />
        <vers num="4.0_sp1" />
      </prod>
      <prod vendor="rim" name="blackberry_router">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2343" published="2005-12-31" name="CVE-2005-2343" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Research in Motion (RIM) BlackBerry Handheld web browser for BlackBerry Handheld before 4.0.2 allows remote attackers to cause a denial of service (hang) via a Java Application Description (JAD) file with a long application name and vendor string, which prevents a browser dialog from being properly dismissed.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/829400" source="CERT-VN" adv="1">VU#829400</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0011" source="VUPEN">ADV-2006-0011</ref>
      <ref url="http://www.securityfocus.com/bid/16099" source="BID">16099</ref>
      <ref url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/?nodeid=1167791" source="CONFIRM">http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/?nodeid=1167791</ref>
      <ref url="http://securitytracker.com/id?1015428" source="SECTRACK">1015428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry">
        <vers num="7100g" />
        <vers num="7100i" />
        <vers num="7100r" />
        <vers num="7100t" />
        <vers num="7100v" />
        <vers num="7100x" />
        <vers num="7105t" />
        <vers num="7130e" />
        <vers num="7230_3.7.1_.41" />
        <vers num="7230_3.8" />
        <vers num="7230_4.0" />
        <vers num="7250" />
        <vers num="7280" />
        <vers num="7290" />
        <vers num="7520" />
        <vers num="7730" />
        <vers num="7750" />
        <vers num="7780" />
        <vers num="8700c" />
        <vers num="8700f" />
        <vers num="8700r" />
      </prod>
      <prod vendor="rim" name="blackberry_desktop_manager">
        <vers num="4.0" />
      </prod>
      <prod vendor="rim" name="blackberry_device_software">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2344" published="2005-12-31" name="CVE-2005-2344" modified="2011-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portable Network Graphics (PNG) file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/646976" source="CERT-VN" adv="1">VU#646976</ref>
      <ref url="http://secunia.com/advisories/18393" source="SECUNIA" patch="1" adv="1">18393</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24063" source="XF">blackberry-attachment-png-bo(24063)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0127" source="VUPEN" adv="1">ADV-2006-0127</ref>
      <ref url="http://www.securityfocus.com/bid/16204" source="BID">16204</ref>
      <ref url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/728075/728850/728215/?nodeid=1167794" source="CONFIRM" adv="1">http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/728075/728850/728215/?nodeid=1167794</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers num="4.0" />
        <vers num="4.0_sp1" />
        <vers num="4.0_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2346" published="2005-08-03" name="CVE-2005-2346" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098314.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098314.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112247652532002&amp;w=2" source="BUGTRAQ">20050727 [ISR] - Novell GroupWise Client Remote Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2353" published="2005-08-05" name="CVE-2005-2353" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-157-1" source="UBUNTU" patch="1" adv="1">USN-157-1</ref>
      <ref url="http://www.securityfocus.com/bid/14443" source="BID">14443</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:174" source="MANDRIVA">MDKSA-2005:174</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:173" source="MANDRIVA">MDKSA-2005:173</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-2355" reject="1" published="2005-07-25" name="CVE-2005-2355" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2335, CVE-2005-2356.  Reason: due to a typo in an advisory, this candidate was accidentally referenced.  Notes: All CVE users should consult CVE-2005-2335 and CVE-2005-2356 to determine the appropriate identifier for the issue.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2357" published="2005-08-16" name="CVE-2005-2357" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21726" source="XF">emcnavispheremanager-directory-traversal(21726)</ref>
      <ref url="http://www.securityfocus.com/bid/14487" source="BID">14487</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=288&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20050805 EMC Navisphere Manager Directory Traversal Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014629" source="SECTRACK">1014629</ref>
      <ref url="http://secunia.com/advisories/16344" source="SECUNIA">16344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="navisphere_manager">
        <vers num="6.4" />
        <vers num="6.4.1.0.0" />
        <vers num="6.5" />
        <vers num="6.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2358" published="2005-08-16" name="CVE-2005-2358" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14487" source="BID" patch="1">14487</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=288&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20050805 EMC Navisphere Manager Directory Traversal Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1014629" source="SECTRACK">1014629</ref>
      <ref url="http://secunia.com/advisories/16344" source="SECUNIA">16344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="navisphere_manager">
        <vers num="6.4" />
        <vers num="6.4.1.0" />
        <vers num="6.5" />
        <vers num="6.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2359" published="2005-08-05" name="CVE-2005-2359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21551" source="XF" patch="1" adv="1">freebsd-aesxcbcmac-security-bypass(21551)</ref>
      <ref url="http://secunia.com/advisories/16244/" source="SECUNIA" patch="1" adv="1">16244</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:19.ipsec.asc" source="FREEBSD">FreeBSD-SA-05:19</ref>
      <ref url="http://www.securityfocus.com/bid/14394" source="BID">14394</ref>
      <ref url="http://securitytracker.com/id?1014586" source="SECTRACK">1014586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2360" published="2005-08-10" name="CVE-2005-2360" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through 0.10.11 allows remote attackers to cause a denial of service (free static memory and application crash) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml" source="GENTOO" patch="1" adv="1">GLSA-200507-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00020.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11254" source="OVAL">oval:org.mitre.oval:def:11254</ref>
      <ref url="http://www.securityfocus.com/bid/14399" source="BID">14399</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-687.html" source="REDHAT">RHSA-2005:687</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.debian.org/security/2005/dsa-853" source="DEBIAN">DSA-853</ref>
      <ref url="http://secunia.com/advisories/17102" source="SECUNIA">17102</ref>
      <ref url="http://secunia.com/advisories/16225/" source="SECUNIA">16225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8.10" />
        <vers num="0.8.11" />
        <vers num="0.8.12" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.16" />
        <vers num="0.8.17" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.8.20" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2361" published="2005-08-10" name="CVE-2005-2361" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the (1) AgentX dissector, (2) PER dissector, (3) DOCSIS dissector, (4) SCTP graphs, (5) HTTP dissector, (6) DCERPC, (7) DHCP, (8) RADIUS dissector, (9) Telnet dissector, (10) IS-IS LSP dissector, or (11) NCP dissector in Ethereal 0.8.19 through 0.10.11 allows remote attackers to cause a denial of service (application crash or abort) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml" source="GENTOO" patch="1">GLSA-200507-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00020.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10225" source="OVAL">oval:org.mitre.oval:def:10225</ref>
      <ref url="http://www.securityfocus.com/bid/14399" source="BID">14399</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-687.html" source="REDHAT">RHSA-2005:687</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.debian.org/security/2005/dsa-853" source="DEBIAN">DSA-853</ref>
      <ref url="http://secunia.com/advisories/17102" source="SECUNIA">17102</ref>
      <ref url="http://secunia.com/advisories/16225/" source="SECUNIA">16225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8.19" />
        <vers num="0.8.20" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2362" published="2005-08-10" name="CVE-2005-2362" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability several dissectors in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a denial of service (application crash) by reassembling certain packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml" source="GENTOO" patch="1">GLSA-200507-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00020.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10059" source="OVAL">oval:org.mitre.oval:def:10059</ref>
      <ref url="http://www.securityfocus.com/bid/14399" source="BID">14399</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-687.html" source="REDHAT">RHSA-2005:687</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://secunia.com/advisories/16225" source="SECUNIA">16225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2363" published="2005-08-10" name="CVE-2005-2363" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the (1) SMPP dissector, (2) 802.3 dissector, (3) DHCP, (4) MEGACO dissector, or (5) H1 dissector in Ethereal 0.8.15 through 0.10.11 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml" source="GENTOO" patch="1">GLSA-200507-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00020.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11271" source="OVAL">oval:org.mitre.oval:def:11271</ref>
      <ref url="http://www.securityfocus.com/bid/14399" source="BID">14399</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-687.html" source="REDHAT">RHSA-2005:687</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-853" source="DEBIAN">DSA-853</ref>
      <ref url="http://secunia.com/advisories/17102" source="SECUNIA">17102</ref>
      <ref url="http://secunia.com/advisories/16225/" source="SECUNIA">16225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8.15" />
        <vers num="0.8.16" />
        <vers num="0.8.17" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.8.20" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2364" published="2005-08-10" name="CVE-2005-2364" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the (1) GIOP dissector, (2) WBXML, or (3) CAMEL dissector in Ethereal 0.8.20 through 0.10.11 allows remote attackers to cause a denial of service (application crash) via certain packets that cause a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml" source="GENTOO" patch="1">GLSA-200507-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00020.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10007" source="OVAL">oval:org.mitre.oval:def:10007</ref>
      <ref url="http://www.securityfocus.com/bid/14399" source="BID">14399</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-687.html" source="REDHAT">RHSA-2005:687</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.osvdb.org/18386" source="OSVDB">18386</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.debian.org/security/2005/dsa-853" source="DEBIAN">DSA-853</ref>
      <ref url="http://secunia.com/advisories/17102" source="SECUNIA">17102</ref>
      <ref url="http://secunia.com/advisories/16225/" source="SECUNIA">16225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8.20" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2365" published="2005-08-10" name="CVE-2005-2365" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the SMB dissector in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a buffer overflow or a denial of service (memory consumption) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml" source="GENTOO" patch="1">GLSA-200507-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00020.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9118" source="OVAL">oval:org.mitre.oval:def:9118</ref>
      <ref url="http://www.securityfocus.com/bid/14399" source="BID">14399</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-687.html" source="REDHAT">RHSA-2005:687</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.debian.org/security/2005/dsa-853" source="DEBIAN">DSA-853</ref>
      <ref url="http://secunia.com/advisories/17102" source="SECUNIA">17102</ref>
      <ref url="http://secunia.com/advisories/16225/" source="SECUNIA">16225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2366" published="2005-08-10" name="CVE-2005-2366" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the BER dissector in Ethereal 0.10.11 allows remote attackers to cause a denial of service (abort or infinite loop) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml" source="GENTOO" patch="1">GLSA-200507-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00020.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11239" source="OVAL">oval:org.mitre.oval:def:11239</ref>
      <ref url="http://www.securityfocus.com/bid/14399" source="BID">14399</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-687.html" source="REDHAT">RHSA-2005:687</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.debian.org/security/2005/dsa-853" source="DEBIAN">DSA-853</ref>
      <ref url="http://secunia.com/advisories/17102" source="SECUNIA">17102</ref>
      <ref url="http://secunia.com/advisories/16225/" source="SECUNIA">16225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2367" published="2005-08-10" name="CVE-2005-2367" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary memory locations and gain privileges via a crafted AFP packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:131" source="MANDRAKE" patch="1" adv="1">MDKSA-2005:131</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml" source="GENTOO" patch="1">GLSA-200507-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00020.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=289&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050805 Multiple Vendor Ethereal AFP Protocol Dissector Format String Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10765" source="OVAL">oval:org.mitre.oval:def:10765</ref>
      <ref url="http://www.securityfocus.com/bid/14399" source="BID">14399</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-687.html" source="REDHAT">RHSA-2005:687</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://www.debian.org/security/2005/dsa-853" source="DEBIAN">DSA-853</ref>
      <ref url="http://secunia.com/advisories/17102" source="SECUNIA">17102</ref>
      <ref url="http://secunia.com/advisories/16225/" source="SECUNIA">16225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2368" published="2005-07-26" name="CVE-2005-2368" modified="2010-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_5.html" source="MISC" patch="1" adv="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_5.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-July/035402.html" source="FULLDISC" patch="1" adv="1">20050725 Help poor children in Uganda</ref>
      <ref url="http://www.securityfocus.com/bid/14374" source="BID">14374</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-745.html" source="REDHAT">RHSA-2005:745</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11302" source="OVAL">oval:org.mitre.oval:def:11302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vim_development_group" name="vim">
        <vers num="6.3" />
        <vers num="6.3.011" />
        <vers num="6.3.025" />
        <vers num="6.3.030" />
        <vers num="6.3.044" />
        <vers num="6.3.081" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2369" published="2005-07-26" name="CVE-2005-2369" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer signedness errors in libgadu, as used in ekg before 1.6rc2 and other packages, may allow remote attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2" source="BUGTRAQ" patch="1">20050721 Multiple vulnerabilities in libgadu and ekg package</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10281" source="OVAL">oval:org.mitre.oval:def:10281</ref>
      <ref url="http://www.securityfocus.com/bid/14415" source="BID">14415</ref>
      <ref url="http://www.debian.org/security/2005/dsa-813" source="DEBIAN">DSA-813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="1.1" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6_rc1" />
        <vers num="2005-04-11" />
        <vers num="2005-06-05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2370" published="2005-07-26" name="CVE-2005-2370" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple "memory alignment errors" in libgadu, as used in ekg before 1.6rc2, Gaim before 1.5.0, and other packages, allows remote attackers to cause a denial of service (bus error) on certain architectures such as SPARC via an incoming message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2" source="BUGTRAQ" patch="1">20050721 Multiple vulnerabilities in libgadu and ekg package</ref>
      <ref url="http://www.securityfocus.com/bid/24600" source="BID">24600</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-627.html" source="REDHAT">RHSA-2005:627</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1318" source="DEBIAN">DSA-1318</ref>
      <ref url="http://www.debian.org/security/2005/dsa-813" source="DEBIAN">DSA-813</ref>
      <ref url="http://secunia.com/advisories/16265" source="SECUNIA" adv="1">16265</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10456" source="OVAL">oval:org.mitre.oval:def:10456</ref>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=20" source="CONFIRM">http://gaim.sourceforge.net/security/index.php?id=20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="1.1" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6_rc1" />
        <vers num="2005-04-11" />
        <vers num="2005-06-05" />
      </prod>
      <prod vendor="rob_flynn" name="gaim">
        <vers prev="1" num="1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2371" published="2005-07-26" name="CVE-2005-2371" modified="2011-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter.  NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.securityfocus.com/bid/14309" source="BID">14309</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422257/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Reports - Overwrite any application server file via desname (fixed after 889 days)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://securitytracker.com/id?1014524" source="SECTRACK">1014524</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112180096507467&amp;w=2" source="BUGTRAQ" adv="1">20050719 Oracle Security Advisory: Overwrite any file via desname in Oracle Reports</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="reports">
        <vers num="10g" />
        <vers num="6.0" />
        <vers num="6i" />
        <vers num="9i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2372" published="2005-07-26" name="CVE-2005-2372" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.red-database-security.com/advisory/oracle_forms_run_any_os_command.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_forms_run_any_os_command.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112180805413784&amp;w=2" source="BUGTRAQ" adv="1">20050719 Oracle Security Advisory: Run any OS Command via unauthorized Oracle Forms</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="forms">
        <vers num="10g" />
        <vers num="3.0" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6i" />
        <vers num="9i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2373" published="2005-07-26" name="CVE-2005-2373" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.whitsoftdev.com/slimftpd/" source="CONFIRM">http://www.whitsoftdev.com/slimftpd/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112196537312610&amp;w=2" source="BUGTRAQ" adv="1">20050721 Arbitrary code execution in SlimFTPd v3.16</ref>
      <ref url="http://securitytracker.com/id?1014542" source="SECTRACK">1014542</ref>
      <ref url="http://secunia.com/advisories/16177" source="SECUNIA">16177</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whitsoft_development" name="slimftpd">
        <vers num="3.15" />
        <vers num="3.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2374" published="2005-07-26" name="CVE-2005-2374" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Belkin 54g wireless routers do not properly set an administrative password, which allows remote attackers to gain access via the (1) Telnet or (2) weba dministration interfaces.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21412" source="XF">belkin-router-default-password(21412)</ref>
      <ref url="http://securitytracker.com/alerts/2005/Jul/1014493.html" source="SECTRACK">1014493</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112144089102115&amp;w=2" source="BUGTRAQ" adv="1">20050715 several vulnerabilities present in Belkin wireless routers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="belkin" name="belkin_54g_wireless_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2375" published="2005-07-26" name="CVE-2005-2375" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/rdrum-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/rdrum-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112171364923678&amp;w=2" source="BUGTRAQ">20050718 Broadcast format string and buffer-overflow in Race Driver 1.20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codemasters" name="toca_race_driver">
        <vers prev="1" num="1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2376" published="2005-07-26" name="CVE-2005-2376" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via a long (1) nickname or (2) chat message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/rdrum-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/rdrum-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112171364923678&amp;w=2" source="BUGTRAQ">20050718 Broadcast format string and buffer-overflow in Race Driver 1.20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codemasters" name="toca_race_driver">
        <vers prev="1" num="1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2377" published="2005-07-26" name="CVE-2005-2377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems, does not properly handle a SIGPIPE signal when sending a search request to an LDAP directory server, which might allow remote attackers to cause a denial of service (crond and other application crash) if they can cause an LDAP server to become unavailable.  NOTE: it is not clear whether this attack scenario is sufficient to include this item in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:121" source="MANDRAKE" patch="1">MDKSA-2005:121</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40501" source="XF">nssldap-sigpipe-dos(40501)</ref>
      <ref url="http://qa.mandriva.com/show_bug.cgi?id=13271" source="MISC">http://qa.mandriva.com/show_bug.cgi?id=13271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2378" published="2005-07-26" name="CVE-2005-2378" modified="2011-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet.  NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422256/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Reports - Read parts of files via desname (fixed after 874 days)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html</ref>
      <ref url="http://securitytracker.com/id?1014527" source="SECTRACK">1014527</ref>
      <ref url="http://securitytracker.com/id?1014525" source="SECTRACK">1014525</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112181242916757&amp;w=2" source="BUGTRAQ" adv="1">20050719 Oracle Security Advisory:  Read parts of any XML-file via customize parameter in Oracle Reports</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112181054226520&amp;w=2" source="BUGTRAQ" adv="1">20050719 Oracle Security Advisory: Read parts of any file via desformat in Oracle Reports</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="reports">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2379" published="2005-07-26" name="CVE-2005-2379" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) debug parameter to showenv, (2) test parameter to parsequery, or (3) delimiter or (4) CELLWRAPPER parameter to rwservlet.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_various_css.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_reports_various_css.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112181649831863&amp;w=2" source="BUGTRAQ" adv="1">20050719 Oracle Security Advisory: Various Cross-Site-Scripting Oracle Reports</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="reports">
        <vers num="9.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2380" published="2005-07-26" name="CVE-2005-2380" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or the sid parameter to (4) dataentry.php or (5) export.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112188282401681&amp;w=2" source="BUGTRAQ">20050720 Multiple Vulnerabilities in PHP Surveyor</ref>
      <ref url="http://secunia.com/advisories/16123" source="SECUNIA">16123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_surveyor" name="php_surveyor">
        <vers num="0.98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2381" published="2005-07-26" name="CVE-2005-2381" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to dumpquestion.php, or an invalid lid parameter to (9) labels.php or (10) dumplabel.php, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112188282401681&amp;w=2" source="BUGTRAQ">20050720 Multiple Vulnerabilities in PHP Surveyor</ref>
      <ref url="http://secunia.com/advisories/16123" source="SECUNIA">16123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_surveyor" name="php_surveyor">
        <vers num="0.98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2382" published="2005-07-26" name="CVE-2005-2382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which allows local users to gain privileges by accessing the Help functionality.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secway.org/advisory/AD20050720EN.txt" source="MISC" adv="1">http://secway.org/advisory/AD20050720EN.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112190569628213&amp;w=2" source="BUGTRAQ" adv="1">20050720 PeanutHull Local Privilege Escalation Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/14330" source="BID">14330</ref>
      <ref url="http://secunia.com/advisories/16124" source="SECUNIA">16124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oray" name="peanuthull">
        <vers num="3.0.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2383" published="2005-07-26" name="CVE-2005-2383" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://newsphp.sourceforge.net/changelog/changelog_1.30.txt" source="CONFIRM" patch="1">http://newsphp.sourceforge.net/changelog/changelog_1.30.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112189453304389&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050720 PHPNews SQL injection vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/14333" source="BID">14333</ref>
      <ref url="http://secunia.com/advisories/16148" source="SECUNIA">16148</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnews" name="phpnews">
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2384" published="2005-07-27" name="CVE-2005-2384" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to write arbitrary files via an ACE archive containing filenames with (1) .. or (2) absolute pathnames.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2005-20/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-20/advisory/</ref>
      <ref url="http://secunia.com/advisories/15776" source="SECUNIA" patch="1" adv="1">15776</ref>
      <ref url="http://www.avast.com/eng/av4_revision_history.html" source="MISC">http://www.avast.com/eng/av4_revision_history.html</ref>
      <ref url="http://securitytracker.com/id?1014544" source="SECTRACK">1014544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alwil" name="avast_antivirus">
        <vers num="4.6.460" edition="" />
        <vers num="4.6.460" edition=":server" />
        <vers num="4.6.665" edition="" />
        <vers num="4.6.665" edition=":pro" />
        <vers num="4.6.665" edition=":home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2385" published="2005-07-27" name="CVE-2005-2385" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to execute arbitrary code via an ACE archive containing a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2005-20/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-20/advisory/</ref>
      <ref url="http://secunia.com/advisories/15776" source="SECUNIA" patch="1" adv="1">15776</ref>
      <ref url="http://www.avast.com/eng/av4_revision_history.html" source="MISC">http://www.avast.com/eng/av4_revision_history.html</ref>
      <ref url="http://securitytracker.com/id?1014544" source="SECTRACK">1014544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alwil" name="avast_antivirus">
        <vers num="4.6.460" edition="" />
        <vers num="4.6.460" edition=":server" />
        <vers num="4.6.665" edition="" />
        <vers num="4.6.665" edition=":pro" />
        <vers num="4.6.665" edition=":home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2386" published="2005-07-27" name="CVE-2005-2386" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14386" source="BID">14386</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=4008" source="MISC" adv="1">http://www.hackerscenter.com/archive/view.asp?id=4008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elemental_software" name="cartwiz">
        <vers num="1.10" />
        <vers num="1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2387" published="2005-07-27" name="CVE-2005-2387" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in GoodTech SMTP server 5.16 allow remote attackers to execute arbitrary code via (1) a RCPT TO command with a long DNS name, or (2) a large number of RCPT TO commands with a long e-mail name arugment in the last command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jul/0402.html" source="BUGTRAQ" adv="1">20050723 GoodTech SMTP server 5.16 RCPT TO command remote buffer overflow</ref>
      <ref url="http://www.securityfocus.com/bid/14357" source="BID">14357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goodtech_systems" name="goodtech_smtp_server">
        <vers num="5.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2388" published="2005-07-27" name="CVE-2005-2388" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14376" source="BID">14376</ref>
      <ref url="http://www.eweek.com/article2/0,1759,1840131,00.asp" source="MISC">http://www.eweek.com/article2/0,1759,1840131,00.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21539" source="XF">windows-usb-device-bo(21539)</ref>
      <ref url="http://www.osvdb.org/18493" source="OSVDB">18493</ref>
      <ref url="http://securitytracker.com/id?1014566" source="SECTRACK">1014566</ref>
      <ref url="http://secunia.com/advisories/16210" source="SECUNIA">16210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" edition="sr2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2389" published="2005-07-27" name="CVE-2005-2389" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hat-squad.com/en/000170.html" source="MISC" adv="1">http://www.hat-squad.com/en/000170.html</ref>
      <ref url="http://secunia.com/advisories/16187" source="SECUNIA" adv="1">16187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="netbackup_enterprise_server">
        <vers num="5.1" />
      </prod>
      <prod vendor="symantec_veritas" name="netbackup_server">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2390" published="2005-07-27" name="CVE-2005-2390" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo mod_sql directive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.proftpd.org/docs/RELEASE_NOTES-1.3.0rc2" source="CONFIRM">http://www.proftpd.org/docs/RELEASE_NOTES-1.3.0rc2</ref>
      <ref url="http://secunia.com/advisories/16181" source="SECUNIA" adv="1">16181</ref>
      <ref url="http://www.securityfocus.com/bid/14381" source="BID">14381</ref>
      <ref url="http://www.securityfocus.com/bid/14380" source="BID">14380</ref>
      <ref url="http://www.debian.org/security/2005/dsa-795" source="DEBIAN">DSA-795</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112604373503912&amp;w=2" source="OPENPKG">OpenPKG-SA-2005.020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.0_pre10" />
        <vers num="1.2.0_pre9" />
        <vers num="1.2.0_rc1" />
        <vers num="1.2.0_rc2" />
        <vers num="1.2.0_rc3" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.10_rc1" />
        <vers num="1.2.10_rc2" />
        <vers num="1.2.10_rc3" />
        <vers num="1.2.1_final" />
        <vers num="1.2.2" />
        <vers num="1.2.2_rc1" />
        <vers num="1.2.2_rc2" />
        <vers num="1.2.2_rc3" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.5_rc1" />
        <vers num="1.2.5_rc2" />
        <vers num="1.2.5_rc3" />
        <vers num="1.2.6" />
        <vers num="1.2.6_rc1" />
        <vers num="1.2.6_rc2" />
        <vers num="1.2.6_rc3" />
        <vers num="1.2.7" />
        <vers num="1.2.7_rc1" />
        <vers num="1.2.7_rc2" />
        <vers num="1.2.7_rc3" />
        <vers num="1.2.8" />
        <vers num="1.2.8_rc1" />
        <vers num="1.2.8_rc2" />
        <vers num="1.2.9" />
        <vers num="1.2.9_rc1" />
        <vers num="1.2.9_rc2" />
        <vers num="1.2.9_rc3" />
        <vers num="1.3.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2391" published="2005-07-27" name="CVE-2005-2391" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in 3Com OfficeConnect Wireless 11g Access Point before 1.03.12 allows remote attackers to obtain sensitive information via the web interface.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16207" source="SECUNIA" patch="1" adv="1">16207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3crwe454g72">
        <vers num="1.02.00" />
        <vers num="1.02.11" />
        <vers num="1.03.05" />
        <vers num="1.03.07" />
        <vers num="1.03.07a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2392" published="2005-07-27" name="CVE-2005-2392" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14346" source="BID" patch="1">14346</ref>
      <ref url="http://www.cmsimple.dk/forum/viewtopic.php?t=2470" source="CONFIRM" patch="1">http://www.cmsimple.dk/forum/viewtopic.php?t=2470</ref>
      <ref url="http://securitytracker.com/id?1014556" source="SECTRACK" patch="1">1014556</ref>
      <ref url="http://lostmon.blogspot.com/2005/07/cmsimple-search-variable-xss.html" source="MISC" patch="1" adv="1">http://lostmon.blogspot.com/2005/07/cmsimple-search-variable-xss.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/442106/100/100/threaded" source="BUGTRAQ">20060803 CMSimple Cross Site Scripting</ref>
      <ref url="http://www.osvdb.org/18128" source="OSVDB">18128</ref>
      <ref url="http://www.aria-security.net/advisory/cmsimple.txt" source="MISC">http://www.aria-security.net/advisory/cmsimple.txt</ref>
      <ref url="http://secunia.com/advisories/16147" source="SECUNIA" adv="1">16147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmsmadesimple" name="cms_made_simple">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" edition="beta1" />
        <vers num="1.3" edition="beta2" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta2" />
        <vers num="2.0" edition="beta3" />
        <vers num="2.0" edition="beta4" />
        <vers num="2.1" />
        <vers num="2.2" edition="beta1" />
        <vers num="2.2" edition="beta2" />
        <vers num="2.2" edition="beta3" />
        <vers num="2.2" edition="beta4" />
        <vers num="2.3" edition="beta1" />
        <vers num="2.3" edition="beta2" />
        <vers num="2.3" edition="beta3" />
        <vers num="2.3" edition="beta4" />
        <vers num="2.3" edition="beta5" />
        <vers num="2.4" edition="beta1" />
        <vers num="2.4" edition="beta2" />
        <vers num="2.4" edition="beta3" />
        <vers num="2.4" edition="beta4" />
        <vers num="2.4" edition="beta5" />
        <vers num="2.4_beta" />
        <vers num="beta_1" />
        <vers num="beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2393" published="2005-07-27" name="CVE-2005-2393" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via (1) the lastusername parameter to index.php or (2) selected_search_arch parameter to search.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014514" source="SECTRACK">1014514</ref>
      <ref url="http://secunia.com/advisories/16129" source="SECUNIA">16129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2394" published="2005-07-27" name="CVE-2005-2394" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014514" source="SECTRACK">1014514</ref>
      <ref url="http://secunia.com/advisories/16129" source="SECUNIA">16129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2395" published="2005-07-27" name="CVE-2005-2395" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14325" source="BID">14325</ref>
      <ref url="http://www.securityfocus.com/archive/1/405666" source="BUGTRAQ">20050719 Mozilla cleartext credentials leak bug report to excuse myself (Re[2]: NTLM HTTP Authentication is insecure by design - a new writeup by Amit Klein)</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=281851" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=281851</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22272" source="XF">mozilla-authentication-weakness(22272)</ref>
      <ref url="http://www.securiteam.com/securitynews/5PP0L00GUQ.html" source="MISC">http://www.securiteam.com/securitynews/5PP0L00GUQ.html</ref>
      <ref url="http://www.osvdb.org/19002" source="OSVDB">19002</ref>
      <ref url="http://securityreason.com/securityalert/8" source="SREASON">8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2396" published="2005-07-27" name="CVE-2005-2396" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14327" source="BID" patch="1">14327</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200507-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200507-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21491" source="XF">mediawiki-page-move-xss(21491)</ref>
      <ref url="http://www.osvdb.org/17763" source="OSVDB">17763</ref>
      <ref url="http://secunia.com/advisories/16130" source="SECUNIA">16130</ref>
      <ref url="http://secunia.com/advisories/15950" source="SECUNIA">15950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.5" />
        <vers num="1.4_beta1" />
        <vers num="1.4_beta2" />
        <vers num="1.4_beta3" />
        <vers num="1.4_beta4" />
        <vers num="1.4_beta5" />
        <vers num="1.4_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2397" published="2005-07-27" name="CVE-2005-2397" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary web script or HTML via the admin parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014573" source="SECTRACK">1014573</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21538" source="XF">phpbook-admin-xss(21538)</ref>
      <ref url="http://www.securityfocus.com/bid/14390" source="BID">14390</ref>
      <ref url="http://www.osvdb.org/18295" source="OSVDB">18295</ref>
      <ref url="http://secunia.com/advisories/16192" source="SECUNIA">16192</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="phpbook">
        <vers num="1.46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2398" published="2005-07-27" name="CVE-2005-2398" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8) dumpsurvey.php, or (9) statistics.php, or the lid parameter to (10) labels.php or (11) dumplabel.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16123" source="SECUNIA" adv="1">16123</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112188282401681&amp;w=2" source="BUGTRAQ">20050720 Multiple Vulnerabilities in PHP Surveyor</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21444" source="XF">php-surveyor-sql-injection(21444)</ref>
      <ref url="http://www.securityfocus.com/bid/14331" source="BID">14331</ref>
      <ref url="http://www.osvdb.org/18108" source="OSVDB">18108</ref>
      <ref url="http://www.osvdb.org/18107" source="OSVDB">18107</ref>
      <ref url="http://www.osvdb.org/18106" source="OSVDB">18106</ref>
      <ref url="http://www.osvdb.org/18105" source="OSVDB">18105</ref>
      <ref url="http://www.osvdb.org/18104" source="OSVDB">18104</ref>
      <ref url="http://www.osvdb.org/18103" source="OSVDB">18103</ref>
      <ref url="http://www.osvdb.org/18102" source="OSVDB">18102</ref>
      <ref url="http://www.osvdb.org/18101" source="OSVDB">18101</ref>
      <ref url="http://www.osvdb.org/18100" source="OSVDB">18100</ref>
      <ref url="http://www.osvdb.org/18099" source="OSVDB">18099</ref>
      <ref url="http://www.osvdb.org/18098" source="OSVDB">18098</ref>
      <ref url="http://securitytracker.com/id?1014538" source="SECTRACK">1014538</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_surveyor" name="php_surveyor">
        <vers num="0.98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2399" published="2005-07-27" name="CVE-2005-2399" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16123" source="SECUNIA" adv="1">16123</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112188282401681&amp;w=2" source="BUGTRAQ">20050720 Multiple Vulnerabilities in PHP Surveyor</ref>
      <ref url="http://www.securityfocus.com/bid/14331" source="BID">14331</ref>
      <ref url="http://securitytracker.com/id?1014538" source="SECTRACK">1014538</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_surveyor" name="php_surveyor">
        <vers num="0.98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2400" published="2005-07-27" name="CVE-2005-2400" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The inc.login.php scripts in PHPFinance 0.3 allows remote attackers to bypass the login and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=343135" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=343135</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1133" source="VUPEN">ADV-2005-1133</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpfinance/phpfinance/inc.login.php?rev=1.2&amp;view=log" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/phpfinance/phpfinance/inc.login.php?rev=1.2&amp;view=log</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpfinance/phpfinance/inc.conf.php?rev=1.2&amp;view=log" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/phpfinance/phpfinance/inc.conf.php?rev=1.2&amp;view=log</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21426" source="XF">phpfinance-logon-bypass(21426)</ref>
      <ref url="http://www.securityfocus.com/bid/14322" source="BID">14322</ref>
      <ref url="http://secunia.com/advisories/13276" source="SECUNIA">13276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpfinance" name="phpfinance">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2401" published="2005-07-27" name="CVE-2005-2401" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14332" source="BID">14332</ref>
      <ref url="http://secunia.com/advisories/16096" source="SECUNIA" adv="1">16096</ref>
      <ref url="http://www.osvdb.org/18111" source="OSVDB">18111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="4.00" />
        <vers num="4.01" />
        <vers num="5.0" />
        <vers num="5.01_service_pack" />
        <vers num="6.0.105" />
        <vers num="6.0.106" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2402" published="2005-07-27" name="CVE-2005-2402" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPSiteSearch 1.7.7d allows remote attackers to inject arbitrary web script or HTML via the query parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rgod.altervista.org/PHPSiteSearch177dpoc.txt" source="MISC">http://www.rgod.altervista.org/PHPSiteSearch177dpoc.txt</ref>
      <ref url="http://secunia.com/advisories/16156" source="SECUNIA" adv="1">16156</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21463" source="XF">phpsitesearch-query-xss(21463)</ref>
      <ref url="http://www.securityfocus.com/bid/14344" source="BID">14344</ref>
      <ref url="http://www.osvdb.org/18142" source="OSVDB">18142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsitesearch" name="phpsitesearch">
        <vers num="1.7.7d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2403" published="2005-07-27" name="CVE-2005-2403" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The login protocol in RealChat 3.5.1b does not use authentication, which allows remote attackers to log on as other users by sniffing the beginning of a chat session and replaying it via a modified username.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014562" source="SECTRACK">1014562</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Jul/0403.html" source="BUGTRAQ" adv="1">20050723 Realchat user impersonation - BSA 200506110001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21497" source="XF">realchat-account-login(21497)</ref>
      <ref url="http://www.securityfocus.com/bid/14358" source="BID">14358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realchat" name="realchat">
        <vers num="3.5.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2404" published="2005-07-27" name="CVE-2005-2404" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in sendcard.php in Sendcard 3.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/1169" source="VUPEN">ADV-2005-1169</ref>
      <ref url="http://secunia.com/advisories/16165" source="SECUNIA" adv="1">16165</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21474" source="XF">sendcard-id-sql-injection(21474)</ref>
      <ref url="http://www.securityfocus.com/bid/14351" source="BID">14351</ref>
      <ref url="http://www.osvdb.org/18153" source="OSVDB">18153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendcard" name="sendcard">
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2405" published="2005-08-01" name="CVE-2005-2405" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.opera.com/linux/changelogs/802/" source="CONFIRM" patch="1">http://www.opera.com/linux/changelogs/802/</ref>
      <ref url="http://secunia.com/advisories/15870" source="SECUNIA" patch="1" adv="1">15870</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1251" source="VUPEN">ADV-2005-1251</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21784" source="XF">opera-content-disposition-extension-spoofing(21784)</ref>
      <ref url="http://www.securityfocus.com/bid/14402" source="BID">14402</ref>
      <ref url="http://securitytracker.com/id?1014592" source="SECTRACK">1014592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="8.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2406" published="2005-08-01" name="CVE-2005-2406" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.opera.com/linux/changelogs/802/" source="CONFIRM" patch="1">http://www.opera.com/linux/changelogs/802/</ref>
      <ref url="http://secunia.com/advisories/15756" source="SECUNIA" patch="1" adv="1">15756</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1251" source="VUPEN">ADV-2005-1251</ref>
      <ref url="http://www.securityfocus.com/bid/14410" source="BID">14410</ref>
      <ref url="http://securitytracker.com/id?1014593" source="SECTRACK">1014593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="8.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2407" published="2005-08-01" name="CVE-2005-2407" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">A design error in Opera 8.01 and earlier allows user-assisted attackers to execute arbitrary code by overlaying a malicious new window above a file download dialog box, then tricking the user into double-clicking on the "Run" button, aka "link hijacking".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.opera.com/linux/changelogs/802/" source="CONFIRM" patch="1">http://www.opera.com/linux/changelogs/802/</ref>
      <ref url="http://secunia.com/advisories/15781" source="SECUNIA" patch="1" adv="1">15781</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1251" source="VUPEN">ADV-2005-1251</ref>
      <ref url="http://www.securityfocus.com/bid/15835" source="BID">15835</ref>
      <ref url="http://securitytracker.com/id?1015353" source="SECTRACK">1015353</ref>
      <ref url="http://secunia.com/secunia_research/2005-19/advisory/" source="MISC">http://secunia.com/secunia_research/2005-19/advisory/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="8.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2409" published="2005-08-01" name="CVE-2005-2409" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://people.freebsd.org/~niels/issues/nbsmtp-20050726.txt" source="MISC" patch="1">http://people.freebsd.org/~niels/issues/nbsmtp-20050726.txt</ref>
      <ref url="http://www.vuxml.org/freebsd/debbb39c-fdb3-11d9-a30d-00b0d09acbfc.html" source="CONFIRM">http://www.vuxml.org/freebsd/debbb39c-fdb3-11d9-a30d-00b0d09acbfc.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21674" source="XF">nbsmtp-format-string(21674)</ref>
      <ref url="http://www.securityfocus.com/bid/14441" source="BID">14441</ref>
      <ref url="http://secunia.com/advisories/16324" source="SECUNIA">16324</ref>
      <ref url="http://secunia.com/advisories/16279" source="SECUNIA">16279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nbsmtp" name="nbsmtp">
        <vers prev="1" num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2410" published="2005-08-01" name="CVE-2005-2410" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://mail.gnome.org/archives/networkmanager-list/2005-July/msg00197.html" source="MLIST">[gnome-networkmanager-list] 20050729 Re: format string bug in nm_info_handler</ref>
      <ref url="http://mail.gnome.org/archives/networkmanager-list/2005-July/msg00196.html" source="MLIST">[gnome-networkmanager-list] 20050728 format string bug in nm_info_handler</ref>
      <ref url="http://lwn.net/Alerts/145678/" source="FEDORA">FEDORA-2005-680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="networkmanager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2411" published="2005-08-01" name="CVE-2005-2411" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on the server, via a URL that is activated by the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21735" source="XF">tdiary-xs-request-forgery(21735)</ref>
      <ref url="http://www.securityfocus.com/bid/14500" source="BID">14500</ref>
      <ref url="http://www.osvdb.org/18604" source="OSVDB">18604</ref>
      <ref url="http://www.debian.org/security/2005/dsa-808" source="DEBIAN">DSA-808</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=482743" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=482743</ref>
      <ref url="http://secunia.com/advisories/16787" source="SECUNIA">16787</ref>
      <ref url="http://secunia.com/advisories/16329" source="SECUNIA">16329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tdiary" name="tdiary">
        <vers prev="1" num="2.0.1" />
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2412" published="2005-08-03" name="CVE-2005-2412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21513" source="XF">php-firstpost-block-file-include(21513)</ref>
      <ref url="http://www.securityfocus.com/bid/14371" source="BID">14371</ref>
      <ref url="http://www.osvdb.org/18394" source="OSVDB">18394</ref>
      <ref url="http://securitytracker.com/id?1014563" source="SECTRACK">1014563</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230599222543&amp;w=2" source="BUGTRAQ">20050724 PHP FirstPost remote file include vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_firstpost" name="php_firstpost">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2413" published="2005-08-03" name="CVE-2005-2413" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21562" source="XF">apa-apaphpinclude-file-include(21562)</ref>
      <ref url="http://www.securityfocus.com/bid/14368" source="BID">14368</ref>
      <ref url="http://www.osvdb.org/18265" source="OSVDB">18265</ref>
      <ref url="http://securitytracker.com/id?1014569" source="SECTRACK">1014569</ref>
      <ref url="http://secunia.com/advisories/16201" source="SECUNIA">16201</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230428725189&amp;w=2" source="BUGTRAQ">20050723 Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atomic_photo_album" name="atomic_photo_album">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.1.0_pre1" />
        <vers num="1.1.0_pre2" />
        <vers num="1.1.0_pre3" />
        <vers num="1.1.0_pre4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2414" published="2005-08-03" name="CVE-2005-2414" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21472" source="XF">mozilla-xpcom-race-condition(21472)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00091-07212005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00091-07212005</ref>
      <ref url="http://securitytracker.com/id?1014550" source="SECTRACK">1014550</ref>
      <ref url="http://securitytracker.com/id?1014548" source="SECTRACK">1014548</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112199282029269&amp;w=2" source="BUGTRAQ">20050721 Mozilla XPCOM Library Race Condition</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpcom" name="xpcom">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2415" published="2005-08-03" name="CVE-2005-2415" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory_112005.59.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_112005.59.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21482" source="XF">contrexx-votingoption-pld-sql-injection(21482)</ref>
      <ref url="http://www.securityfocus.com/bid/14352" source="BID">14352</ref>
      <ref url="http://www.osvdb.org/18167" source="OSVDB">18167</ref>
      <ref url="http://www.osvdb.org/18166" source="OSVDB">18166</ref>
      <ref url="http://securitytracker.com/id?1014554" source="SECTRACK">1014554</ref>
      <ref url="http://secunia.com/advisories/16169" source="SECUNIA">16169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112206702015439&amp;w=2" source="BUGTRAQ">20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="astalavista_it_engineering" name="contrexx">
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2416" published="2005-08-03" name="CVE-2005-2416" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory_112005.59.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_112005.59.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21487" source="XF">contrexx-blog-xss(21487)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21484" source="XF">contrexx-search-xss(21484)</ref>
      <ref url="http://www.securityfocus.com/bid/14352" source="BID">14352</ref>
      <ref url="http://www.osvdb.org/18169" source="OSVDB">18169</ref>
      <ref url="http://www.osvdb.org/18168" source="OSVDB">18168</ref>
      <ref url="http://securitytracker.com/id?1014554" source="SECTRACK">1014554</ref>
      <ref url="http://secunia.com/advisories/16169" source="SECUNIA">16169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112206702015439&amp;w=2" source="BUGTRAQ">20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="astalavista_it_engineering" name="contrexx">
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2417" published="2005-08-03" name="CVE-2005-2417" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory_112005.59.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_112005.59.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21488" source="XF">contrexx-version-disclosure(21488)</ref>
      <ref url="http://www.securityfocus.com/bid/14352" source="BID">14352</ref>
      <ref url="http://www.osvdb.org/18170" source="OSVDB">18170</ref>
      <ref url="http://securitytracker.com/id?1014554" source="SECTRACK">1014554</ref>
      <ref url="http://secunia.com/advisories/16169" source="SECUNIA">16169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112206702015439&amp;w=2" source="BUGTRAQ">20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="astalavista_it_engineering" name="contrexx">
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-2418" reject="1" published="2005-08-03" name="CVE-2005-2418" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2403.  Reason: This candidate is a duplicate of CVE-2005-2403.  Notes: All CVE users should reference CVE-2005-2403 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2005-2419" published="2005-08-03" name="CVE-2005-2419" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request to firmwarecfg.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21521" source="XF">eci-router-login-security-bypass(21521)</ref>
      <ref url="http://www.securityfocus.com/bid/14364" source="BID">14364</ref>
      <ref url="http://secunia.com/advisories/16205" source="SECUNIA">16205</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230649106740&amp;w=2" source="BUGTRAQ">20050724 ECI router login bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eci_telecom" name="b-focus_router">
        <vers num="312" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2420" published="2005-08-03" name="CVE-2005-2420" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21540" source="XF">ftplocate-fsite-command-execution(21540)</ref>
      <ref url="http://www.securityfocus.com/bid/14367" source="BID">14367</ref>
      <ref url="http://www.osvdb.org/18305" source="OSVDB">18305</ref>
      <ref url="http://securitytracker.com/id?1014570" source="SECTRACK">1014570</ref>
      <ref url="http://secunia.com/advisories/16218" source="SECUNIA">16218</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230697123357&amp;w=2" source="BUGTRAQ">20050725 Chroot Security Group Advisory  2005-07-25  -- ftplocate</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2421" published="2005-08-03" name="CVE-2005-2421" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21535" source="XF">beehiveforum-webtag-sql-injection(21535)</ref>
      <ref url="http://www.securityfocus.com/bid/14361" source="BID">14361</ref>
      <ref url="http://secunia.com/advisories/16217" source="SECUNIA">16217</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230744103930&amp;w=2" source="BUGTRAQ">20050725 Beehive Forum Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beehive_forum" name="beehive_forum">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6rc1" />
        <vers num="0.6rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2422" published="2005-08-03" name="CVE-2005-2422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14363" source="BID">14363</ref>
      <ref url="http://secunia.com/advisories/16217" source="SECUNIA">16217</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230744103930&amp;w=2" source="BUGTRAQ">20050725 Beehive Forum Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beehive_forum" name="beehive_forum">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6rc1" />
        <vers num="0.6rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2423" published="2005-08-03" name="CVE-2005-2423" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Beehive Forum allows remote attackers to obtain sensitive information via (1) an invalid final_uri or sort_by parameter to index.php or a direct request to (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.php, (7) db.inc.php, (8) dictionary.inc.php or (9) search_index.php, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21536" source="XF">beehive-path-disclosure(21536)</ref>
      <ref url="http://secunia.com/advisories/16217" source="SECUNIA">16217</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230744103930&amp;w=2" source="BUGTRAQ">20050725 Beehive Forum Multiple Vulnerabilities</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2424" published="2005-08-03" name="CVE-2005-2424" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securenetwork.it/advisories/" source="MISC" adv="1">http://www.securenetwork.it/advisories/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21552" source="XF">santis50-packet-gain-access(21552)</ref>
      <ref url="http://www.securityfocus.com/bid/14372" source="BID">14372</ref>
      <ref url="http://www.osvdb.org/18294" source="OSVDB">18294</ref>
      <ref url="http://secunia.com/advisories/16215" source="SECUNIA">16215</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230914431638&amp;w=2" source="BUGTRAQ">20050725 Siemens SANTIS 50 Authentication Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="santis_50">
        <vers num="4.2.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2425" published="2005-08-03" name="CVE-2005-2425" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a (1) long history parameter in the configuration file (ares.conf) or (2) long search string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21818" source="XF">aresfileshare-long-string-bo(21818)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21557" source="XF">ares-longconfstring-bo(21557)</ref>
      <ref url="http://www.securityfocus.com/bid/14377" source="BID">14377</ref>
      <ref url="http://securitytracker.com/id?1014576" source="SECTRACK">1014576</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112239196706345&amp;w=2" source="BUGTRAQ">20050725 Ares FileShare 1.1 'Long Searched String' Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ares" name="fileshare">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2426" published="2005-08-03" name="CVE-2005-2426" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21531" source="XF">ftpshell-port-dos(21531)</ref>
      <ref url="http://www.securityfocus.com/bid/14382" source="BID">14382</ref>
      <ref url="http://securitytracker.com/id?1014580" source="SECTRACK">1014580</ref>
      <ref url="http://secunia.com/advisories/16189" source="SECUNIA">16189</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112239297430460&amp;w=2" source="BUGTRAQ">20050726 Denial of service vulnerability in FTPshell Server Version 3.38</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftpshell" name="ftpshell_server">
        <vers num="3.38" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2427" published="2005-08-03" name="CVE-2005-2427" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21554" source="XF">cartwiz-viewcart-xss(21554)</ref>
      <ref url="http://www.securityfocus.com/bid/14386" source="BID">14386</ref>
      <ref url="http://www.osvdb.org/18463" source="OSVDB">18463</ref>
      <ref url="http://securitytracker.com/id?1014581" source="SECTRACK">1014581</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112240525414263&amp;w=2" source="BUGTRAQ">20050726 [HSC Security Group] XSS in CartWiz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elemental_software" name="cartwiz">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2428" published="2005-08-03" name="CVE-2005-2428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21556" source="XF">lotus-domino-names-obtain-information(21556)</ref>
      <ref url="http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf" source="MISC" adv="1">http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21212934" source="CONFIRM" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg21212934</ref>
      <ref url="http://secunia.com/advisories/16231/" source="SECUNIA" adv="1">16231</ref>
      <ref url="http://www.securityfocus.com/bid/14389" source="BID">14389</ref>
      <ref url="http://www.securiteam.com/securitynews/5FP0E15GLQ.html" source="MISC">http://www.securiteam.com/securitynews/5FP0E15GLQ.html</ref>
      <ref url="http://www.osvdb.org/18462" source="OSVDB">18462</ref>
      <ref url="http://securitytracker.com/id?1014584" source="SECTRACK">1014584</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112240869130356&amp;w=2" source="BUGTRAQ">20050726 CYBSEC - Security Advisory: Default Configuration Information</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2429" published="2005-08-03" name="CVE-2005-2429" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24346" source="XF">office-mso97shareddg-dos(24346)</ref>
      <ref url="http://www.osvdb.org/18484" source="OSVDB">18484</ref>
      <ref url="http://secunia.com/advisories/16256" source="SECUNIA">16256</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112248181422193&amp;w=2" source="BUGTRAQ">20050727 Shared section vulnerability when opening microsoft office</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="2.0" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2430" published="2005-08-03" name="CVE-2005-2430" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to detail.php, (5) the text field on the search page, (6) group_id parameter to qrs.php, (7) form, (8) rows, (9) cols or (10) wrap parameter to notepad.php, or the login field on the login form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21558" source="XF">gforge-multiple-xss(21558)</ref>
      <ref url="http://secunia.com/advisories/16253/" source="SECUNIA" adv="1">16253</ref>
      <ref url="http://www.securityfocus.com/bid/14405" source="BID">14405</ref>
      <ref url="http://www.osvdb.org/18304" source="OSVDB">18304</ref>
      <ref url="http://www.osvdb.org/18303" source="OSVDB">18303</ref>
      <ref url="http://www.osvdb.org/18302" source="OSVDB">18302</ref>
      <ref url="http://www.osvdb.org/18301" source="OSVDB">18301</ref>
      <ref url="http://www.osvdb.org/18300" source="OSVDB">18300</ref>
      <ref url="http://www.osvdb.org/18299" source="OSVDB">18299</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1094" source="DEBIAN">DSA-1094</ref>
      <ref url="http://secunia.com/advisories/20622" source="SECUNIA">20622</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112259845904350&amp;w=2" source="BUGTRAQ">20050727 Cross Site Scripting vulnerabilities in GForge</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2431" published="2005-08-03" name="CVE-2005-2431" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112259845904350&amp;w=2" source="BUGTRAQ">20050727 Cross Site Scripting vulnerabilities in GForge</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2432" published="2005-08-03" name="CVE-2005-2432" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21576" source="XF">phplist-id-sql-injection(21576)</ref>
      <ref url="http://www.securityfocus.com/bid/14403" source="BID">14403</ref>
      <ref url="http://www.osvdb.org/18316" source="OSVDB">18316</ref>
      <ref url="http://securitytracker.com/id?1014607" source="SECTRACK">1014607</ref>
      <ref url="http://secunia.com/advisories/16274" source="SECUNIA" adv="1">16274</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291396731712&amp;w=2" source="BUGTRAQ">20050731 PHPList Vunerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112258115325054&amp;w=2" source="BUGTRAQ">20050728 PhpList Sql Injection and Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tincan" name="phplist">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2433" published="2005-08-03" name="CVE-2005-2433" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21579" source="XF">phplist-multiple-scripts-path-disclosure(21579)</ref>
      <ref url="http://www.osvdb.org/18329" source="OSVDB">18329</ref>
      <ref url="http://www.osvdb.org/18328" source="OSVDB">18328</ref>
      <ref url="http://www.osvdb.org/18327" source="OSVDB">18327</ref>
      <ref url="http://www.osvdb.org/18326" source="OSVDB">18326</ref>
      <ref url="http://www.osvdb.org/18325" source="OSVDB">18325</ref>
      <ref url="http://www.osvdb.org/18324" source="OSVDB">18324</ref>
      <ref url="http://www.osvdb.org/18323" source="OSVDB">18323</ref>
      <ref url="http://www.osvdb.org/18322" source="OSVDB">18322</ref>
      <ref url="http://www.osvdb.org/18321" source="OSVDB">18321</ref>
      <ref url="http://www.osvdb.org/18320" source="OSVDB">18320</ref>
      <ref url="http://www.osvdb.org/18319" source="OSVDB">18319</ref>
      <ref url="http://www.osvdb.org/18318" source="OSVDB">18318</ref>
      <ref url="http://www.osvdb.org/18317" source="OSVDB">18317</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112258115325054&amp;w=2" source="BUGTRAQ">20050728 PhpList Sql Injection and Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tincan" name="phplist">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2434" published="2005-08-03" name="CVE-2005-2434" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff the SSL connection and obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21635" source="XF">linksys-wrt54g-session-decrypt(21635)</ref>
      <ref url="http://www.securityfocus.com/bid/14407" source="BID">14407</ref>
      <ref url="http://securitytracker.com/id?1014596" source="SECTRACK">1014596</ref>
      <ref url="http://secunia.com/advisories/16271" source="SECUNIA">16271</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112258422806340&amp;w=2" source="BUGTRAQ">20050728 Vulnerability in Linksys Router access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="wrt54g">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2435" published="2005-08-03" name="CVE-2005-2435" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21631" source="XF">website-baker-browse-xss(21631)</ref>
      <ref url="http://www.securityfocus.com/bid/14404" source="BID">14404</ref>
      <ref url="http://www.osvdb.org/18342" source="OSVDB">18342</ref>
      <ref url="http://secunia.com/advisories/16263" source="SECUNIA">16263</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112260471228762&amp;w=2" source="BUGTRAQ">20050728 Website Baker Project Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="website_baker" name="website_baker">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2436" published="2005-08-03" name="CVE-2005-2436" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21633" source="XF">website-baker-url-path-disclosure(21633)</ref>
      <ref url="http://www.osvdb.org/18344" source="OSVDB">18344</ref>
      <ref url="http://www.osvdb.org/18343" source="OSVDB">18343</ref>
      <ref url="http://secunia.com/advisories/16263" source="SECUNIA">16263</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112260471228762&amp;w=2" source="BUGTRAQ">20050728 Website Baker Project Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="website_baker" name="website_baker">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2437" published="2005-08-03" name="CVE-2005-2437" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21634" source="XF">website-baker-adminmedia-file-upload(21634)</ref>
      <ref url="http://www.securityfocus.com/bid/14406" source="BID">14406</ref>
      <ref url="http://www.osvdb.org/18345" source="OSVDB">18345</ref>
      <ref url="http://secunia.com/advisories/16263" source="SECUNIA">16263</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112260471228762&amp;w=2" source="BUGTRAQ">20050728 Website Baker Project Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="website_baker" name="website_baker">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2438" published="2005-08-03" name="CVE-2005-2438" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory_122005.60.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_122005.60.html</ref>
      <ref url="http://www.usebb.net/community/topic.php?id=605" source="CONFIRM">http://www.usebb.net/community/topic.php?id=605</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21651" source="XF">usebb-colorbbcode-xss(21651)</ref>
      <ref url="http://www.securityfocus.com/bid/14412" source="BID">14412</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112264706213040&amp;w=2" source="BUGTRAQ">20050728 Advisory 12/2005: UseBB Multiple Vulnerabilities</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2439" published="2005-08-03" name="CVE-2005-2439" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.usebb.net/community/topic.php?id=605" source="CONFIRM" patch="1">http://www.usebb.net/community/topic.php?id=605</ref>
      <ref url="http://www.hardened-php.net/advisory_122005.60.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_122005.60.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21652" source="XF">usebb-search-sql-injection(21652)</ref>
      <ref url="http://www.securityfocus.com/bid/14413" source="BID">14413</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112264706213040&amp;w=2" source="BUGTRAQ">20050728 Advisory 12/2005: UseBB Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usebb" name="usebb">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.3a" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.5" />
        <vers num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2440" published="2005-08-03" name="CVE-2005-2440" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in Thomson Web Skill Vantage Manager allows remote attackers to execute arbitrary SQL commands via the svmPassword parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21637" source="XF">webskill-login-sql-injection(21637)</ref>
      <ref url="http://www.securityfocus.com/bid/14409" source="BID">14409</ref>
      <ref url="http://secunia.com/advisories/16268/" source="SECUNIA" adv="1">16268</ref>
      <ref url="http://www.osvdb.org/18330" source="OSVDB">18330</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112258777107822&amp;w=2" source="BUGTRAQ">20050728 Thomson Web Skill Vantage Manager</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomson_netg" name="web_skill_vantage_manager">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2441" published="2005-08-03" name="CVE-2005-2441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21680" source="XF">vbzoom-profile-login-xss(21680)</ref>
      <ref url="http://www.securityfocus.com/bid/14423" source="BID">14423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426874/100/0/threaded" source="BUGTRAQ">20060306 SQL injection &amp; XSS IN vbzoom v1.11</ref>
      <ref url="http://www.osvdb.org/18663" source="OSVDB">18663</ref>
      <ref url="http://www.osvdb.org/18662" source="OSVDB">18662</ref>
      <ref url="http://securitytracker.com/id?1014614" source="SECTRACK">1014614</ref>
      <ref url="http://secunia.com/advisories/16220" source="SECUNIA">16220</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112300586019568&amp;w=2" source="BUGTRAQ">20050729 VBZoom Cross Site Scripting Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vbzoom" name="vbzoom">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2442" published="2005-08-03" name="CVE-2005-2442" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Javascript from one application into another.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21541" source="XF">spidynamics-webinspect-xas(21541)</ref>
      <ref url="http://www.securityfocus.com/bid/14385" source="BID">14385</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-July/035414.html" source="FULLDISC" adv="1">20050726 SPIDynamics WebInspect Cross-Application Scripting (XAS)</ref>
      <ref url="http://securitytracker.com/id?1014582" source="SECTRACK">1014582</ref>
      <ref url="http://secunia.com/advisories/16191" source="SECUNIA">16191</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112264765216499&amp;w=2" source="BUGTRAQ">20050728 SPIDynamics WebInspect Cross-ApplicationScripting (XAS)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112239353829324&amp;w=2" source="BUGTRAQ">20050726 SPIDynamics WebInspect Cross-Application Scripting (XAS)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spi_dynamics" name="webinspect">
        <vers num="5.0.196" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2443" published="2005-08-03" name="CVE-2005-2443" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kshout 2.x and 3.x stores settings.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soulblack.com.ar/repo/papers/advisory/kshout_advisory.txt" source="MISC">http://www.soulblack.com.ar/repo/papers/advisory/kshout_advisory.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24352" source="XF">kshout-settings-information-disclosure(24352)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274114623893&amp;w=2" source="BUGTRAQ">20050729 Kshout Data Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kshout" name="kshout">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2444" published="2005-08-03" name="CVE-2005-2444" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Trillian Pro 3.1 build 121, when checking Yahoo e-mail, stores the password in plaintext in a world readable file and does not delete the file after login, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21667" source="XF">trillian-mail-plaintext-password(21667)</ref>
      <ref url="http://secunia.com/advisories/16289" source="SECUNIA">16289</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274667603628&amp;w=2" source="BUGTRAQ">20050730 Trillian Ver 3.1 saves password's in plain Text</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_studios" name="trillian_pro">
        <vers num="3.1_build_121" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2445" published="2005-08-03" name="CVE-2005-2445" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewPrd.asp in Product Cart 2.6 allows remote attackers to execute arbitrary SQL commands via the idcategory parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21672" source="XF">productcart-viewprd-sql-injection(21672)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20956" source="XF">productcart-multiple-script-sql-injection(20956)</ref>
      <ref url="http://www.securityfocus.com/bid/13881" source="BID">13881</ref>
      <ref url="http://www.osvdb.org/18508" source="OSVDB">18508</ref>
      <ref url="http://www.osvdb.org/17329" source="OSVDB">17329</ref>
      <ref url="http://securitytracker.com/id?1014129" source="SECTRACK">1014129</ref>
      <ref url="http://secunia.com/advisories/14833" source="SECUNIA">14833</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274710020521&amp;w=2" source="BUGTRAQ">20050730 [HSC Security Group] SQL Injection in Product Cart 2.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="product_cart">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-2446" reject="1" published="2005-08-03" name="CVE-2005-2446" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2369.  Reason: This candidate is a duplicate of CVE-2005-2369.  Notes: All CVE users should reference CVE-2005-2369 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" seq="2005-2447" reject="1" published="2005-08-03" name="CVE-2005-2447" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2370.  Reason: This candidate is a duplicate of CVE-2005-2370.  Notes: All CVE users should reference CVE-2005-2370 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <other />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2448" published="2005-08-03" name="CVE-2005-2448" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple "endianness errors" in libgadu in ekg before 1.6rc2 allow remote attackers to cause a denial of service (invalid behavior in applications) on big-endian systems.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11263" source="OVAL">oval:org.mitre.oval:def:11263</ref>
      <ref url="http://www.securityfocus.com/bid/24600" source="BID">24600</ref>
      <ref url="http://www.securityfocus.com/bid/14415" source="BID">14415</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1318" source="DEBIAN">DSA-1318</ref>
      <ref url="http://www.debian.org/security/2005/dsa-813" source="DEBIAN">DSA-813</ref>
      <ref url="http://secunia.com/advisories/16363" source="SECUNIA">16363</ref>
      <ref url="http://secunia.com/advisories/16155" source="SECUNIA">16155</ref>
      <ref url="http://secunia.com/advisories/16140" source="SECUNIA">16140</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2" source="BUGTRAQ">20050721 Multiple vulnerabilities in libgadu and ekg package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="1.1" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6_rc1" />
        <vers num="2005-04-11" />
        <vers num="2005-06-05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2449" published="2005-08-03" name="CVE-2005-2449" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in sandbox before 1.2.11 allows local users to create or overwrite arbitrary files via symlink attack on sandboxpids.tmp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200507-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200507-22</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=96782" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=96782</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21519" source="XF">sandbox-race-condition(21519)</ref>
      <ref url="http://www.securityfocus.com/bid/14375" source="BID">14375</ref>
      <ref url="http://securitytracker.com/id?1014574" source="SECTRACK">1014574</ref>
      <ref url="http://secunia.com/advisories/16214" source="SECUNIA">16214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sandbox" name="sandbox">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.1_r3" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.5_r1" />
        <vers num="1.2.5_r2" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2450" published="2005-08-03" name="CVE-2005-2450" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21555" source="XF" patch="1">clam-antivirus-file-format-gain-access(21555)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=344514" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=344514</ref>
      <ref url="http://www.securityfocus.com/bid/14359" source="BID">14359</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200507-25.xml" source="GENTOO">GLSA-200507-25</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000987" source="CONECTIVA">CLSA-2005:987</ref>
      <ref url="http://www.osvdb.org/18259" source="OSVDB">18259</ref>
      <ref url="http://www.osvdb.org/18258" source="OSVDB">18258</ref>
      <ref url="http://www.osvdb.org/18257" source="OSVDB">18257</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
      <ref url="http://secunia.com/advisories/16458" source="SECUNIA">16458</ref>
      <ref url="http://secunia.com/advisories/16296" source="SECUNIA">16296</ref>
      <ref url="http://secunia.com/advisories/16250" source="SECUNIA">16250</ref>
      <ref url="http://secunia.com/advisories/16229" source="SECUNIA">16229</ref>
      <ref url="http://secunia.com/advisories/16180" source="SECUNIA">16180</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230864412932&amp;w=2" source="BUGTRAQ">20050725 ClamAV Multiple Rem0te Buffer Overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2451" published="2005-08-03" name="CVE-2005-2451" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-210A.html" source="CERT">TA05-210A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/930892" source="CERT-VN">VU#930892</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21591" source="XF" patch="1">cisco-ios-ipv6-packet-command-execution(21591)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050729-ipv6.shtml" source="CISCO" patch="1" adv="1">20050729 IPv6 Crafted Packet Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5445" source="OVAL">oval:org.mitre.oval:def:5445</ref>
      <ref url="http://www.securityfocus.com/bid/14414" source="BID">14414</ref>
      <ref url="http://www.osvdb.org/18332" source="OSVDB">18332</ref>
      <ref url="http://securitytracker.com/id?1014598" source="SECTRACK">1014598</ref>
      <ref url="http://secunia.com/advisories/16272" source="SECUNIA">16272</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0663.html" source="FULLDISC">20050729 Cisco IOS Shellcode Presentation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0s" />
        <vers num="12.0sl" />
        <vers num="12.0st" />
        <vers num="12.0sy" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2eu" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ez" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2mx" />
        <vers num="12.2s" />
        <vers num="12.2seb" />
        <vers num="12.2sec" />
        <vers num="12.2so" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xw" />
        <vers num="12.2xz" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zn" />
        <vers num="12.2zo" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xm" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xt" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
      </prod>
      <prod vendor="cisco" name="ios_xr">
        <vers num="3.0.1" />
        <vers num="3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2452" published="2005-08-03" name="CVE-2005-2452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-156-1" source="UBUNTU" patch="1">USN-156-1</ref>
      <ref url="https://bugzilla.ubuntu.com/show_bug.cgi?id=12008" source="MISC">https://bugzilla.ubuntu.com/show_bug.cgi?id=12008</ref>
      <ref url="http://www.securityfocus.com/bid/14417" source="BID">14417</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:144" source="MANDRAKE">MDKSA-2005:144</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:143" source="MANDRAKE">MDKSA-2005:143</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:142" source="MANDRAKE">MDKSA-2005:142</ref>
      <ref url="http://secunia.com/advisories/16486" source="SECUNIA" adv="1">16486</ref>
      <ref url="http://secunia.com/advisories/16266" source="SECUNIA" adv="1">16266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.5.5" />
        <vers num="3.5.7" />
        <vers num="3.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2453" published="2005-08-04" name="CVE-2005-2453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2005-31/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-31/advisory/</ref>
      <ref url="http://secunia.com/advisories/16301" source="SECUNIA" patch="1" adv="1">16301</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21696" source="XF">networkactiv-xss(21696)</ref>
      <ref url="http://www.securityfocus.com/bid/14473" source="BID">14473</ref>
      <ref url="http://www.osvdb.org/18525" source="OSVDB">18525</ref>
      <ref url="http://securitytracker.com/id?1014624" source="SECTRACK">1014624</ref>
    </refs>
    <vuln_soft>
      <prod vendor="networkactiv" name="networkactiv_web_server">
        <vers num="1.0" />
        <vers num="2.0.0.6" />
        <vers num="3.0.1.1" />
        <vers num="3.5.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2454" published="2005-12-31" name="CVE-2005-2454" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 7.0.2.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/383092" source="CERT-VN">VU#383092</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29660" source="XF">lotusnotes-directory-insecure-permission(29660)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4093" source="VUPEN" adv="1">ADV-2006-4093</ref>
      <ref url="http://www.securityfocus.com/bid/20612" source="BID">20612</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449126/100/0/threaded" source="BUGTRAQ">20061018 Secunia Research: IBM Lotus Notes Insecure Default FolderPermissions</ref>
      <ref url="http://www.osvdb.org/29761" source="OSVDB">29761</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21246773" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21246773</ref>
      <ref url="http://securitytracker.com/id?1017086" source="SECTRACK">1017086</ref>
      <ref url="http://secunia.com/secunia_research/2005-29/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-29/advisory/</ref>
      <ref url="http://secunia.com/advisories/27342" source="SECUNIA" adv="1">27342</ref>
      <ref url="http://secunia.com/advisories/19537" source="SECUNIA" adv="1">19537</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="7.0.0" />
        <vers num="7.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2455" published="2005-08-04" name="CVE-2005-2455" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API function, (2) list installed scripts using GM_scripts, or obtain sensitive information via (3) GM_setValue and GM_getValue.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21453" source="XF" patch="1">mozilla-greasemonkey-information-disclosure(21453)</ref>
      <ref url="http://www.securityfocus.com/bid/14336" source="BID" patch="1">14336</ref>
      <ref url="http://www.securiteam.com/securitynews/5CP0P20GBK.html" source="MISC" patch="1">http://www.securiteam.com/securitynews/5CP0P20GBK.html</ref>
      <ref url="http://securitytracker.com/id?1014529" source="SECTRACK" patch="1">1014529</ref>
      <ref url="http://secunia.com/advisories/16128" source="SECUNIA" patch="1" adv="1">16128</ref>
      <ref url="http://greasemonkey.mozdev.org/changes/0.3.5.html" source="CONFIRM" patch="1">http://greasemonkey.mozdev.org/changes/0.3.5.html</ref>
      <ref url="http://greaseblog.blogspot.com/2005/07/mandatory-greasemonkey-update.html" source="CONFIRM" patch="1">http://greaseblog.blogspot.com/2005/07/mandatory-greasemonkey-update.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1147" source="VUPEN">ADV-2005-1147</ref>
      <ref url="http://www.osvdb.org/18154" source="OSVDB">18154</ref>
      <ref url="http://mozdev.org/pipermail/greasemonkey/2005-July/004022.html" source="MLIST">[Greasemonkey] 20050718 greasemonkey for secure data over insecure networks / sites</ref>
      <ref url="http://mozdev.org/pipermail/greasemonkey/2005-July/004000.html" source="MLIST">[Greasemonkey] 20050718 greasemonkey for secure data over insecure networks / sites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greasemonkey" name="greasemonkey">
        <vers num="0.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2456" published="2005-08-04" name="CVE-2005-2456" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFRM_POLICY_OUT, which is used as an index in the sock->sk_policy array.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.mail-archive.com/netdev@vger.kernel.org/msg00520.html" source="MISC" patch="1">http://www.mail-archive.com/netdev@vger.kernel.org/msg00520.html</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a4f1bac62564049ea4718c4624b0fadc9f597c84" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a4f1bac62564049ea4718c4624b0fadc9f597c84</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=blobdiff;h=8da3e25b2c4c1f305fd85428d3a9eb62b543bfba;hp=ecade4893a139cc35d4fe345ce70242ede5358c4;hb=a4f1bac62564049ea4718c4624b0fadc9f597c84;f=net/xfrm/xfrm_user.c" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=blobdiff;h=8da3e25b2c4c1f305fd85428d3a9eb62b543bfba;hp=ecade4893a139cc35d4fe345ce70242ede5358c4;hb=a4f1bac62564049ea4718c4624b0fadc9f597c84;f=net/xfrm/xfrm_user.c</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRAKE">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10858" source="OVAL">oval:org.mitre.oval:def:10858</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21710" source="XF">linux-kernel-xfrm-dos(21710)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1" source="UBUNTU">USN-169-1</ref>
      <ref url="http://www.securityfocus.com/bid/14477" source="BID">14477</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html" source="SUSE">SUSE-SA:2005:050</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRIVA">MDKSA-2005:219</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://www.debian.org/security/2005/dsa-921" source="DEBIAN">DSA-921</ref>
      <ref url="http://secunia.com/advisories/18059" source="SECUNIA">18059</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://secunia.com/advisories/16500" source="SECUNIA">16500</ref>
      <ref url="http://secunia.com/advisories/16298" source="SECUNIA">16298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2457" published="2005-08-23" name="CVE-2005-2457" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The driver for compressed ISO file systems (zisofs) in the Linux kernel before 2.6.12.5 allows local users and remote attackers to cause a denial of service (kernel crash) via a crafted compressed ISO file system.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1" source="UBUNTU" adv="1">USN-169-1</ref>
      <ref url="http://www.securityfocus.com/bid/14614" source="BID">14614</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://secunia.com/advisories/16355/" source="SECUNIA">16355</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded" source="SUSE">SUSE-SA:2005:068</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html" source="SUSE">SUSE-SA:2005:050</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRIVA">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" source="MANDRAKE">MDKSA-2005:218</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1018" source="DEBIAN">DSA-1018</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA">19374</ref>
      <ref url="http://secunia.com/advisories/19369" source="SECUNIA">19369</ref>
      <ref url="http://secunia.com/advisories/17918" source="SECUNIA">17918</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
      <ref url="http://secunia.com/advisories/16500" source="SECUNIA">16500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2458" published="2005-08-23" name="CVE-2005-2458" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16355/" source="SECUNIA" patch="1" adv="1">16355</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1" source="UBUNTU" adv="1">USN-169-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRAKE">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://sources.redhat.com/ml/bug-gnu-utils/1999-06/msg00183.html" source="MLIST">[bug-gnu-utils] 19990625 Re: bug in gzip: segfault when doing "gzip -t" on a broken file</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10785" source="OVAL">oval:org.mitre.oval:def:10785</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5</ref>
      <ref url="http://www.securityfocus.com/bid/14719" source="BID">14719</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded" source="FEDORA">FLSA:157459-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded" source="FEDORA">FLSA:157459-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded" source="SUSE">SUSE-SA:2005:068</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0191.html" source="REDHAT">RHSA-2006:0191</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0190.html" source="REDHAT">RHSA-2006:0190</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0144.html" source="REDHAT">RHSA-2006:0144</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0101.html" source="REDHAT">RHSA-2006:0101</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html" source="SUSE">SUSE-SA:2005:050</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRAKE">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://www.debian.org/security/2005/dsa-921" source="DEBIAN">DSA-921</ref>
      <ref url="http://secunia.com/advisories/19252" source="SECUNIA">19252</ref>
      <ref url="http://secunia.com/advisories/18684" source="SECUNIA">18684</ref>
      <ref url="http://secunia.com/advisories/18510" source="SECUNIA">18510</ref>
      <ref url="http://secunia.com/advisories/18059" source="SECUNIA">18059</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
      <ref url="http://secunia.com/advisories/17918" source="SECUNIA">17918</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
      <ref url="http://secunia.com/advisories/16500" source="SECUNIA">16500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2459" published="2005-08-23" name="CVE-2005-2459" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer dereference, a different vulnerbility than CVE-2005-2458.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16355/" source="SECUNIA" patch="1" adv="1">16355</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1" source="UBUNTU" adv="1">USN-169-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=94584" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=94584</ref>
      <ref url="http://www.securityfocus.com/bid/14720" source="BID">14720</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded" source="SUSE">SUSE-SA:2005:068</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html" source="SUSE">SUSE-SA:2005:050</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRIVA">MDKSA-2005:219</ref>
      <ref url="http://www.debian.org/security/2005/dsa-922" source="DEBIAN">DSA-922</ref>
      <ref url="http://www.debian.org/security/2005/dsa-921" source="DEBIAN">DSA-921</ref>
      <ref url="http://secunia.com/advisories/18059" source="SECUNIA">18059</ref>
      <ref url="http://secunia.com/advisories/18056" source="SECUNIA">18056</ref>
      <ref url="http://secunia.com/advisories/17918" source="SECUNIA">17918</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
      <ref url="http://secunia.com/advisories/16500" source="SECUNIA">16500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2460" published="2005-12-31" name="CVE-2005-2460" modified="2008-09-05" discovered="2005-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14425" source="BID">14425</ref>
      <ref url="http://www.osvdb.org/18397" source="OSVDB">18397</ref>
      <ref url="http://www.osvdb.org/18395" source="OSVDB">18395</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00092-07302005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00092-07302005</ref>
      <ref url="http://secunia.com/advisories/16286" source="SECUNIA" adv="1">16286</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274359718863&amp;w=2" source="BUGTRAQ">20050730 Kayako liveResponse Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="liveresponse">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2461" published="2005-12-31" name="CVE-2005-2461" modified="2008-09-05" discovered="2005-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14425" source="BID">14425</ref>
      <ref url="http://www.osvdb.org/18396" source="OSVDB">18396</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00092-07302005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00092-07302005</ref>
      <ref url="http://secunia.com/advisories/16286" source="SECUNIA" adv="1">16286</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274359718863&amp;w=2" source="BUGTRAQ">20050730 Kayako liveResponse Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="liveresponse">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2462" published="2005-12-31" name="CVE-2005-2462" modified="2008-09-05" discovered="2005-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and possibly remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14425" source="BID">14425</ref>
      <ref url="http://www.osvdb.org/18398" source="OSVDB">18398</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00092-07302005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00092-07302005</ref>
      <ref url="http://secunia.com/advisories/16286" source="SECUNIA" adv="1">16286</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274359718863&amp;w=2" source="BUGTRAQ">20050730 Kayako liveResponse Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="liveresponse">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2463" published="2005-12-31" name="CVE-2005-2463" modified="2008-09-05" discovered="2005-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and other include scripts, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14425" source="BID">14425</ref>
      <ref url="http://www.osvdb.org/18399" source="OSVDB">18399</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00092-07302005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00092-07302005</ref>
      <ref url="http://secunia.com/advisories/16286" source="SECUNIA" adv="1">16286</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274359718863&amp;w=2" source="BUGTRAQ">20050730 Kayako liveResponse Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="liveresponse">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2464" published="2005-12-31" name="CVE-2005-2464" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">login.php in PCXP/TOPPE CMS allows remote attackers to bypass authentication and gain privileges by modifying the cookie to match the target userid.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274251601106&amp;w=2" source="BUGTRAQ">20050730 PC-EXPERIENCE/TOPPE CMS Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcxp_toppe_cms" name="pcxp_toppe_cms">
        <vers num="1.15" />
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2465" published="2005-12-31" name="CVE-2005-2465" modified="2008-09-05" discovered="2005-07-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in pm.php in PCXP/TOPPE CMS allows remote attackers to inject arbitrary web script or HTML via the msg variable.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14428" source="BID">14428</ref>
      <ref url="http://www.osvdb.org/18715" source="OSVDB">18715</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274251601106&amp;w=2" source="BUGTRAQ">20050730 PC-EXPERIENCE/TOPPE CMS Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pc-experience" name="pc-experience">
        <vers num="1.15" />
        <vers num="2.0" />
      </prod>
      <prod vendor="toppe" name="toppe_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2466" published="2005-12-31" name="CVE-2005-2466" modified="2011-03-07" discovered="2005-07-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the auth_user function in admin.php in OpenBook 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21643" source="XF">openbook-authuser-sql-injection(21643)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1301" source="VUPEN">ADV-2005-1301</ref>
      <ref url="http://www.securityfocus.com/bid/14444" source="BID">14444</ref>
      <ref url="http://www.osvdb.org/18475" source="OSVDB">18475</ref>
      <ref url="http://securitytracker.com/id?1014606" source="SECTRACK">1014606</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291283419785&amp;w=2" source="BUGTRAQ">20050730 [SVadvisory] - SQL injection in OpenBook 1.2.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbook" name="openbook">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2467" published="2005-12-31" name="CVE-2005-2467" modified="2011-03-07" discovered="2005-07-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014603" source="SECTRACK" patch="1">1014603</ref>
      <ref url="http://secunia.com/advisories/16304" source="SECUNIA" patch="1" adv="1">16304</ref>
      <ref url="http://lists.mysql.com/eventum-users/2072" source="CONFIRM" patch="1">http://lists.mysql.com/eventum-users/2072</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1287" source="VUPEN">ADV-2005-1287</ref>
      <ref url="http://www.securityfocus.com/bid/14436" source="BID">14436</ref>
      <ref url="http://www.osvdb.org/18402" source="OSVDB">18402</ref>
      <ref url="http://www.osvdb.org/18401" source="OSVDB">18401</ref>
      <ref url="http://www.osvdb.org/18400" source="OSVDB">18400</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00093-07312005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00093-07312005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112292193807958&amp;w=2" source="BUGTRAQ">20050731 MySQL Eventum Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="eventum">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2468" published="2005-12-31" name="CVE-2005-2468" modified="2011-03-07" discovered="2005-07-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/18406" source="OSVDB" patch="1">18406</ref>
      <ref url="http://www.osvdb.org/18405" source="OSVDB" patch="1">18405</ref>
      <ref url="http://www.osvdb.org/18404" source="OSVDB" patch="1">18404</ref>
      <ref url="http://www.osvdb.org/18403" source="OSVDB" patch="1">18403</ref>
      <ref url="http://securitytracker.com/id?1014603" source="SECTRACK" patch="1">1014603</ref>
      <ref url="http://secunia.com/advisories/16304" source="SECUNIA" patch="1" adv="1">16304</ref>
      <ref url="http://lists.mysql.com/eventum-users/2072" source="CONFIRM" patch="1">http://lists.mysql.com/eventum-users/2072</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1287" source="VUPEN">ADV-2005-1287</ref>
      <ref url="http://www.securityfocus.com/bid/14437" source="BID">14437</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00093-07312005" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00093-07312005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112292193807958&amp;w=2" source="BUGTRAQ">20050731 MySQL Eventum Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="eventum">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2469" published="2005-10-20" name="CVE-2005-2469" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the NMAP Agent for Novell NetMail 3.52C and possibly earlier versions allows local users to execute arbitrary code via a long user name in the USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972438.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972438.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972433.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972433.htm</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972340.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972340.htm</ref>
      <ref url="http://secunia.com/secunia_research/2005-23/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-23/advisory/</ref>
      <ref url="http://secunia.com/advisories/15925/" source="SECUNIA" patch="1" adv="1">15925</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22727" source="XF">netmail-nmap-user-bo(22727)</ref>
      <ref url="http://www.securityfocus.com/bid/15080" source="BID">15080</ref>
      <ref url="http://www.osvdb.org/19916" source="OSVDB">19916</ref>
      <ref url="http://securitytracker.com/id?1015048" source="SECTRACK">1015048</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0299.html" source="FULLDISC">20051012 Secunia Research: Novell NetMail NMAP Agent "USER" Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netmail">
        <vers num="3.5.2" edition="c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2470" published="2005-08-16" name="CVE-2005-2470" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/896220" source="CERT-VN">VU#896220</ref>
      <ref url="http://www.adobe.com/support/techdocs/321644.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/321644.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1434" source="VUPEN">ADV-2005-1434</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21860" source="XF">adobe-acrobat-reader-plugin-bo(21860)</ref>
      <ref url="http://www.securityfocus.com/bid/14603" source="BID">14603</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-750.html" source="REDHAT">RHSA-2005:750</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200508-11.xml" source="GENTOO">GLSA-200508-11</ref>
      <ref url="http://securitytracker.com/id?1014712" source="SECTRACK">1014712</ref>
      <ref url="http://secunia.com/advisories/16466" source="SECUNIA">16466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="5.0" />
        <vers num="5.0.5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2471" published="2005-08-05" name="CVE-2005-2471" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21500" source="XF">netpbm-dsafer-command-execution(21500)</ref>
      <ref url="http://www.trustix.org/errata/2005/0038/" source="TRUSTIX" adv="1">2005-0038</ref>
      <ref url="http://www.securityfocus.com/bid/14379" source="BID">14379</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-743.html" source="REDHAT">RHSA-2005:743</ref>
      <ref url="http://www.osvdb.org/18253" source="OSVDB">18253</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE">SUSE-SR:2005:019</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1021" source="DEBIAN">DSA-1021</ref>
      <ref url="http://securitytracker.com/id?1014752" source="SECTRACK">1014752</ref>
      <ref url="http://secunia.com/advisories/19436" source="SECUNIA" adv="1">19436</ref>
      <ref url="http://secunia.com/advisories/18330" source="SECUNIA" adv="1">18330</ref>
      <ref url="http://secunia.com/advisories/16184" source="SECUNIA" adv="1">16184</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11645" source="OVAL">oval:org.mitre.oval:def:11645</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=319757" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=319757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netpbm" name="netpbm">
        <vers num="2.10.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2472" published="2005-08-05" name="CVE-2005-2472" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1) HELO or (2) MAIL FROM commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://reedarvin.thearvins.com/20050730-01.html" source="MISC" patch="1">http://reedarvin.thearvins.com/20050730-01.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-August/035647.html" source="FULLDISC" patch="1">20050801 Buffer overflow in BusinessMail email server system 4.60.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21636" source="XF">businessmail-smtp-dos(21636)</ref>
      <ref url="http://www.securityfocus.com/bid/14434" source="BID">14434</ref>
      <ref url="http://secunia.com/advisories/16306" source="SECUNIA" adv="1">16306</ref>
      <ref url="http://www.osvdb.org/18407" source="OSVDB">18407</ref>
      <ref url="http://securitytracker.com/id?1014602" source="SECTRACK">1014602</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291456305261&amp;w=2" source="BUGTRAQ">20050801 Buffer overflow in BusinessMail email server system 4.60.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netcplus" name="businessmail">
        <vers num="4.60.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2473" published="2005-08-05" name="CVE-2005-2473" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ChurchInfo allow remote attackers to execute arbitrary SQL commands via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, (8) DepositSlipID parameter to DepositSlipEditor.php, (9) QueryID parameter to QueryView.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21647" source="XF">churchinfo-sql-injection(21647)</ref>
      <ref url="http://www.securityfocus.com/bid/14438" source="BID">14438</ref>
      <ref url="http://www.osvdb.org/18428" source="OSVDB">18428</ref>
      <ref url="http://www.osvdb.org/18427" source="OSVDB">18427</ref>
      <ref url="http://www.osvdb.org/18424" source="OSVDB">18424</ref>
      <ref url="http://www.osvdb.org/18423" source="OSVDB">18423</ref>
      <ref url="http://www.osvdb.org/18422" source="OSVDB">18422</ref>
      <ref url="http://www.osvdb.org/18421" source="OSVDB">18421</ref>
      <ref url="http://www.osvdb.org/18420" source="OSVDB">18420</ref>
      <ref url="http://www.osvdb.org/18419" source="OSVDB">18419</ref>
      <ref url="http://www.osvdb.org/18418" source="OSVDB">18418</ref>
      <ref url="http://www.osvdb.org/18417" source="OSVDB">18417</ref>
      <ref url="http://www.osvdb.org/18416" source="OSVDB">18416</ref>
      <ref url="http://www.osvdb.org/18415" source="OSVDB">18415</ref>
      <ref url="http://www.osvdb.org/18414" source="OSVDB">18414</ref>
      <ref url="http://www.osvdb.org/18413" source="OSVDB">18413</ref>
      <ref url="http://www.osvdb.org/18412" source="OSVDB">18412</ref>
      <ref url="http://www.osvdb.org/18411" source="OSVDB">18411</ref>
      <ref url="http://www.osvdb.org/18410" source="OSVDB">18410</ref>
      <ref url="http://www.osvdb.org/18409" source="OSVDB">18409</ref>
      <ref url="http://www.osvdb.org/18408" source="OSVDB">18408</ref>
      <ref url="http://securitytracker.com/id?1014617" source="SECTRACK">1014617</ref>
      <ref url="http://secunia.com/advisories/16292" source="SECUNIA">16292</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291550713546&amp;w=2" source="BUGTRAQ">20050801 ChurchInfo Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="churchinfo" name="churchinfo">
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2474" published="2005-08-05" name="CVE-2005-2474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ChurchInfo allows remote attackers to execute obtain sensitive information via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, an invalid Number parameter to (8) SelectList.php or (9) SelectDelete.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php, which reveal the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21648" source="XF">churchinfo-path-disclosure(21648)</ref>
      <ref url="http://www.osvdb.org/18450" source="OSVDB">18450</ref>
      <ref url="http://www.osvdb.org/18439" source="OSVDB">18439</ref>
      <ref url="http://www.osvdb.org/18438" source="OSVDB">18438</ref>
      <ref url="http://www.osvdb.org/18437" source="OSVDB">18437</ref>
      <ref url="http://www.osvdb.org/18436" source="OSVDB">18436</ref>
      <ref url="http://www.osvdb.org/18435" source="OSVDB">18435</ref>
      <ref url="http://www.osvdb.org/18434" source="OSVDB">18434</ref>
      <ref url="http://www.osvdb.org/18433" source="OSVDB">18433</ref>
      <ref url="http://www.osvdb.org/18432" source="OSVDB">18432</ref>
      <ref url="http://www.osvdb.org/18431" source="OSVDB">18431</ref>
      <ref url="http://www.osvdb.org/18430" source="OSVDB">18430</ref>
      <ref url="http://www.osvdb.org/18429" source="OSVDB">18429</ref>
      <ref url="http://www.osvdb.org/18426" source="OSVDB">18426</ref>
      <ref url="http://www.osvdb.org/18425" source="OSVDB">18425</ref>
      <ref url="http://securitytracker.com/id?1014617" source="SECTRACK">1014617</ref>
      <ref url="http://secunia.com/advisories/16292" source="SECUNIA">16292</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291550713546&amp;w=2" source="BUGTRAQ">20050801 ChurchInfo Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="churchinfo" name="churchinfo">
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2475" published="2005-08-05" name="CVE-2005-2475" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9975" source="OVAL">oval:org.mitre.oval:def:9975</ref>
      <ref url="http://www.ubuntu.com/usn/usn-191-1" source="UBUNTU">USN-191-1</ref>
      <ref url="http://www.trustix.org/errata/2005/0053/" source="TRUSTIX">2005-0053</ref>
      <ref url="http://www.securityfocus.com/bid/14450" source="BID">14450</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0203.html" source="REDHAT">RHSA-2007:0203</ref>
      <ref url="http://www.osvdb.org/18530" source="OSVDB">18530</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:197" source="MANDRIVA">MDKSA-2005:197</ref>
      <ref url="http://www.debian.org/security/2005/dsa-903" source="DEBIAN">DSA-903</ref>
      <ref url="http://securityreason.com/securityalert/32" source="SREASON">32</ref>
      <ref url="http://secunia.com/advisories/25098" source="SECUNIA">25098</ref>
      <ref url="http://secunia.com/advisories/17653" source="SECUNIA">17653</ref>
      <ref url="http://secunia.com/advisories/17342" source="SECUNIA">17342</ref>
      <ref url="http://secunia.com/advisories/17045" source="SECUNIA">17045</ref>
      <ref url="http://secunia.com/advisories/17006" source="SECUNIA">17006</ref>
      <ref url="http://secunia.com/advisories/16985" source="SECUNIA">16985</ref>
      <ref url="http://secunia.com/advisories/16309" source="SECUNIA">16309</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112300046224117&amp;w=2" source="BUGTRAQ">20050801 unzip TOCTOU file-permissions vulnerability</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.39/SCOSA-2005.39.txt" source="SCO">SCOSA-2005.39</ref>
    </refs>
    <vuln_soft>
      <prod vendor="info-zip" name="unzip">
        <vers num="5.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2476" published="2005-08-05" name="CVE-2005-2476" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16262" source="SECUNIA" adv="1">16262</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21676" source="XF">naxtorshoppingcart-password-xss(21676)</ref>
      <ref url="http://www.securityfocus.com/bid/14454" source="BID">14454</ref>
      <ref url="http://securitytracker.com/id?1014613" source="SECTRACK">1014613</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112301600608192&amp;w=2" source="BUGTRAQ">20050802 [NOBYTES.COM: #8] Naxtor Shopping Cart 1.0 - Information Disclosure &amp; Possible SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="naxtor" name="shopping_cart">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2477" published="2005-08-05" name="CVE-2005-2477" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">shop_display_products.php in Naxtor Shopping Cart 1.0 allows remote attackers to obtain sensitive information via a cat_id with a "'" (single quote), which reveals the path in an error message, possibly due to an SQL injection vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16262" source="SECUNIA" adv="1">16262</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21677" source="XF">naxtorshoppingcart-path-disclosure(21677)</ref>
      <ref url="http://www.securityfocus.com/bid/14456" source="BID">14456</ref>
      <ref url="http://securitytracker.com/id?1014613" source="SECTRACK">1014613</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112301600608192&amp;w=2" source="BUGTRAQ">20050802 [NOBYTES.COM: #8] Naxtor Shopping Cart 1.0 - Information Disclosure &amp; Possible SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="naxtor" name="shopping_cart">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2478" published="2005-08-05" name="CVE-2005-2478" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in SilverNews 2.0.3 allows remote attackers to execute arbitrary SQL commands via the user field on the login page in the Admin control panel.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16315" source="SECUNIA" patch="1" adv="1">16315</ref>
      <ref url="http://www.securityfocus.com/bid/14466" source="BID">14466</ref>
      <ref url="http://www.rgod.altervista.org/silvernews.html" source="MISC">http://www.rgod.altervista.org/silvernews.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21688" source="XF">silvernews-username-sql-injection(21688)</ref>
      <ref url="http://www.osvdb.org/18517" source="OSVDB">18517</ref>
      <ref url="http://securitytracker.com/id?1014622" source="SECTRACK">1014622</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112309780321088&amp;w=2" source="BUGTRAQ">20050803 Silvernews 2.0.3 (possibly previous versions ) SQL Injection / Login Bypass / Remote commands execution / cross site scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silver-scripts" name="silvernews">
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2479" published="2005-08-05" name="CVE-2005-2479" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21679" source="XF">quickneasy-user-command-dos(21679)</ref>
      <ref url="http://www.securityfocus.com/bid/14451" source="BID">14451</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428812/100/0/threaded" source="BUGTRAQ">20060325 Re: Quick 'n Easy FTP Server 3.0 pro / lite (buffer overflow vulnerabilities)</ref>
      <ref url="http://securitytracker.com/id?1014615" source="SECTRACK">1014615</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112319110831249&amp;w=2" source="BUGTRAQ">20050803 Re: Re: Quick 'n Easy FTP Server 3.0 pro / lite (buffer overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112309262324047&amp;w=2" source="BUGTRAQ">20050802 Re: Quick 'n Easy FTP Server 3.0 pro / lite (buffer overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112300508617889&amp;w=2" source="BUGTRAQ">20050802 Quick 'n Easy FTP Server 3.0 pro / lite (buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pablo_software_solutions" name="quick_n_easy_ftp_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2480" published="2005-08-05" name="CVE-2005-2480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14460" source="BID">14460</ref>
      <ref url="http://secunia.com/advisories/16320" source="SECUNIA" adv="1">16320</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21697" source="XF">fusebox-fuseaction-xss(21697)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112309656102615&amp;w=2" source="BUGTRAQ">20050803 Coldfusion Fusebox V4.1.0 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion_fusebox">
        <vers num="4.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2481" published="2005-08-05" name="CVE-2005-2481" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112309656102615&amp;w=2" source="BUGTRAQ">20050803 Coldfusion Fusebox V4.1.0 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion_fusebox">
        <vers num="4.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2482" published="2005-08-07" name="CVE-2005-2482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16318" source="SECUNIA" patch="1" adv="1">16318</ref>
      <ref url="http://metasploit.com/archive/framework/msg00469.html" source="CONFIRM">http://metasploit.com/archive/framework/msg00469.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21705" source="XF">metasploit-defanged-bypass-security(21705)</ref>
      <ref url="http://www.securityfocus.com/bid/14455" source="BID">14455</ref>
      <ref url="http://www.osvdb.org/18495" source="OSVDB">18495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metasploit" name="metasploit_framework">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2483" published="2005-08-07" name="CVE-2005-2483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell services (.ks) script, which can reference functions from libraries that are used by that script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_id=12539317" source="MLIST" patch="1">[karrigell-main] 20050802 Re: SECURITY: python namespace exposure</ref>
      <ref url="http://secunia.com/advisories/16319" source="SECUNIA" adv="1">16319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21668" source="XF">karrigel-dos(21668)</ref>
      <ref url="http://www.securityfocus.com/bid/14463" source="BID">14463</ref>
      <ref url="http://www.osvdb.org/18506" source="OSVDB">18506</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=7863293&amp;forum_id=32318" source="MLIST">[karrigell-main] 20050731 SECURITY: python namespace exposure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="karrigell" name="karrigell">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0_beta" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2484" published="2005-08-07" name="CVE-2005-2484" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the rdb_query function for Denora IRC Stats 1.0 might allow attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21686" source="XF" patch="1">denora-rdbquery-bo(21686)</ref>
      <ref url="http://www.securityfocus.com/bid/14471" source="BID" patch="1">14471</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=346819" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=346819</ref>
      <ref url="http://secunia.com/advisories/16281" source="SECUNIA" patch="1" adv="1">16281</ref>
      <ref url="http://denora.nomadirc.net/index.php" source="CONFIRM" patch="1">http://denora.nomadirc.net/index.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1319" source="VUPEN">ADV-2005-1319</ref>
    </refs>
    <vuln_soft>
      <prod vendor="denora_irc_stats" name="denora_irc_stats">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2485" published="2005-08-07" name="CVE-2005-2485" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14472" source="BID" patch="1">14472</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=346801" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=346801</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21687" source="XF">logicampus-helpdesk-xss(21687)</ref>
      <ref url="http://secunia.com/advisories/16297" source="SECUNIA">16297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logicampus" name="logicampus">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2486" published="2005-08-07" name="CVE-2005-2486" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14474" source="BID">14474</ref>
      <ref url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0508/53.html" source="BUGTRAQ">20050804 SQL IN PortailPHP</ref>
      <ref url="http://www.osvdb.org/18685" source="OSVDB">18685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="portailphp" name="portailphp">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2487" published="2005-08-07" name="CVE-2005-2487" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101833-1" source="SUNALERT" patch="1" adv="1">101833</ref>
      <ref url="http://secunia.com/advisories/16295" source="SECUNIA" patch="1" adv="1">16295</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21706" source="XF">mcdata-switch-director-dos(21706)</ref>
      <ref url="http://www.securityfocus.com/bid/14475" source="BID">14475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcdata" name="intrepid_6064_director_switch">
        <vers num="" />
      </prod>
      <prod vendor="mcdata" name="intrepid_6140_director_switch">
        <vers num="" />
      </prod>
      <prod vendor="mcdata" name="sphereon_4300_fabric_switch">
        <vers num="" />
      </prod>
      <prod vendor="mcdata" name="sphereon_4500_fabric_switch">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2488" published="2005-08-07" name="CVE-2005-2488" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rgod.altervista.org/webc.html" source="MISC">http://www.rgod.altervista.org/webc.html</ref>
      <ref url="http://securitytracker.com/id?1014616" source="SECTRACK">1014616</ref>
      <ref url="http://secunia.com/advisories/16317" source="SECUNIA" adv="1">16317</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21689" source="XF">webcms-multiple-script-xss(21689)</ref>
      <ref url="http://www.securityfocus.com/bid/14464" source="BID">14464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_content_management" name="web_content_management_news_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2489" published="2005-08-07" name="CVE-2005-2489" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rgod.altervista.org/webc.html" source="MISC">http://www.rgod.altervista.org/webc.html</ref>
      <ref url="http://securitytracker.com/id?1014616" source="SECTRACK">1014616</ref>
      <ref url="http://secunia.com/advisories/16317" source="SECUNIA" adv="1">16317</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21694" source="XF">webcms-addmodifyinput-create-account(21694)</ref>
      <ref url="http://www.securityfocus.com/bid/14465" source="BID">14465</ref>
      <ref url="http://www.osvdb.org/18524" source="OSVDB">18524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_content_management" name="web_content_management_news_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2490" published="2005-09-14" name="CVE-2005-2490" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 before 2.6.13.1 allows local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166248" source="MISC" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166248</ref>
      <ref url="http://secunia.com/advisories/16747/" source="SECUNIA" patch="1" adv="1">16747</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22217" source="XF">kernel-sendmsg-bo(22217)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.ubuntu.com/usn/usn-178-1" source="UBUNTU" adv="1">USN-178-1</ref>
      <ref url="http://www.securityfocus.com/bid/14785" source="BID">14785</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRAKE">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.13.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.13.1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10481" source="OVAL">oval:org.mitre.oval:def:10481</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded" source="FEDORA">FLSA:157459-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded" source="FEDORA">FLSA:157459-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded" source="SUSE">SUSE-SA:2005:068</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:235" source="MANDRIVA">MDKSA-2005:235</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRIVA">MDKSA-2005:219</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA">19374</ref>
      <ref url="http://secunia.com/advisories/17918" source="SECUNIA">17918</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112690609622266&amp;w=2" source="TRUSTIX">2005-0049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2491" published="2005-08-23" name="CVE-2005-2491" modified="2011-09-06" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1014744" source="SECTRACK" patch="1">1014744</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4502" source="VUPEN">ADV-2006-4502</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4320" source="VUPEN">ADV-2006-4320</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0789" source="VUPEN">ADV-2006-0789</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2659" source="VUPEN">ADV-2005-2659</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1511" source="VUPEN">ADV-2005-1511</ref>
      <ref url="http://www.securityfocus.com/bid/14620" source="BID">14620</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded" source="HP">SSRT051251</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded" source="HP">SSRT051251</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11516" source="OVAL">oval:org.mitre.oval:def:11516</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">SSRT090208</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">HPSBOV02683</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522" source="HP">SSRT061238</ref>
      <ref url="http://www.securityfocus.com/bid/15647" source="BID">15647</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427046/100/0/threaded" source="FEDORA">FLSA:168516</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0197.html" source="REDHAT">RHSA-2006:0197</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-761.html" source="REDHAT">RHSA-2005:761</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-358.html" source="REDHAT">RHSA-2005:358</ref>
      <ref url="http://www.php.net/release_4_4_1.php" source="CONFIRM">http://www.php.net/release_4_4_1.php</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_52_apache2.html" source="SUSE">SUSE-SA:2005:052</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_49_php.html" source="SUSE">SUSE-SA:2005:049</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_48_pcre.html" source="SUSE">SUSE-SA:2005:048</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml" source="GENTOO">GLSA-200509-19</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200509-12.xml" source="GENTOO">GLSA-200509-12</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200509-02.xml" source="GENTOO">GLSA-200509-02</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200508-17.xml" source="GENTOO">GLSA-200509-08</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00021.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00021.html</ref>
      <ref url="http://www.debian.org/security/2005/dsa-821" source="DEBIAN">DSA-821</ref>
      <ref url="http://www.debian.org/security/2005/dsa-819" source="DEBIAN">DSA-819</ref>
      <ref url="http://www.debian.org/security/2005/dsa-817" source="DEBIAN">DSA-817</ref>
      <ref url="http://www.debian.org/security/2005/dsa-800" source="DEBIAN">DSA-800</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1" source="SUNALERT">102198</ref>
      <ref url="http://securityreason.com/securityalert/604" source="SREASON">604</ref>
      <ref url="http://secunia.com/advisories/22875" source="SECUNIA">22875</ref>
      <ref url="http://secunia.com/advisories/22691" source="SECUNIA">22691</ref>
      <ref url="http://secunia.com/advisories/21522" source="SECUNIA">21522</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA">19532</ref>
      <ref url="http://secunia.com/advisories/19193" source="SECUNIA">19193</ref>
      <ref url="http://secunia.com/advisories/19072" source="SECUNIA">19072</ref>
      <ref url="http://secunia.com/advisories/17813" source="SECUNIA">17813</ref>
      <ref url="http://secunia.com/advisories/17252" source="SECUNIA">17252</ref>
      <ref url="http://secunia.com/advisories/16679" source="SECUNIA">16679</ref>
      <ref url="http://secunia.com/advisories/16502" source="SECUNIA">16502</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112606064317223&amp;w=2" source="OPENPKG">OpenPKG-SA-2005.018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2" source="SUSE">SUSE-SA:2005:051</ref>
      <ref url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html" source="TRUSTIX">TSLSA-2005-0059</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522" source="HP">SSRT061238</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=302847" source="APPLE">APPLE-SA-2005-11-29</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt" source="SCO">SCOSA-2006.10</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:735" source="OVAL" sig="1">oval:org.mitre.oval:def:735</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1659" source="OVAL" sig="1">oval:org.mitre.oval:def:1659</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1496" source="OVAL" sig="1">oval:org.mitre.oval:def:1496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcre" name="pcre">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2492" published="2005-09-14" name="CVE-2005-2492" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166830" source="MISC" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166830</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22218" source="XF">kernel-rawsendmsg-obtain-information(22218)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-178-1" source="UBUNTU">USN-178-1</ref>
      <ref url="http://www.securityfocus.com/bid/14787" source="BID">14787</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.13.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.13.1</ref>
      <ref url="http://secunia.com/advisories/16747/" source="SECUNIA" adv="1">16747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11031" source="OVAL">oval:org.mitre.oval:def:11031</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded" source="FEDORA">FLSA:157459-3</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded" source="SUSE">SUSE-SA:2005:068</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-514.html" source="REDHAT">RHSA-2005:514</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:235" source="MANDRIVA">MDKSA-2005:235</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220" source="MANDRIVA">MDKSA-2005:220</ref>
      <ref url="http://secunia.com/advisories/17918" source="SECUNIA">17918</ref>
      <ref url="http://secunia.com/advisories/17073" source="SECUNIA">17073</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112690609622266&amp;w=2" source="TRUSTIX">2005-0049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2494" published="2005-09-06" name="CVE-2005-2494" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050905-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050905-1.txt</ref>
      <ref url="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.2-kdebase-kcheckpass.diff" source="MISC" patch="1">ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.2-kdebase-kcheckpass.diff</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9388" source="OVAL">oval:org.mitre.oval:def:9388</ref>
      <ref url="http://www.ubuntu.com/usn/usn-176-1" source="UBUNTU">USN-176-1</ref>
      <ref url="http://www.suresec.org/advisories/adv6.pdf" source="MISC">http://www.suresec.org/advisories/adv6.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/14736" source="BID">14736</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0582.html" source="REDHAT">RHSA-2006:0582</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:160" source="MANDRAKE">MDKSA-2005:160</ref>
      <ref url="http://www.debian.org/security/2005/dsa-815" source="DEBIAN">DSA-815</ref>
      <ref url="http://secunia.com/advisories/21481" source="SECUNIA">21481</ref>
      <ref url="http://secunia.com/advisories/18139" source="SECUNIA">18139</ref>
      <ref url="http://secunia.com/advisories/16692" source="SECUNIA">16692</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112611555928169&amp;w=2" source="BUGTRAQ">20050907 [ Suresec Advisories ] - Kcheckpass file creation vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112603999215453&amp;w=2" source="BUGTRAQ">20050905 [KDE Security Advisory] kcheckpass local root vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2495" published="2005-09-15" name="CVE-2005-2495" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/102441" source="CERT-VN">VU#102441</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22244" source="XF">xorg-pixmap-bo(22244)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3140" source="VUPEN" adv="1">ADV-2006-3140</ref>
      <ref url="http://www.securityfocus.com/bid/14807" source="BID">14807</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/442163/100/0/threaded" source="HP">HPSBUX02137</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/442163/100/0/threaded" source="HP">HPSBUX02137</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427045/100/0/threaded" source="FEDORA">FLSA:168264-2</ref>
      <ref url="http://www.securityfocus.com/advisories/9286" source="FEDORA">FEDORA-2005-894</ref>
      <ref url="http://www.securityfocus.com/advisories/9285" source="FEDORA">FEDORA-2005-893</ref>
      <ref url="http://www.securityfocus.com/advisories/9242" source="UBUNTU">USN-182-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-501.html" source="REDHAT" adv="1">RHSA-2005:501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-396.html" source="REDHAT" adv="1">RHSA-2005:396</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-329.html" source="REDHAT">RHSA-2005:329</ref>
      <ref url="http://www.osvdb.org/19352" source="OSVDB">19352</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_56_xserver.html" source="SUSE">SUSE-SA:2005:056</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_23_sr.html" source="SUSE">SUSE-SR:2005:023</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:164" source="MANDRAKE">MDKSA-2005:164</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200509-07.xml" source="GENTOO">GLSA-200509-07</ref>
      <ref url="http://www.debian.org/security/2005/dsa-816" source="DEBIAN">DSA-816</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-226.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-226.pdf</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-218.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-218.pdf</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101953-1" source="SUNALERT">101953</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101926-1" source="SUNALERT">101926</ref>
      <ref url="http://securitytracker.com/id?1014887" source="SECTRACK">1014887</ref>
      <ref url="http://secunia.com/advisories/21318" source="SECUNIA" adv="1">21318</ref>
      <ref url="http://secunia.com/advisories/19796" source="SECUNIA" adv="1">19796</ref>
      <ref url="http://secunia.com/advisories/19624" source="SECUNIA" adv="1">19624</ref>
      <ref url="http://secunia.com/advisories/17278" source="SECUNIA" adv="1">17278</ref>
      <ref url="http://secunia.com/advisories/17258" source="SECUNIA" adv="1">17258</ref>
      <ref url="http://secunia.com/advisories/17215" source="SECUNIA" adv="1">17215</ref>
      <ref url="http://secunia.com/advisories/17044" source="SECUNIA" adv="1">17044</ref>
      <ref url="http://secunia.com/advisories/16790" source="SECUNIA" adv="1">16790</ref>
      <ref url="http://secunia.com/advisories/16777" source="SECUNIA" adv="1">16777</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9615" source="OVAL">oval:org.mitre.oval:def:9615</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112690609622266&amp;w=2" source="TRUSTIX">2005-0049</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U" source="SGI">20060403-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.22/SCOSA-2006.22.txt" source="SCO">SCOSA-2006.22</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:998" source="OVAL" sig="1">oval:org.mitre.oval:def:998</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1044" source="OVAL" sig="1">oval:org.mitre.oval:def:1044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="xfree86">
        <vers num="3.3.6" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.1.0" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2496" published="2005-09-02" name="CVE-2005-2496" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/22035" source="XF" patch="1">ntp-incorrect-group-permissions(22035)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1561" source="VUPEN">ADV-2005-1561</ref>
      <ref url="http://www.securityspace.com/smysecure/catid.html?id=55155" source="FEDORA" adv="1">FEDORA-2005-812</ref>
      <ref url="http://secunia.com/advisories/16602" source="SECUNIA" adv="1">16602</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9669" source="OVAL">oval:org.mitre.oval:def:9669</ref>
      <ref url="http://www.securityfocus.com/bid/14673" source="BID">14673</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0393.html" source="REDHAT">RHSA-2006:0393</ref>
      <ref url="http://www.osvdb.org/19055" source="OSVDB">19055</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:156" source="MANDRAKE">MDKSA-2005:156</ref>
      <ref url="http://www.debian.org/security/2005/dsa-801" source="DEBIAN">DSA-801</ref>
      <ref url="http://securitytracker.com/id?1016679" source="SECTRACK">1016679</ref>
      <ref url="http://secunia.com/advisories/21464" source="SECUNIA">21464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dave_mills" name="ntpd">
        <vers prev="1" num="4.2.0.a.2004-06-17_4.fc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-2497" reject="1" published="2005-10-07" name="CVE-2005-2497" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2641.  Reason: This candidate is a duplicate of CVE-2005-2641.  Notes: All CVE users should reference CVE-2005-2641 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2498" published="2005-08-15" name="CVE-2005-2498" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory_152005.67.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_152005.67.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112412415822890&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050815 [DRUPAL-SA-2005-004] Drupal 4.6.3 / 4.5.5 fixes critical XML-RPC issue</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9569" source="OVAL">oval:org.mitre.oval:def:9569</ref>
      <ref url="http://www.securityfocus.com/bid/14560" source="BID">14560</ref>
      <ref url="http://www.securityfocus.com/archive/1/408125" source="BUGTRAQ">20050815 Advisory 15/2005: PHPXMLRPC Remote PHP Code Injection Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-748.html" source="REDHAT">RHSA-2005:748</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_49_php.html" source="SUSE">SUSE-SA:2005:049</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml" source="GENTOO">GLSA-200509-19</ref>
      <ref url="http://www.fedoralegacy.org/updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.html" source="FEDORA">FLSA:166943</ref>
      <ref url="http://www.debian.org/security/2005/dsa-842" source="DEBIAN">DSA-842</ref>
      <ref url="http://www.debian.org/security/2005/dsa-840" source="DEBIAN">DSA-840</ref>
      <ref url="http://www.debian.org/security/2005/dsa-798" source="DEBIAN">DSA-798</ref>
      <ref url="http://www.debian.org/security/2005/dsa-789" source="DEBIAN">DSA-789</ref>
      <ref url="http://secunia.com/advisories/17440" source="SECUNIA">17440</ref>
      <ref url="http://secunia.com/advisories/17066" source="SECUNIA">17066</ref>
      <ref url="http://secunia.com/advisories/17053" source="SECUNIA">17053</ref>
      <ref url="http://secunia.com/advisories/16976" source="SECUNIA">16976</ref>
      <ref url="http://secunia.com/advisories/16693" source="SECUNIA">16693</ref>
      <ref url="http://secunia.com/advisories/16635" source="SECUNIA">16635</ref>
      <ref url="http://secunia.com/advisories/16619" source="SECUNIA">16619</ref>
      <ref url="http://secunia.com/advisories/16563" source="SECUNIA">16563</ref>
      <ref url="http://secunia.com/advisories/16558" source="SECUNIA">16558</ref>
      <ref url="http://secunia.com/advisories/16550" source="SECUNIA">16550</ref>
      <ref url="http://secunia.com/advisories/16491" source="SECUNIA">16491</ref>
      <ref url="http://secunia.com/advisories/16469" source="SECUNIA">16469</ref>
      <ref url="http://secunia.com/advisories/16468" source="SECUNIA">16468</ref>
      <ref url="http://secunia.com/advisories/16465" source="SECUNIA">16465</ref>
      <ref url="http://secunia.com/advisories/16460" source="SECUNIA">16460</ref>
      <ref url="http://secunia.com/advisories/16441" source="SECUNIA">16441</ref>
      <ref url="http://secunia.com/advisories/16432" source="SECUNIA">16432</ref>
      <ref url="http://secunia.com/advisories/16431" source="SECUNIA">16431</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2" source="SUSE">SUSE-SA:2005:051</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112431497300344&amp;w=2" source="BUGTRAQ">20050817 [PHPADSNEW-SA-2005-001] phpAdsNew and phpPgAds 2.0.6 fix multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edd_dumbill" name="phpxmlrpc">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-2499" published="2005-08-23" name="CVE-2005-2499" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-747.html" source="REDHAT" patch="1" adv="1">RHSA-2005:747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9538" source="OVAL">oval:org.mitre.oval:def:9538</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22316" source="XF">slocate-directory-structure-dos(22316)</ref>
      <ref url="http://www.securityfocus.com/bid/14640" source="BID">14640</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-346.html" source="REDHAT">RHSA-2005:346</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-345.html" source="REDHAT">RHSA-2005:345</ref>
      <ref url="http://www.osvdb.org/19034" source="OSVDB">19034</ref>
      <ref url="http://securitytracker.com/id?1014751" source="SECTRACK">1014751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slocate" name="slocate">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2500" published="2005-08-08" name="CVE-2005-2500" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_44_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:044</ref>
      <ref url="http://lkml.org/lkml/2005/6/23/19" source="MISC">http://lkml.org/lkml/2005/6/23/19</ref>
      <ref url="http://lkml.org/lkml/2005/6/23/126" source="CONFIRM">http://lkml.org/lkml/2005/6/23/126</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21805" source="XF">kernel-xdrxcodearray-dos(21805)</ref>
      <ref url="http://www.securityfocus.com/bid/14470" source="BID">14470</ref>
      <ref url="http://secunia.com/advisories/16406" source="SECUNIA">16406</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@42b9c4fdYUuaq0joRUZi8W0Q-2hA1A" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@42b9c4fdYUuaq0joRUZi8W0Q-2hA1A</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2501" published="2005-08-19" name="CVE-2005-2501" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-229A.html" source="CERT" patch="1" adv="1">TA05-229A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/435188" source="CERT-VN" patch="1" adv="1">VU#435188</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-08-17</ref>
      <ref url="http://securitytracker.com/id?1014695" source="SECTRACK">1014695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2502" published="2005-08-19" name="CVE-2005-2502" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-229A.html" source="CERT">TA05-229A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/172948" source="CERT-VN">VU#172948</ref>
      <ref url="http://securitytracker.com/id?1014695" source="SECTRACK">1014695</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2503" published="2005-08-19" name="CVE-2005-2503" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-08-17</ref>
      <ref url="http://securitytracker.com/id?1014696" source="SECTRACK">1014696</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2504" published="2005-08-19" name="CVE-2005-2504" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2505" published="2005-08-19" name="CVE-2005-2505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-08-17</ref>
      <ref url="http://securitytracker.com/id?1014697" source="SECTRACK">1014697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-2506" published="2005-08-19" name="CVE-2005-2506" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-08-17</ref>
      <ref url="http://securitytracker.com/id?1014697" source="SECTRACK">1014697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-2507" published="2005-08-19" name="CVE-2005-2507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows 
