<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="1.2" pub_date="2013-05-17" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2005-0001" published="2005-05-02" name="CVE-2005-0001" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18849" source="XF">linux-fault-handler-gain-privileges(18849)</ref>
      <ref url="http://www.trustix.org/errata/2005/0001/" source="TRUSTIX">2005-0001</ref>
      <ref url="http://www.securityfocus.com/bid/12244" source="BID">12244</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT">RHSA-2005:092</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-043.html" source="REDHAT">RHSA-2005:043</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT">RHSA-2005:016</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://securitytracker.com/id?1012862" source="SECTRACK">1012862</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/13822" source="SECUNIA">13822</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10322" source="OVAL">oval:org.mitre.oval:def:10322</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581146702951&amp;w=2" source="BUGTRAQ">20050114 [USN-60-0] Linux kernel vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110554694522719&amp;w=2" source="BUGTRAQ">20050112 Linux kernel i386 SMP page fault handler privilege escalation</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030826.html" source="FULLDISC">20050112 Linux kernel i386 SMP page fault handler privilege escalation</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0022-pagefault.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0022-pagefault.txt</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.7"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.10"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.9" edition="2.6.20"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0002" published="2005-05-02" name="CVE-2005-0002" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-22.xml" source="GENTOO" adv="1">GLSA-200501-22</ref>
      <ref url="http://securitytracker.com/id?1012840" source="SECTRACK">1012840</ref>
      <ref url="http://secunia.com/advisories/13865" source="SECUNIA">13865</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="poppassd_pam">
        <vers prev="1" num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0003" published="2005-04-14" name="CVE-2005-0003" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12261" source="BID" patch="1" adv="1">12261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-043.html" source="REDHAT" patch="1" adv="1">RHSA-2005:043</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18886" source="XF">linux-vma-gain-privileges(18886)</ref>
      <ref url="http://www.trustix.org/errata/2005/0001/" source="TRUSTIX">2005-0001</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE">SUSE-SA:2005:018</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://securitytracker.com/id?1012885" source="SECTRACK">1012885</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9512" source="OVAL">oval:org.mitre.oval:def:9512</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg" source="MISC">http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx"/>
      </prod>
      <prod vendor="avaya" name="mn100">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="network_routing">
        <vers num=""/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2"/>
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0"/>
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8710">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="1.1"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="10.1" edition=""/>
        <vers num="10.1" edition=":x86_64"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":amd64"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":x86_64"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":workstation"/>
        <vers num="3.0" edition=":advanced_servers"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0004" published="2005-04-14" name="CVE-2005-0004" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12277" source="BID" patch="1" adv="1">12277</ref>
      <ref url="http://www.debian.org/security/2005/dsa-647" source="DEBIAN" patch="1" adv="1">DSA-647</ref>
      <ref url="http://secunia.com/advisories/13867" source="SECUNIA" patch="1" adv="1">13867</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18922" source="XF">mysql-mysqlaccess-symlink(18922)</ref>
      <ref url="http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html" source="CONFIRM">http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608297217224&amp;w=2" source="BUGTRAQ">20050118 [USN-63-1] MySQL client vulnerability</ref>
      <ref url="http://lists.mysql.com/internals/20600" source="CONFIRM">http://lists.mysql.com/internals/20600</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000947" source="CONECTIVA">CLA-2005:947</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:036" source="MANDRAKE">MDKSA-2005:036</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1" source="SUNALERT">101864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11" edition="gamma"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
        <vers num="4.0.15"/>
        <vers num="4.0.18"/>
        <vers num="4.0.2"/>
        <vers num="4.0.20"/>
        <vers num="4.0.21"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.5a"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7" edition="gamma"/>
        <vers num="4.0.8" edition="gamma"/>
        <vers num="4.0.9" edition="gamma"/>
        <vers num="4.1.0" edition="alpha"/>
        <vers num="4.1.0.0"/>
        <vers num="4.1.2" edition="alpha"/>
        <vers num="4.1.3" edition="beta"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":ppc"/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":sparc"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num=""/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition=""/>
        <vers num="7.3" edition=":i386"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0005" published="2005-05-02" name="CVE-2005-0005" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-071.html" source="REDHAT" patch="1">RHSA-2005:071</ref>
      <ref url="http://www.debian.org/security/2005/dsa-646" source="DEBIAN" patch="1" adv="1">DSA-646</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=184&amp;type=vulnerabilities" source="IDEFENSE">20050117 Multiple Vendor ImageMagick .psd Image File Decode Heap Overflow Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-37.xml" source="GENTOO">GLSA-200501-37</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9925" source="OVAL">oval:org.mitre.oval:def:9925</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608222117215&amp;w=2" source="BUGTRAQ">20050118 [USN-62-1] imagemagick vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-070.html" source="REDHAT">RHSA-2005:070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="graphicsmagick" name="graphicsmagick">
        <vers num="1.0"/>
        <vers num="1.0.6"/>
        <vers num="1.1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
      </prod>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3"/>
        <vers num="5.4.3"/>
        <vers num="5.4.7"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.2.5"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.6"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8"/>
        <vers num="6.1"/>
        <vers num="6.1.1.6"/>
        <vers num="6.1.2"/>
        <vers num="6.1.3"/>
        <vers num="6.1.4"/>
        <vers num="6.1.5"/>
        <vers num="6.1.6"/>
        <vers num="6.1.7"/>
        <vers num="6.2"/>
        <vers num="6.2.0.4"/>
        <vers num="6.2.0.7"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":ppc"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":sparc"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5"/>
        <vers num="0.7"/>
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0006" published="2005-05-02" name="CVE-2005-0006" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The COPS dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (infinite loop).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1" adv="1">13946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18999" source="XF" adv="1">ethereal-cops-dos(18999)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT" adv="1">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO" adv="1">GLSA-200501-27</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC" adv="1">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10801" source="OVAL">oval:org.mitre.oval:def:10801</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.6"/>
        <vers num="0.10.7"/>
        <vers num="0.10.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0007" published="2005-05-02" name="CVE-2005-0007" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DLSw dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash from assertion).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19000" source="XF" patch="1">ethereal-dlsw-dos(19000)</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1">13946</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO">GLSA-200501-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11381" source="OVAL">oval:org.mitre.oval:def:11381</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.6"/>
        <vers num="0.10.7"/>
        <vers num="0.10.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0008" published="2005-05-02" name="CVE-2005-0008" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DNP dissector in Ethereal 0.10.5 through 0.10.8 allows remote attackers to cause "memory corruption."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19001" source="XF">ethereal-dnp-memory-corruption(19001)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT" adv="1">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO" adv="1">GLSA-200501-27</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC">P-106</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA">13946</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10689" source="OVAL">oval:org.mitre.oval:def:10689</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.5"/>
        <vers num="0.10.6"/>
        <vers num="0.10.7"/>
        <vers num="0.10.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0009" published="2005-05-02" name="CVE-2005-0009" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Gnutella dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO" patch="1">GLSA-200501-27</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1" adv="1">13946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19002" source="XF" adv="1">ethereal-gnutella-dos(19002)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT" adv="1">RHSA-2005:037</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC" adv="1">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10623" source="OVAL">oval:org.mitre.oval:def:10623</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.6"/>
        <vers num="0.10.7"/>
        <vers num="0.10.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0010" published="2005-05-02" name="CVE-2005-0010" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19003" source="XF" patch="1">ethereal-mmse-free-memory(19003)</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1">13946</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO">GLSA-200501-27</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9521" source="OVAL">oval:org.mitre.oval:def:9521</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-011.html" source="REDHAT">RHSA-2005:011</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.4"/>
        <vers num="0.10.5"/>
        <vers num="0.10.6"/>
        <vers num="0.10.7"/>
        <vers num="0.10.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0011" published="2005-05-02" name="CVE-2005-0011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050215-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050215-1.txt</ref>
      <ref url="http://secunia.com/advisories/14306" source="SECUNIA" patch="1">14306</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.html" source="FEDORA" adv="1">FEDORA-2005-148</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-23.xml" source="GENTOO" adv="1">GLSA-200502-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0012" published="2005-05-02" name="CVE-2005-0012" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12203" source="BID" patch="1">12203</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18807" source="XF" adv="1">dillo-capi-format-string(18807)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-11.xml" source="GENTOO" adv="1">GLSA-200501-11</ref>
      <ref url="http://secunia.com/advisories/13760/" source="SECUNIA" adv="1">13760</ref>
      <ref url="http://secunia.com/advisories/13764" source="SECUNIA">13764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dillo" name="dillo_web_browser">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.2.2"/>
        <vers num="0.2.3"/>
        <vers num="0.2.4"/>
        <vers num="0.3"/>
        <vers num="0.3.1"/>
        <vers num="0.4"/>
        <vers num="0.5.1"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3"/>
        <vers num="0.6.4"/>
        <vers num="0.6.5"/>
        <vers num="0.6.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.1.2"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.8.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0013" published="2005-05-02" name="CVE-2005-0013" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-665" source="DEBIAN" patch="1">DSA-665</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml" source="GENTOO" adv="1">GLSA-200501-44</ref>
      <ref url="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6" source="CONFIRM">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</ref>
      <ref url="http://www.securityfocus.com/bid/12400" source="BID">12400</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded" source="FEDORA">FLSA:152904</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-371.html" source="REDHAT">RHSA-2005:371</ref>
      <ref url="http://www.osvdb.org/13297" source="OSVDB">13297</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028" source="MANDRAKE">MDKSA-2005:028</ref>
      <ref url="http://securitytracker.com/id?1013019" source="SECTRACK">1013019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncpfs" name="ncpfs">
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0014" published="2005-05-02" name="CVE-2005-0014" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml" source="GENTOO">GLSA-200501-44</ref>
      <ref url="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6" source="CONFIRM">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</ref>
      <ref url="http://www.securityfocus.com/bid/12400" source="BID">12400</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded" source="FEDORA">FLSA:152904</ref>
      <ref url="http://www.osvdb.org/13298" source="OSVDB">13298</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028" source="MANDRAKE">MDKSA-2005:028</ref>
      <ref url="http://securitytracker.com/id?1013019" source="SECTRACK">1013019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncpfs" name="ncpfs">
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers prev="1" num="2.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0015" published="2005-05-02" name="CVE-2005-0015" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-650" source="DEBIAN" patch="1" adv="1">DSA-650</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18997" source="XF" adv="1">sword-diatheke-command-execution(18997)</ref>
      <ref url="http://securitytracker.com/id?1012955" source="SECTRACK">1012955</ref>
      <ref url="http://secunia.com/advisories/13897" source="SECUNIA">13897</ref>
      <ref url="http://www.securityfocus.com/bid/12320" source="BID">12320</ref>
      <ref url="http://secunia.com/advisories/13941" source="SECUNIA">13941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crosswire_bible_society" name="sword">
        <vers num="1.5.7a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0016" published="2005-04-14" name="CVE-2005-0016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-640" source="DEBIAN" patch="1" adv="1">DSA-640</ref>
      <ref url="http://secunia.com/advisories/13884/" source="SECUNIA" patch="1" adv="1">13884</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18930" source="XF" adv="1">gatos-xatitv-bo(18930)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gatos" name="gatos">
        <vers num="0.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0017" published="2005-05-02" name="CVE-2005-0017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-661" source="DEBIAN" patch="1">DSA-661</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-43.xml" source="GENTOO">GLSA-200501-43</ref>
      <ref url="http://www.securityfocus.com/bid/12380" source="BID">12380</ref>
      <ref url="http://securitytracker.com/id?1013028" source="SECTRACK">1013028</ref>
      <ref url="http://secunia.com/advisories/14067" source="SECUNIA">14067</ref>
      <ref url="http://secunia.com/advisories/14052" source="SECUNIA">14052</ref>
      <ref url="http://secunia.com/advisories/14041" source="SECUNIA">14041</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0018" published="2005-05-02" name="CVE-2005-0018" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12380" source="BID" patch="1">12380</ref>
      <ref url="http://www.debian.org/security/2005/dsa-661" source="DEBIAN" patch="1" adv="1">DSA-661</ref>
      <ref url="http://securitytracker.com/id?1013028" source="SECTRACK">1013028</ref>
      <ref url="http://secunia.com/advisories/14052" source="SECUNIA">14052</ref>
      <ref url="http://secunia.com/advisories/14041" source="SECUNIA">14041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f2c_open_source_project" name="f2c_translator">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0019" published="2005-04-27" name="CVE-2005-0019" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12518" source="BID" patch="1" adv="1">12518</ref>
      <ref url="http://www.debian.org/security/2005/dsa-675" source="DEBIAN" patch="1" adv="1">DSA-675</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19297" source="XF" adv="1">hztty-command-execution(19297)</ref>
      <ref url="http://securitytracker.com/id?1013154" source="SECTRACK">1013154</ref>
      <ref url="http://secunia.com/advisories/14236" source="SECUNIA">14236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yongguang_zhang" name="hztty">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0020" published="2005-04-14" name="CVE-2005-0020" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-641" source="DEBIAN" patch="1" adv="1">DSA-641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18933" source="XF" adv="1">playmidi-bo(18933)</ref>
      <ref url="http://www.securityfocus.com/bid/12274" source="BID">12274</ref>
      <ref url="http://www.osvdb.org/13049" source="OSVDB">13049</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:010" source="MANDRAKE">MDKSA-2005:010</ref>
      <ref url="http://securitytracker.com/id?1012957" source="SECTRACK">1012957</ref>
      <ref url="http://secunia.com/advisories/13898" source="SECUNIA">13898</ref>
      <ref url="http://secunia.com/advisories/13890" source="SECUNIA">13890</ref>
      <ref url="http://secunia.com/advisories/13828" source="SECUNIA">13828</ref>
    </refs>
    <vuln_soft>
      <prod vendor="playmidi" name="playmidi">
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.17"/>
        <vers num="2.3.18"/>
        <vers num="2.3.19"/>
        <vers num="2.3.2"/>
        <vers num="2.3.20"/>
        <vers num="2.3.21"/>
        <vers num="2.3.22"/>
        <vers num="2.3.23"/>
        <vers num="2.3.24"/>
        <vers num="2.3.25"/>
        <vers num="2.3.25.1"/>
        <vers num="2.3.26"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="10.1" edition=""/>
        <vers num="10.1" edition=":x86_64"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0021" published="2005-05-02" name="CVE-2005-0021" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/132992" source="CERT-VN" patch="1">VU#132992</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-025.html" source="REDHAT" patch="1">RHSA-2005:025</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=183&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050114 Exim dns_buld_reverse() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=179&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050107 Exim host_aton() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html" source="MLIST">[exim] 20050104 2 smallish security issues</ref>
      <ref url="http://www.debian.org/security/2005/dsa-637" source="DEBIAN" adv="1">DSA-637</ref>
      <ref url="http://www.debian.org/security/2005/dsa-635" source="DEBIAN" adv="1">DSA-635</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-23.xml" source="GENTOO" adv="1">GLSA-200501-23</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10347" source="OVAL">oval:org.mitre.oval:def:10347</ref>
      <ref url="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44" source="CONFIRM">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers prev="1" num="4.40"/>
        <vers num="4.41"/>
        <vers num="4.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0022" published="2005-05-02" name="CVE-2005-0022" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-025.html" source="REDHAT" patch="1">RHSA-2005:025</ref>
      <ref url="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html" source="MLIST" patch="1">[exim] 20050104 2 smallish security issues</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=178&amp;type=vulnerabilities" source="IDEFENSE">20050107 Exim auth_spa_server() Buffer Overflow Vulnerability</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-23.xml" source="GENTOO" adv="1">GLSA-200501-23</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11293" source="OVAL">oval:org.mitre.oval:def:11293</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824870908614&amp;w=2" source="BUGTRAQ">20050212 exim auth_spa_server() PoC exploit</ref>
      <ref url="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44" source="CONFIRM">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</ref>
      <ref url="http://www.securityfocus.com/bid/12188" source="BID">12188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers prev="1" num="4.40"/>
        <vers num="4.41"/>
        <vers num="4.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0023" published="2005-10-05" name="CVE-2005-0023" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <env/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/22496" source="XF">libzvt-gnomeptyhelper-spoof(22496)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1931" source="VUPEN">ADV-2005-1931</ref>
      <ref url="http://www.securityfocus.com/bid/15004" source="BID">15004</ref>
      <ref url="http://secunia.com/advisories/17023" source="SECUNIA" adv="1">17023</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112879572407250&amp;w=2" source="BUGTRAQ">20051007 gnome-pty-helper writes arbitrary utmp records</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=317312" source="MISC">http://bugzilla.gnome.org/show_bug.cgi?id=317312</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330907" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="libvte4">
        <vers num=""/>
      </prod>
      <prod vendor="gnome" name="libzvt2">
        <vers num="1.4.2.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0033" published="2005-05-02" name="CVE-2005-0033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/327633" source="CERT-VN" adv="1">VU#327633</ref>
      <ref url="http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html" source="MISC" patch="1">http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind8.php" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/bind8.php</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19063" source="XF">bind-qusedns-bo(19063)</ref>
      <ref url="http://www.securityfocus.com/bid/12364" source="BID">12364</ref>
      <ref url="http://securitytracker.com/id?1012996" source="SECTRACK">1012996</ref>
      <ref url="http://secunia.com/advisories/18291" source="SECUNIA">18291</ref>
      <ref url="http://secunia.com/advisories/14009" source="SECUNIA">14009</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.1/SCOSA-2006.1.txt" source="SCO">SCOSA-2006.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.4.4"/>
        <vers num="8.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0034" published="2005-05-02" name="CVE-2005-0034" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/938617" source="CERT-VN" patch="1">VU#938617</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19062" source="XF" patch="1">bind-named-dns-dos(19062)</ref>
      <ref url="http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html" source="MISC" patch="1">http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX">2005-0003</ref>
      <ref url="http://www.securityfocus.com/bid/12365" source="BID">12365</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind9.php" source="CONFIRM">http://www.isc.org/index.pl?/sw/bind/bind9.php</ref>
      <ref url="http://securitytracker.com/id?1012995" source="SECTRACK">1012995</ref>
      <ref url="http://secunia.com/advisories/14008" source="SECUNIA">14008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0035" published="2005-05-02" name="CVE-2005-0035" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <env/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/0310" source="VUPEN">ADV-2005-0310</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf" source="MISC">http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf</ref>
      <ref url="http://www.hyperdose.com/advisories/H2005-06.txt" source="MISC">http://www.hyperdose.com/advisories/H2005-06.txt</ref>
      <ref url="http://www.adobe.com/support/techdocs/331465.html" source="CONFIRM">http://www.adobe.com/support/techdocs/331465.html</ref>
      <ref url="http://www.securityfocus.com/bid/12989" source="BID">12989</ref>
      <ref url="http://www.osvdb.org/15242" source="OSVDB">15242</ref>
      <ref url="http://secunia.com/advisories/14813" source="SECUNIA">14813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="4.5"/>
        <vers num="5.0"/>
        <vers num="5.0.5"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0036" published="2005-12-31" name="CVE-2005-0036" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" source="MISC" patch="1" adv="1">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" source="MISC" patch="1">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</ref>
      <ref url="http://www.securityfocus.com/bid/13729" source="BID">13729</ref>
      <ref url="http://www.osvdb.org/25291" source="OSVDB">25291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delegate" name="delegate">
        <vers num="5.9.3"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="7.8.0"/>
        <vers num="7.8.1"/>
        <vers num="7.8.2"/>
        <vers num="7.9.11"/>
        <vers num="8.10"/>
        <vers num="8.10.1"/>
        <vers prev="1" num="8.10.2"/>
        <vers num="8.3.3"/>
        <vers num="8.3.4"/>
        <vers num="8.4.0"/>
        <vers num="8.5.0"/>
        <vers num="8.9"/>
        <vers num="8.9.1"/>
        <vers num="8.9.2"/>
        <vers num="8.9.3"/>
        <vers num="8.9.4"/>
        <vers num="8.9.5"/>
        <vers num="8.9.6"/>
      </prod>
      <prod vendor="etl" name="delegate">
        <vers num="5.9"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0037" published="2005-12-31" name="CVE-2005-0037" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.10 </sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" source="MISC" patch="1">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</ref>
      <ref url="http://www.securityfocus.com/bid/13729" source="BID">13729</ref>
      <ref url="http://www.osvdb.org/25291" source="OSVDB">25291</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" source="MISC">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnrd" name="dnrd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0038" published="2005-12-31" name="CVE-2005-0038" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" source="MISC">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</ref>
      <ref url="http://www.securityfocus.com/bid/13729" source="BID">13729</ref>
      <ref url="http://www.osvdb.org/25291" source="OSVDB">25291</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" source="MISC">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerdns" name="powerdns">
        <vers num="2.0_rc1"/>
        <vers num="2.8"/>
        <vers num="2.9.0"/>
        <vers num="2.9.1"/>
        <vers num="2.9.10"/>
        <vers num="2.9.11"/>
        <vers num="2.9.12"/>
        <vers num="2.9.13"/>
        <vers num="2.9.14"/>
        <vers num="2.9.15"/>
        <vers prev="1" num="2.9.16"/>
        <vers num="2.9.2"/>
        <vers num="2.9.3a"/>
        <vers num="2.9.4"/>
        <vers num="2.9.5"/>
        <vers num="2.9.6"/>
        <vers num="2.9.7"/>
        <vers num="2.9.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0039" published="2005-05-10" name="CVE-2005-0039" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/302220" source="CERT-VN">VU#302220</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2806" source="VUPEN">ADV-2005-2806</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0507" source="VUPEN">ADV-2005-0507</ref>
      <ref url="http://www.securityfocus.com/archive/1/407774" source="HP">SSRT5957</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en" source="MISC">http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en</ref>
      <ref url="http://www.securityfocus.com/bid/13562" source="BID">13562</ref>
      <ref url="http://www.securityfocus.com/archive/1/407774" source="HP">HPSBTU01217</ref>
      <ref url="http://securitytracker.com/id?1015320" source="SECTRACK">1015320</ref>
      <ref url="http://secunia.com/advisories/17938" source="SECUNIA">17938</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566201610350&amp;w=2" source="BUGTRAQ">20050509 NISCC Vulnerability Advisory IPSEC - 004033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nissc" name="ipsec">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0040" published="2005-05-19" name="CVE-2005-0040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.woany.co.uk/advisories/dotnetnukexss.txt" source="MISC" adv="1">http://www.woany.co.uk/advisories/dotnetnukexss.txt</ref>
      <ref url="http://secunia.com/advisories/15397" source="SECUNIA">15397</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627180518591&amp;w=2" source="BUGTRAQ">20050516 DotNetNuke (Multiple XSS)</ref>
      <ref url="http://www.securityfocus.com/bid/13647" source="BID">13647</ref>
      <ref url="http://www.securityfocus.com/bid/13646" source="BID">13646</ref>
      <ref url="http://www.securityfocus.com/bid/13644" source="BID">13644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotnetnuke" name="dotnetnuke">
        <vers prev="1" num="3.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0043" published="2005-05-02" name="CVE-2005-0043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/377368" source="CERT-VN" patch="1" adv="1">VU#377368</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=180&amp;type=vulnerabilities" source="IDEFENSE" patch="1">20050113 Apple iTunes Playlist Parsing Buffer Overflow Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-01-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18851" source="XF">itunes-m3u-pls-bo(18851)</ref>
      <ref url="http://www.securityfocus.com/bid/12238" source="BID">12238</ref>
      <ref url="http://www.osvdb.org/12833" source="OSVDB">12833</ref>
      <ref url="http://securitytracker.com/id?1012839" source="SECTRACK">1012839</ref>
      <ref url="http://secunia.com/advisories/13804" source="SECUNIA">13804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0044" published="2005-05-02" name="CVE-2005-0044" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927889" source="CERT-VN" patch="1">VU#927889</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT">TA05-039A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx" source="MS" patch="1">MS05-012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19109" source="XF" adv="1">win-ole-code-execution(19109)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4499" source="OVAL" sig="1">oval:org.mitre.oval:def:4499</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3568" source="OVAL" sig="1">oval:org.mitre.oval:def:3568</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2917" source="OVAL" sig="1">oval:org.mitre.oval:def:2917</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1180" source="OVAL" sig="1">oval:org.mitre.oval:def:1180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0045" published="2005-05-02" name="CVE-2005-0045" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1" adv="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/652537" source="CERT-VN" patch="1" adv="1">VU#652537</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19089" source="XF" patch="1" adv="1">win-smb-code-execution(19089)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-011.mspx" source="MS" patch="1">MS05-011</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110795643831169&amp;w=2" source="NTBUGTRAQ">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040962600205&amp;w=2" source="BUGTRAQ">20050309 Update: MS05-011 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792638401852&amp;w=2" source="BUGTRAQ">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12484" source="BID">12484</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4043" source="OVAL" sig="1">oval:org.mitre.oval:def:4043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1889" source="OVAL" sig="1">oval:org.mitre.oval:def:1889</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1847" source="OVAL" sig="1">oval:org.mitre.oval:def:1847</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1606" source="OVAL" sig="1">oval:org.mitre.oval:def:1606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:tablet_pc"/>
        <vers num="" edition="sp2:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0047" published="2005-05-02" name="CVE-2005-0047" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/597889" source="CERT-VN" patch="1">VU#597889</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx" source="MS" patch="1">MS05-012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19105" source="XF">win-com-gain-privileges(19105)</ref>
      <ref url="http://www.argeniss.com/research/SSExploit.c" source="MISC">http://www.argeniss.com/research/SSExploit.c</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755870828817&amp;w=2" source="BUGTRAQ">20050530 [Argeniss] MS05-012 Exploit</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:901" source="OVAL" sig="1">oval:org.mitre.oval:def:901</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2892" source="OVAL" sig="1">oval:org.mitre.oval:def:2892</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2351" source="OVAL" sig="1">oval:org.mitre.oval:def:2351</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1159" source="OVAL" sig="1">oval:org.mitre.oval:def:1159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0048" published="2005-05-02" name="CVE-2005-0048" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html" source="CERT" patch="1">TA05-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/233754" source="CERT-VN" patch="1" adv="1">VU#233754</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" source="MS" patch="1">MS05-019</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/192" source="ISS" adv="1">20050412 Windows IP Options Remote Compromise</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4549" source="OVAL" sig="1">oval:org.mitre.oval:def:4549</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3824" source="OVAL" sig="1">oval:org.mitre.oval:def:3824</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1744" source="OVAL" sig="1">oval:org.mitre.oval:def:1744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0049" published="2005-05-02" name="CVE-2005-0049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/340409" source="CERT-VN" patch="1">VU#340409</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-006.mspx" source="MS" patch="1">MS05-006</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19091" source="XF" adv="1">win-sharepoint-services-xss(19091)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_portal_server">
        <vers num="2003" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_team_services">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0050" published="2005-05-02" name="CVE-2005-0050" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/130433" source="CERT-VN" patch="1">VU#130433</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-010.mspx" source="MS" patch="1" adv="1">MS05-010</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19101" source="XF" adv="1">win-license-code-execution(19101)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:644" source="OVAL" sig="1">oval:org.mitre.oval:def:644</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4786" source="OVAL" sig="1">oval:org.mitre.oval:def:4786</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3582" source="OVAL" sig="1">oval:org.mitre.oval:def:3582</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2568" source="OVAL" sig="1">oval:org.mitre.oval:def:2568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="2000" edition=""/>
        <vers num="2000" edition=":small_business_server"/>
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":small_business_server"/>
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0051" published="2005-05-02" name="CVE-2005-0051" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1" adv="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/939074" source="CERT-VN" patch="1">VU#939074</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-007.mspx" source="MS" patch="1">MS05-007</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19093" source="XF">win-named-pipe-information-disclosure(19093)</ref>
      <ref url="http://www.securityfocus.com/bid/12486" source="BID">12486</ref>
      <ref url="http://securitytracker.com/id?1013112" source="SECTRACK">1013112</ref>
      <ref url="http://secunia.com/advisories/14189" source="SECUNIA">14189</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3055" source="OVAL" sig="1">oval:org.mitre.oval:def:3055</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2292" source="OVAL" sig="1">oval:org.mitre.oval:def:2292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:tablet_pc"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0053" published="2005-05-02" name="CVE-2005-0053" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/698835" source="CERT-VN" patch="1">VU#698835</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19117" source="XF" patch="1" adv="1">ie-dragdrop-gain-privileges(19117)</ref>
      <ref url="http://www.securityfocus.com/bid/11466" source="BID" patch="1">11466</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" source="MS" patch="1">MS05-014</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-008.mspx" source="MS" patch="1">MS05-008</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4864" source="OVAL" sig="1">oval:org.mitre.oval:def:4864</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4726" source="OVAL" sig="1">oval:org.mitre.oval:def:4726</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3006" source="OVAL" sig="1">oval:org.mitre.oval:def:3006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2953" source="OVAL" sig="1">oval:org.mitre.oval:def:2953</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2046" source="OVAL" sig="1">oval:org.mitre.oval:def:2046</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1334" source="OVAL" sig="1">oval:org.mitre.oval:def:1334</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1015" source="OVAL" sig="1">oval:org.mitre.oval:def:1015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.0.1" edition="sp4"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:tablet_pc"/>
        <vers num="" edition="sp2:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0054" published="2005-05-02" name="CVE-2005-0054" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/580299" source="CERT-VN" patch="1" adv="1">VU#580299</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" source="MS" patch="1">MS05-014</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796851002781&amp;w=2" source="BUGTRAQ" patch="1">20050209 Internet Explorer zone spoofing with encoded URLs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19214" source="XF">ie-file-url-encode(19214)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3586" source="OVAL" sig="1">oval:org.mitre.oval:def:3586</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3196" source="OVAL" sig="1">oval:org.mitre.oval:def:3196</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3060" source="OVAL" sig="1">oval:org.mitre.oval:def:3060</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1736" source="OVAL" sig="1">oval:org.mitre.oval:def:1736</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1308" source="OVAL" sig="1">oval:org.mitre.oval:def:1308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01"/>
        <vers num="5.5"/>
        <vers num="6" edition="windows_server_2003_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0055" published="2005-05-02" name="CVE-2005-0055" modified="2008-12-06" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/843771" source="CERT-VN" patch="1">VU#843771</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" source="MS" patch="1">MS05-014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19137" source="XF" adv="1">ie-cdf-execute-code(19137)</ref>
      <ref url="http://securitytracker.com/id?1013125" source="SECTRACK">1013125</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:710" source="OVAL" sig="1">oval:org.mitre.oval:def:710</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3910" source="OVAL" sig="1">oval:org.mitre.oval:def:3910</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3137" source="OVAL" sig="1">oval:org.mitre.oval:def:3137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2692" source="OVAL" sig="1">oval:org.mitre.oval:def:2692</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1005" source="OVAL" sig="1">oval:org.mitre.oval:def:1005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.0.1" edition="sp4"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0056" published="2005-05-02" name="CVE-2005-0056" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/823971" source="CERT-VN" patch="1">VU#823971</ref>
      <ref url="http://www.securityfocus.com/bid/12427" source="BID" patch="1">12427</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" source="MS" patch="1">MS05-014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19137" source="XF" adv="1">ie-cdf-execute-code(19137)</ref>
      <ref url="http://securitytracker.com/id?1013126" source="SECTRACK">1013126</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4947" source="OVAL" sig="1">oval:org.mitre.oval:def:4947</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4085" source="OVAL" sig="1">oval:org.mitre.oval:def:4085</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3318" source="OVAL" sig="1">oval:org.mitre.oval:def:3318</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2817" source="OVAL" sig="1">oval:org.mitre.oval:def:2817</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2385" source="OVAL" sig="1">oval:org.mitre.oval:def:2385</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01"/>
        <vers num="5.5"/>
        <vers num="6" edition="windows_server_2003_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0057" published="2005-05-02" name="CVE-2005-0057" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/820427" source="CERT-VN" patch="1">VU#820427</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-015.mspx" source="MS" patch="1">MS05-015</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19110" source="XF" adv="1">win-hyperlink-code-execution(19110)</ref>
      <ref url="http://www.securityfocus.com/bid/12479" source="BID">12479</ref>
      <ref url="http://securitytracker.com/id?1013119" source="SECTRACK">1013119</ref>
      <ref url="http://secunia.com/advisories/14195" source="SECUNIA">14195</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:713" source="OVAL" sig="1">oval:org.mitre.oval:def:713</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3203" source="OVAL" sig="1">oval:org.mitre.oval:def:3203</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2570" source="OVAL" sig="1">oval:org.mitre.oval:def:2570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0058" published="2005-08-10" name="CVE-2005-0058" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-040.mspx" source="MS" patch="1">MS05-040</ref>
      <ref url="http://secunia.com/advisories/16354/" source="SECUNIA" patch="1" adv="1">16354</ref>
      <ref url="http://www.securityfocus.com/bid/14518" source="BID">14518</ref>
      <ref url="http://securitytracker.com/id?1014639" source="SECTRACK">1014639</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1297" source="OVAL" sig="1">oval:org.mitre.oval:def:1297</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1213" source="OVAL" sig="1">oval:org.mitre.oval:def:1213</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1075" source="OVAL" sig="1">oval:org.mitre.oval:def:1075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100088" source="OVAL" sig="1">oval:org.mitre.oval:def:100088</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100086" source="OVAL" sig="1">oval:org.mitre.oval:def:100086</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100085" source="OVAL" sig="1">oval:org.mitre.oval:def:100085</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100084" source="OVAL" sig="1">oval:org.mitre.oval:def:100084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0059" published="2005-05-02" name="CVE-2005-0059" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-017.mspx" source="MS" patch="1">MS05-017</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4988" source="OVAL" sig="1">oval:org.mitre.oval:def:4988</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4384" source="OVAL" sig="1">oval:org.mitre.oval:def:4384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0060" published="2005-05-02" name="CVE-2005-0060" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx" source="MS" patch="1">MS05-018</ref>
      <ref url="http://www.ngssoftware.com/advisories/ms-01.txt" source="MISC" adv="1">http://www.ngssoftware.com/advisories/ms-01.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343529426926&amp;w=2" source="BUGTRAQ" adv="1">20050413 Windows kernel overflow fixed</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4797" source="OVAL" sig="1">oval:org.mitre.oval:def:4797</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3941" source="OVAL" sig="1">oval:org.mitre.oval:def:3941</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2731" source="OVAL" sig="1">oval:org.mitre.oval:def:2731</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2562" source="OVAL" sig="1">oval:org.mitre.oval:def:2562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0061" published="2005-05-02" name="CVE-2005-0061" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx" source="MS" patch="1">MS05-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4593" source="OVAL" sig="1">oval:org.mitre.oval:def:4593</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3994" source="OVAL" sig="1">oval:org.mitre.oval:def:3994</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1761" source="OVAL" sig="1">oval:org.mitre.oval:def:1761</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1656" source="OVAL" sig="1">oval:org.mitre.oval:def:1656</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0063" published="2005-05-02" name="CVE-2005-0063" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-016.mspx" source="MS" patch="1">MS05-016</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=231&amp;type=vulnerabilities" source="IDEFENSE" patch="1">20050412 Microsoft MSHTA Script Execution Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0335" source="VUPEN">ADV-2005-0335</ref>
      <ref url="http://www.securiteam.com/exploits/5YP0T0AFFW.html" source="MISC">http://www.securiteam.com/exploits/5YP0T0AFFW.html</ref>
      <ref url="http://www.securityfocus.com/bid/13132" source="BID">13132</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755356016155&amp;w=2" source="BUGTRAQ">20050529 Spam exploiting MS05-016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:587" source="OVAL" sig="1">oval:org.mitre.oval:def:587</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:573" source="OVAL" sig="1">oval:org.mitre.oval:def:573</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4710" source="OVAL" sig="1">oval:org.mitre.oval:def:4710</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:407" source="OVAL" sig="1">oval:org.mitre.oval:def:407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3456" source="OVAL" sig="1">oval:org.mitre.oval:def:3456</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2184" source="OVAL" sig="1">oval:org.mitre.oval:def:2184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0064" published="2005-05-02" name="CVE-2005-0064" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2353" source="FEDORA" patch="1" adv="1">FLSA:2353</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2352" source="FEDORA" patch="1" adv="1">FLSA:2352</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-066.html" source="REDHAT" patch="1" adv="1">RHSA-2005:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-059.html" source="REDHAT" patch="1" adv="1">RHSA-2005:059</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-057.html" source="REDHAT" patch="1" adv="1">RHSA-2005:057</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT" patch="1" adv="1">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-034.html" source="REDHAT" patch="1" adv="1">RHSA-2005:034</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=186&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050118 Multiple Unix/Linux Vendor Xpdf makeFileKey2 Stack Overflow</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-28.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-10</ref>
      <ref url="http://www.debian.org/security/2005/dsa-648" source="DEBIAN" patch="1" adv="1">DSA-648</ref>
      <ref url="http://www.debian.org/security/2005/dsa-645" source="DEBIAN" patch="1" adv="1">DSA-645</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110625368019554&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 [USN-64-1] xpdf, CUPS vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000921" source="CONECTIVA" patch="1" adv="1">CLA-2005:921</ref>
      <ref url="ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch" source="CONFIRM" patch="1">ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-026.html" source="REDHAT">RHSA-2005:026</ref>
      <ref url="http://secunia.com/advisories/17277" source="SECUNIA">17277</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11781" source="OVAL">oval:org.mitre.oval:def:11781</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt" source="SCO">SCOSA-2005.42</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:021" source="MANDRAKE">MDKSA-2005:021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:020" source="MANDRAKE">MDKSA-2005:020</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:019" source="MANDRAKE">MDKSA-2005:019</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:018" source="MANDRAKE">MDKSA-2005:018</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:017" source="MANDRAKE">MDKSA-2005:017</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:016" source="MANDRAKE">MDKSA-2005:016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.5a"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7a"/>
        <vers num="0.80"/>
        <vers num="0.90"/>
        <vers num="0.91"/>
        <vers num="0.91a"/>
        <vers num="0.91b"/>
        <vers num="0.91c"/>
        <vers num="0.92"/>
        <vers num="0.92a"/>
        <vers num="0.92b"/>
        <vers num="0.92c"/>
        <vers num="0.92d"/>
        <vers num="0.92e"/>
        <vers num="0.93"/>
        <vers num="0.93a"/>
        <vers num="0.93b"/>
        <vers num="0.93c"/>
        <vers num="1.0"/>
        <vers num="1.0a"/>
        <vers num="1.1"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0065" published="2005-05-02" name="CVE-2005-0065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The original design of TCP does not check that the TCP sequence number in an ICMP error message is within the range of sequence numbers for data that has been sent but not acknowledged (aka "TCP sequence number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0066" published="2004-12-22" name="CVE-2005-0066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0067" published="2004-12-22" name="CVE-2005-0067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0068" published="2004-12-22" name="CVE-2005-0068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0069" published="2005-01-13" name="CVE-2005-0069" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18870" source="XF" patch="1" adv="1">vim-symlink(18870)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-122.html" source="REDHAT" patch="1" adv="1">RHSA-2005:122</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-036.html" source="REDHAT" patch="1" adv="1">RHSA-2005:036</ref>
      <ref url="http://secunia.com/advisories/13841/" source="SECUNIA" patch="1" adv="1">13841</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608387001863&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050118 [USN-61-1] vim vulnerabilities</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2343" source="FEDORA" adv="1">FLSA:2343</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9402" source="OVAL">oval:org.mitre.oval:def:9402</ref>
      <ref url="http://securitytracker.com/id?1012938" source="SECTRACK">1012938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vim_development_group" name="vim">
        <vers num="6.3.011"/>
        <vers num="6.3.025"/>
        <vers num="6.3.030"/>
        <vers num="6.3.044"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0070" published="2005-05-02" name="CVE-2005-0070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-681" source="DEBIAN" patch="1" adv="1">DSA-681</ref>
      <ref url="http://www.securityfocus.com/bid/12546" source="BID">12546</ref>
      <ref url="http://securitytracker.com/id?1013206" source="SECTRACK">1013206</ref>
      <ref url="http://secunia.com/advisories/14300" source="SECUNIA">14300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="synaesthesia" name="synaesthesia">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0071" published="2005-05-02" name="CVE-2005-0071" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vdr before 1.2.6 does not securely create files, which allows attackers to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19066" source="XF">vdr-dvdapi-file-overwrite(19066)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-42.xml" source="GENTOO">GLSA-200501-42</ref>
      <ref url="http://www.debian.org/security/2005/dsa-656" source="DEBIAN">DSA-656</ref>
      <ref url="http://www.securityfocus.com/bid/12356" source="BID">12356</ref>
      <ref url="http://secunia.com/advisories/14066" source="SECUNIA">14066</ref>
      <ref url="http://secunia.com/advisories/13995" source="SECUNIA">13995</ref>
      <ref url="http://secunia.com/advisories/13930" source="SECUNIA">13930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vdr" name="vdr">
        <vers num="1.0.0"/>
        <vers num="1.0.4"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0072" published="2005-01-24" name="CVE-2005-0072" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-655" source="DEBIAN" patch="1" adv="1">DSA-655</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19045" source="XF" adv="1">zhcon-information-disclosure(19045)</ref>
      <ref url="http://www.securityfocus.com/bid/12343" source="BID">12343</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012" source="MANDRAKE">MDKSA-2005:012</ref>
      <ref url="http://securitytracker.com/id?1012977" source="SECTRACK">1012977</ref>
      <ref url="http://secunia.com/advisories/13987" source="SECUNIA">13987</ref>
      <ref url="http://secunia.com/advisories/13982" source="SECUNIA">13982</ref>
      <ref url="http://secunia.com/advisories/13977" source="SECUNIA">13977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ejoy_and_hu_yong" name="zhcon">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0073" published="2005-05-02" name="CVE-2005-0073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-677" source="DEBIAN" patch="1" adv="1">DSA-677</ref>
      <ref url="http://securitytracker.com/id?1013163" source="SECTRACK">1013163</ref>
      <ref url="http://secunia.com/advisories/14224" source="SECUNIA">14224</ref>
      <ref url="http://secunia.com/advisories/14217" source="SECUNIA">14217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="sympa">
        <vers num="3.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0074" published="2005-02-11" name="CVE-2005-0074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-676" source="DEBIAN" patch="1" adv="1">DSA-676</ref>
      <ref url="http://www.securityfocus.com/bid/12523" source="BID">12523</ref>
      <ref url="http://securitytracker.com/id?1013162" source="SECTRACK">1013162</ref>
      <ref url="http://secunia.com/advisories/14250" source="SECUNIA">14250</ref>
      <ref url="http://secunia.com/advisories/14248" source="SECUNIA">14248</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpcd" name="xpcd">
        <vers num="2.08"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0075" published="2005-01-29" name="CVE-2005-0075" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2005-01-14" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2005-01-14</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-135.html" source="REDHAT" patch="1" adv="1">RHSA-2005:135</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-099.html" source="REDHAT" patch="1" adv="1">RHSA-2005:099</ref>
      <ref url="http://secunia.com/advisories/13962/" source="SECUNIA" patch="1" adv="1">13962</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9587" source="OVAL">oval:org.mitre.oval:def:9587</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" source="BUGTRAQ" adv="1">20050129 SquirrelMail Security Advisory</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" source="GENTOO">GLSA-200501-39</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.4"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.3a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0076" published="2005-05-02" name="CVE-2005-0076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19271" source="XF">xview-xvparseone-bo(19271)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-672" source="DEBIAN">DSA-672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0077" published="2005-05-02" name="CVE-2005-0077" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19068" source="XF" patch="1" adv="1">dbi-library-file-overwrite(19068)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-072.html" source="REDHAT" patch="1" adv="1">RHSA-2005:072</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-38</ref>
      <ref url="http://www.debian.org/security/2005/dsa-658" source="DEBIAN" patch="1" adv="1">DSA-658</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667936707597&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050125 [USN-70-1] Perl DBI module vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10552" source="OVAL">oval:org.mitre.oval:def:10552</ref>
      <ref url="http://www.securityfocus.com/bid/12360" source="BID">12360</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426530/30/6600/threaded" source="FEDORA">FLSA-2006:178989</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:030" source="MANDRAKE">MDKSA-2005:030</ref>
      <ref url="http://securitytracker.com/id?1013007" source="SECTRACK">1013007</ref>
      <ref url="http://secunia.com/advisories/14050" source="SECUNIA">14050</ref>
      <ref url="http://secunia.com/advisories/14015" source="SECUNIA">14015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":woody"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num=""/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0"/>
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0078" published="2005-05-02" name="CVE-2005-0078" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19084" source="XF" patch="1" adv="1">kdebase-screensaver-security-bypass(19084)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-009.html" source="REDHAT" patch="1" adv="1">RHSA-2005:009</ref>
      <ref url="http://www.debian.org/security/2005/dsa-660" source="DEBIAN" patch="1" adv="1">DSA-660</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9260" source="OVAL">oval:org.mitre.oval:def:9260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":woody"/>
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
        <vers num="2.1_beta1"/>
        <vers num="2.1_beta2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2_beta1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0_beta_1"/>
        <vers num="3.0_beta_2"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":advanced_servers"/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":workstation"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0079" published="2005-05-02" name="CVE-2005-0079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xtrlock 2.0 allows local users to cause a denial of service (application crash) and hijack the desktop session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-649" source="DEBIAN" patch="1">DSA-649</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18991" source="XF">xtrlock-screen-lock-bypass(18991)</ref>
      <ref url="http://www.securityfocus.com/bid/12316" source="BID">12316</ref>
      <ref url="http://secunia.com/advisories/13938" source="SECUNIA">13938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xtrlock" name="xtrlock">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0080" published="2005-05-02" name="CVE-2005-0080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2" source="BUGTRAQ" patch="1">20050110 [USN-59-1] mailman vulnerabilities</ref>
      <ref url="http://qa.debian.org/bts-security.html" source="MISC">http://qa.debian.org/bts-security.html</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1.5"/>
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0081" published="2005-04-14" name="CVE-2005-0081" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00"/>
        <vers num="7.5.00.08"/>
        <vers num="7.5.00.11"/>
        <vers num="7.5.00.12"/>
        <vers num="7.5.00.14"/>
        <vers num="7.5.00.15"/>
        <vers num="7.5.00.16"/>
        <vers num="7.5.00.18"/>
        <vers num="7.5.00.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0082" published="2005-04-14" name="CVE-2005-0082" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00"/>
        <vers num="7.5.00.08"/>
        <vers num="7.5.00.11"/>
        <vers num="7.5.00.12"/>
        <vers num="7.5.00.14"/>
        <vers num="7.5.00.15"/>
        <vers num="7.5.00.16"/>
        <vers num="7.5.00.18"/>
        <vers num="7.5.00.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0083" published="2005-05-02" name="CVE-2005-0083" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19687" source="XF" patch="1" adv="1">maxdb-null-pointer-dos(19687)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=218&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050314 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0084" published="2005-05-02" name="CVE-2005-0084" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8 allows remote attackers to execute arbitrary code via a crafted packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-27</ref>
      <ref url="http://www.debian.org/security/2005/dsa-653" source="DEBIAN" patch="1">DSA-653</ref>
      <ref url="http://secunia.com/advisories/13946/" source="SECUNIA" patch="1">13946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19004" source="XF">ethereal-x11-bo(19004)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT">RHSA-2005:037</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00017.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-106.shtml" source="CIAC">P-106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9140" source="OVAL">oval:org.mitre.oval:def:9140</ref>
      <ref url="http://www.securityfocus.com/bid/12326" source="BID">12326</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" source="MANDRAKE">MDKSA-2005:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10"/>
        <vers num="0.10.0"/>
        <vers num="0.10.0a"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
        <vers num="0.10.4"/>
        <vers num="0.10.5"/>
        <vers num="0.10.6"/>
        <vers num="0.10.7"/>
        <vers num="0.10.8"/>
        <vers num="0.8"/>
        <vers num="0.8.13"/>
        <vers num="0.8.14"/>
        <vers num="0.8.15"/>
        <vers num="0.8.16"/>
        <vers num="0.8.17a"/>
        <vers num="0.8.18"/>
        <vers num="0.8.19"/>
        <vers num="0.8.20"/>
        <vers num="0.9"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
        <vers num="0.9.16"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0085" published="2005-04-27" name="CVE-2005-0085" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12442" source="BID" patch="1" adv="1">12442</ref>
      <ref url="http://www.debian.org/security/2005/dsa-680" source="DEBIAN" patch="1" adv="1">DSA-680</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19223" source="XF">htdig-config-xss(19223)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-073.html" source="REDHAT">RHSA-2005:073</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml" source="GENTOO">GLSA-200502-16</ref>
      <ref url="http://securitytracker.com/id?1013078" source="SECTRACK">1013078</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10878" source="OVAL">oval:org.mitre.oval:def:10878</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-090.html" source="REDHAT">RHSA-2005:090</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html" source="FEDORA">FLSA-2006:152907</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:063" source="MANDRAKE">MDKSA-2005:063</ref>
      <ref url="http://secunia.com/advisories/17415" source="SECUNIA">17415</ref>
      <ref url="http://secunia.com/advisories/17414" source="SECUNIA">17414</ref>
      <ref url="http://secunia.com/advisories/15007" source="SECUNIA">15007</ref>
      <ref url="http://secunia.com/advisories/14795" source="SECUNIA">14795</ref>
      <ref url="http://secunia.com/advisories/14303" source="SECUNIA">14303</ref>
      <ref url="http://secunia.com/advisories/14276" source="SECUNIA">14276</ref>
      <ref url="http://secunia.com/advisories/14255" source="SECUNIA">14255</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt" source="SCO">SCOSA-2005.46</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htdig" name="htdig">
        <vers num="3.1.5"/>
        <vers num="3.1.5_7"/>
        <vers num="3.1.5_8"/>
        <vers num="3.1.6"/>
        <vers num="3.2.0"/>
        <vers num="3.2.0b2"/>
        <vers num="3.2.0b3"/>
        <vers num="3.2.0b4"/>
        <vers num="3.2.0b5"/>
        <vers num="3.2.0b6"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="10.1" edition=""/>
        <vers num="10.1" edition=":x86_64"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":x86_64"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":x86_64"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0086" published="2005-05-02" name="CVE-2005-0086" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2404" source="FEDORA">FLSA:2404</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19131" source="XF">less-file-bo(19131)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-068.html" source="REDHAT" adv="1">RHSA-2005:068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11027" source="OVAL">oval:org.mitre.oval:def:11027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation"/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":advanced_servers"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0087" published="2005-04-27" name="CVE-2005-0087" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-033.html" source="REDHAT" patch="1" adv="1">RHSA-2005:033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10355" source="OVAL">oval:org.mitre.oval:def:10355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alsa" name="alsa-lib">
        <vers num="1.0.6"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":desktop"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0088" published="2005-05-02" name="CVE-2005-0088" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/356409" source="CERT-VN">VU#356409</ref>
      <ref url="http://www.debian.org/security/2005/dsa-689" source="DEBIAN" patch="1">DSA-689</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-14.xml" source="GENTOO" patch="1">GLSA-200502-14</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX">2005-0003</ref>
      <ref url="http://www.securityfocus.com/bid/12519" source="BID">12519</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430286/100/0/threaded" source="FEDORA">FLSA:152896</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-104.html" source="REDHAT">RHSA-2005:104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-100.html" source="REDHAT">RHSA-2005:100</ref>
      <ref url="http://securitytracker.com/id?1013156" source="SECTRACK">1013156</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10617" source="OVAL">oval:org.mitre.oval:def:10617</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815313218389&amp;w=2" source="BUGTRAQ">20050211 [USN-80-1] mod_python vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000926" source="CONECTIVA">CLA-2005:926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_python">
        <vers num="1.9a"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.4.1"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.7"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers prev="1" num="2.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0089" published="2005-05-02" name="CVE-2005-0089" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
      <env/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.python.org/security/PSF-2005-001/" source="CONFIRM" patch="1">http://www.python.org/security/PSF-2005-001/</ref>
      <ref url="http://www.debian.org/security/2005/dsa-666" source="DEBIAN" patch="1">DSA-666</ref>
      <ref url="http://python.org/security/PSF-2005-001/patch-2.2.txt" source="CONFIRM" patch="1">http://python.org/security/PSF-2005-001/patch-2.2.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746469728728&amp;w=2" source="BUGTRAQ" patch="1">20050203 Python Security Advisory PSF-2005-001 - SimpleXMLRPCServer.py</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19217" source="XF">python-simplexmlrpcserver-bypass(19217)</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX">2005-0003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-108.html" source="REDHAT">RHSA-2005:108</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9811" source="OVAL">oval:org.mitre.oval:def:9811</ref>
      <ref url="http://www.securityfocus.com/bid/12437" source="BID">12437</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:035" source="MANDRAKE">MDKSA-2005:035</ref>
      <ref url="http://securitytracker.com/id?1013083" source="SECTRACK">1013083</ref>
      <ref url="http://secunia.com/advisories/14128" source="SECUNIA">14128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python_software_foundation" name="python">
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0090" published="2005-05-02" name="CVE-2005-0090" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an "access check," which allows local users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20618" source="XF">red-hat-regression-dos(20618)</ref>
      <ref url="http://www.securityfocus.com/bid/12599" source="BID" adv="1">12599</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10425" source="OVAL">oval:org.mitre.oval:def:10425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0091" published="2005-05-02" name="CVE-2005-0091" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20619" source="XF">red-hat-patch-gain-privileges(20619)</ref>
      <ref url="http://www.securityfocus.com/bid/12599" source="BID">12599</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" adv="1">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11249" source="OVAL">oval:org.mitre.oval:def:11249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0092" published="2005-02-19" name="CVE-2005-0092" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12599" source="BID" patch="1" adv="1">12599</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20620" source="XF">red-hat-patch-dos(20620)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11647" source="OVAL">oval:org.mitre.oval:def:11647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0093" reject="1" published="2005-05-02" name="CVE-2005-0093" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0094" published="2005-01-15" name="CVE-2005-0094" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.debian.org/security/2005/dsa-651" source="DEBIAN" patch="1" adv="1">DSA-651</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-25</ref>
      <ref url="http://secunia.com/advisories/13825" source="SECUNIA" patch="1" adv="1">13825</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" adv="1">2005-0003</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2005_1.txt" source="CONFIRM" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_1.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11146" source="OVAL">oval:org.mitre.oval:def:11146</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" adv="1">CLA-2005:923</ref>
      <ref url="http://www.securityfocus.com/bid/12276" source="BID">12276</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014" source="MANDRAKE">MDKSA-2005:014</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2"/>
        <vers num="2.1_patch2"/>
        <vers num="2.3_.stable4"/>
        <vers num="2.3_.stable5"/>
        <vers num="2.3_stable5"/>
        <vers num="2.4"/>
        <vers num="2.4_.stable2"/>
        <vers num="2.4_.stable6"/>
        <vers num="2.4_.stable7"/>
        <vers num="2.4_stable7"/>
        <vers num="2.5.6"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
        <vers num="2.5.stable7"/>
        <vers num="2.5_.stable1"/>
        <vers num="2.5_.stable3"/>
        <vers num="2.5_.stable4"/>
        <vers num="2.5_.stable5"/>
        <vers num="2.5_.stable6"/>
        <vers num="2.5_stable3"/>
        <vers num="2.5_stable4"/>
        <vers num="2.5_stable9"/>
        <vers num="2.6.stable1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0095" published="2005-01-15" name="CVE-2005-0095" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2005_2.txt" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_2.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://www.debian.org/security/2005/dsa-651" source="DEBIAN" patch="1" adv="1">DSA-651</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-25</ref>
      <ref url="http://secunia.com/advisories/13825" source="SECUNIA" patch="1" adv="1">13825</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" patch="1" adv="1">CLA-2005:923</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10269" source="OVAL">oval:org.mitre.oval:def:10269</ref>
      <ref url="http://www.securityfocus.com/bid/12275" source="BID">12275</ref>
      <ref url="http://www.osvdb.org/12886" source="OSVDB">12886</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014" source="MANDRAKE">MDKSA-2005:014</ref>
      <ref url="http://securitytracker.com/id?1012882" source="SECTRACK">1012882</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2"/>
        <vers num="2.1_patch2"/>
        <vers num="2.3_.stable4"/>
        <vers num="2.3_.stable5"/>
        <vers num="2.3_stable5"/>
        <vers num="2.4"/>
        <vers num="2.4_.stable2"/>
        <vers num="2.4_.stable6"/>
        <vers num="2.4_.stable7"/>
        <vers num="2.4_stable7"/>
        <vers num="2.5.6"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
        <vers num="2.5.stable7"/>
        <vers num="2.5_.stable1"/>
        <vers num="2.5_.stable3"/>
        <vers num="2.5_.stable4"/>
        <vers num="2.5_.stable5"/>
        <vers num="2.5_.stable6"/>
        <vers num="2.5_stable3"/>
        <vers num="2.5_stable4"/>
        <vers num="2.5_stable9"/>
        <vers num="2.6.stable1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0096" published="2005-01-25" name="CVE-2005-0096" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-25</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" patch="1" adv="1">CLA-2005:923</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" adv="1">2005-0003</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10233" source="OVAL">oval:org.mitre.oval:def:10233</ref>
      <ref url="http://www.securityfocus.com/bid/12324" source="BID">12324</ref>
      <ref url="http://securitytracker.com/id?1012818" source="SECTRACK">1012818</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2"/>
        <vers num="2.1_patch2"/>
        <vers num="2.3_.stable4"/>
        <vers num="2.3_.stable5"/>
        <vers num="2.3_stable5"/>
        <vers num="2.4"/>
        <vers num="2.4_.stable2"/>
        <vers num="2.4_.stable6"/>
        <vers num="2.4_.stable7"/>
        <vers num="2.4_stable7"/>
        <vers num="2.5.6"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
        <vers num="2.5.stable7"/>
        <vers num="2.5_.stable1"/>
        <vers num="2.5_.stable3"/>
        <vers num="2.5_.stable4"/>
        <vers num="2.5_.stable5"/>
        <vers num="2.5_.stable6"/>
        <vers num="2.5_stable3"/>
        <vers num="2.5_stable4"/>
        <vers num="2.5_stable9"/>
        <vers num="2.6.stable1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0097" published="2005-01-11" name="CVE-2005-0097" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-25</ref>
      <ref url="http://secunia.com/advisories/13789" source="SECUNIA" patch="1" adv="1">13789</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11646" source="OVAL">oval:org.mitre.oval:def:11646</ref>
      <ref url="http://www.securityfocus.com/bid/12220" source="BID">12220</ref>
      <ref url="http://securitytracker.com/id?1012818" source="SECTRACK">1012818</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2"/>
        <vers num="2.1_patch2"/>
        <vers num="2.3_.stable4"/>
        <vers num="2.3_.stable5"/>
        <vers num="2.3_stable5"/>
        <vers num="2.4"/>
        <vers num="2.4_.stable2"/>
        <vers num="2.4_.stable6"/>
        <vers num="2.4_.stable7"/>
        <vers num="2.4_stable7"/>
        <vers num="2.5.6"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
        <vers num="2.5.stable7"/>
        <vers num="2.5_.stable1"/>
        <vers num="2.5_.stable3"/>
        <vers num="2.5_.stable4"/>
        <vers num="2.5_.stable5"/>
        <vers num="2.5_.stable6"/>
        <vers num="2.5_stable3"/>
        <vers num="2.5_stable4"/>
        <vers num="2.5_stable9"/>
        <vers num="2.6.stable1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0098" published="2005-03-08" name="CVE-2005-0098" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-691" source="DEBIAN" patch="1" adv="1">DSA-691</ref>
      <ref url="http://secunia.com/advisories/14495" source="SECUNIA" adv="1">14495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abuse" name="abuse-sdl">
        <vers prev="1" num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0099" published="2005-03-08" name="CVE-2005-0099" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-691" source="DEBIAN" patch="1" adv="1">DSA-691</ref>
      <ref url="http://secunia.com/advisories/14495" source="SECUNIA" patch="1" adv="1">14495</ref>
      <ref url="http://www.osvdb.org/14610" source="OSVDB">14610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abuse" name="abuse-sdl">
        <vers prev="1" num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0100" published="2005-02-07" name="CVE-2005-0100" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19246" source="XF" patch="1" adv="1">xemacs-movemail-format-string(19246)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-133.html" source="REDHAT" patch="1" adv="1">RHSA-2005:133</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-112.html" source="REDHAT" patch="1" adv="1">RHSA-2005:112</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-110.html" source="REDHAT" patch="1" adv="1">RHSA-2005:110</ref>
      <ref url="http://www.debian.org/security/2005/dsa-685" source="DEBIAN" patch="1" adv="1">DSA-685</ref>
      <ref url="http://www.debian.org/security/2005/dsa-671" source="DEBIAN" patch="1" adv="1">DSA-671</ref>
      <ref url="http://www.debian.org/security/2005/dsa-670" source="DEBIAN" patch="1" adv="1">DSA-670</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9408" source="OVAL">oval:org.mitre.oval:def:9408</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780416112719&amp;w=2" source="BUGTRAQ" adv="1">20050207 [USN-76-1] Emacs vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12462" source="BID">12462</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433928/30/5010/threaded" source="FEDORA">FLSA-2006:152898</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:038" source="MANDRAKE">MDKSA-2005:038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="emacs">
        <vers prev="1" num="20.0"/>
        <vers num="21.3"/>
      </prod>
      <prod vendor="gnu" name="xemacs">
        <vers prev="1" num="21.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0101" published="2005-02-01" name="CVE-2005-0101" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19178" source="XF">newspost-socketgetline-bo(19178)</ref>
      <ref url="http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html</ref>
      <ref url="http://secunia.com/advisories/14092/" source="SECUNIA" adv="1">14092</ref>
      <ref url="http://people.freebsd.org/~niels/issues/newspost-20050114.txt" source="MISC" adv="1">http://people.freebsd.org/~niels/issues/newspost-20050114.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746336728781&amp;w=2" source="BUGTRAQ" adv="1">20050202 RE: SECURITEY.NNOV.RU NewsPost buffer overflow [EXPLOIT]</ref>
      <ref url="http://www.securityfocus.com/bid/12418" source="BID">12418</ref>
      <ref url="http://securitytracker.com/id?1013056" source="SECTRACK">1013056</ref>
      <ref url="http://secunia.com/advisories/14098" source="SECUNIA">14098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newspost" name="newspost">
        <vers prev="1" num="2.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0102" published="2005-01-24" name="CVE-2005-0102" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19031" source="XF" patch="1" adv="1">evolution-camellockhelper-bo(19031)</ref>
      <ref url="http://www.securityfocus.com/bid/12354" source="BID" patch="1" adv="1">12354</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-397.html" source="REDHAT" patch="1" adv="1">RHSA-2005:397</ref>
      <ref url="http://www.debian.org/security/2005/dsa-673" source="DEBIAN" patch="1" adv="1">DSA-673</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-35.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-35</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000925" source="CONECTIVA" patch="1" adv="1">CLA-2005:925</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-238.html" source="REDHAT">RHSA-2005:238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9616" source="OVAL">oval:org.mitre.oval:def:9616</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-69-1" source="UBUNTU">USN-69-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:024" source="MANDRAKE">MDKSA-2005:024</ref>
      <ref url="http://securitytracker.com/id?1012981" source="SECTRACK">1012981</ref>
      <ref url="http://secunia.com/advisories/13830" source="SECUNIA">13830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.3.2_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0103" published="2005-01-24" name="CVE-2005-0103" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-135.html" source="REDHAT" patch="1" adv="1">RHSA-2005:135</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-099.html" source="REDHAT" patch="1" adv="1">RHSA-2005:099</ref>
      <ref url="http://secunia.com/advisories/13962/" source="SECUNIA" patch="1" adv="1">13962</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19037" source="XF">squirrelmail-frame-file-include(19037)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" source="GENTOO">GLSA-200501-39</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10670" source="OVAL">oval:org.mitre.oval:def:10670</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" source="BUGTRAQ" adv="1">20050129 SquirrelMail Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.4"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.3_rc1"/>
        <vers num="1.4.3a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0104" published="2005-01-29" name="CVE-2005-0104" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2005-01-20" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2005-01-20</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-135.html" source="REDHAT" patch="1" adv="1">RHSA-2005:135</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-099.html" source="REDHAT" patch="1" adv="1">RHSA-2005:099</ref>
      <ref url="http://www.debian.org/security/2005/dsa-662" source="DEBIAN" patch="1" adv="1">DSA-662</ref>
      <ref url="http://secunia.com/advisories/14096" source="SECUNIA" patch="1" adv="1">14096</ref>
      <ref url="http://secunia.com/advisories/13962/" source="SECUNIA" patch="1" adv="1">13962</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050129 SquirrelMail Security Advisory</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10568" source="OVAL">oval:org.mitre.oval:def:10568</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19036" source="XF">squirrelmail-webmailphp-xss(19036)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" source="GENTOO">GLSA-200501-39</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.4"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.3_rc1"/>
        <vers num="1.4.3a"/>
        <vers num="1.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0105" published="2005-02-16" name="CVE-2005-0105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-684" source="DEBIAN" patch="1" adv="1">DSA-684</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typespeed" name="typespeed">
        <vers num="0.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0106" published="2005-05-03" name="CVE-2005-0106" modified="2009-11-13" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-113-1" source="UBUNTU" patch="1">USN-113-1</ref>
      <ref url="http://www.securityfocus.com/bid/13471" source="BID">13471</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:023" source="MANDRIVA">MDKSA-2006:023</ref>
      <ref url="http://secunia.com/advisories/18639" source="SECUNIA">18639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="5.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0107" published="2005-02-25" name="CVE-2005-0107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-690" source="DEBIAN" patch="1" adv="1">DSA-690</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="bsmtpd">
        <vers prev="1" num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0108" published="2005-01-11" name="CVE-2005-0108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18841" source="XF" adv="1">modauthradius-dos(18841)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-659" source="DEBIAN" adv="1">DSA-659</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02" source="MISC" adv="1">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548193312050&amp;w=2" source="BUGTRAQ" adv="1">20050111 Apache mod_auth_radius remote integer overflow</ref>
      <ref url="http://www.securityfocus.com/bid/12217" source="BID">12217</ref>
      <ref url="http://securitytracker.com/id?1012829" source="SECTRACK">1012829</ref>
      <ref url="http://secunia.com/advisories/14046" source="SECUNIA">14046</ref>
      <ref url="http://secunia.com/advisories/13773" source="SECUNIA">13773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_auth_radius">
        <vers num="1.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0109" published="2005-03-05" name="CVE-2005-0109" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/911878" source="CERT-VN" adv="1">VU#911878</ref>
      <ref url="http://www.securityfocus.com/bid/12724" source="BID" patch="1" adv="1">12724</ref>
      <ref url="http://securitytracker.com/id?1013967" source="SECTRACK" patch="1" adv="1">1013967</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/3002" source="VUPEN">ADV-2005-3002</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0540" source="VUPEN">ADV-2005-0540</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-800.html" source="REDHAT">RHSA-2005:800</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-476.html" source="REDHAT">RHSA-2005:476</ref>
      <ref url="http://www.daemonology.net/papers/htt.pdf" source="MISC">http://www.daemonology.net/papers/htt.pdf</ref>
      <ref url="http://www.daemonology.net/hyperthreading-considered-harmful/" source="MISC">http://www.daemonology.net/hyperthreading-considered-harmful/</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754" source="MISC">http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1" source="SUNALERT" adv="1">101739</ref>
      <ref url="http://secunia.com/advisories/18165" source="SECUNIA">18165</ref>
      <ref url="http://secunia.com/advisories/15348" source="SECUNIA">15348</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9747" source="OVAL">oval:org.mitre.oval:def:9747</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-misc&amp;m=110995101417256&amp;w=2" source="MLIST">[openbsd-misc] 20050304 Re: FreeBSD hiding security stuff</ref>
      <ref url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=110994370429609&amp;w=2" source="MLIST">[freebsd-security] 20050304 [Fwd: Re: FW:FreeBSD hiding security stuff]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=freebsd-hackers&amp;m=110994026421858&amp;w=2" source="MLIST">[freebsd-hackers] 20050304 Re: FW:FreeBSD hiding security stuff</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txt" source="SCO">SCOSA-2005.24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0" edition="releng"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5" edition="stable"/>
        <vers num="3.5.1" edition="release"/>
        <vers num="3.5.1" edition="stable"/>
        <vers num="4.0" edition="alpha"/>
        <vers num="4.0" edition="releng"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
        <vers num="4.1.1" edition="stable"/>
        <vers num="4.10" edition="release"/>
        <vers num="4.10" edition="release_p8"/>
        <vers num="4.10" edition="releng"/>
        <vers num="4.11" edition="release_p3"/>
        <vers num="4.11" edition="releng"/>
        <vers num="4.11" edition="stable"/>
        <vers num="4.2" edition="stable"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.3" edition="release_p38"/>
        <vers num="4.3" edition="releng"/>
        <vers num="4.3" edition="stable"/>
        <vers num="4.4" edition="release_p42"/>
        <vers num="4.4" edition="releng"/>
        <vers num="4.4" edition="stable"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.5" edition="release_p32"/>
        <vers num="4.5" edition="releng"/>
        <vers num="4.5" edition="stable"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.6" edition="release_p20"/>
        <vers num="4.6" edition="releng"/>
        <vers num="4.6" edition="stable"/>
        <vers num="4.6.2"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.7" edition="release_p17"/>
        <vers num="4.7" edition="releng"/>
        <vers num="4.7" edition="stable"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="4.8" edition="release_p6"/>
        <vers num="4.8" edition="releng"/>
        <vers num="4.9" edition="pre-release"/>
        <vers num="4.9" edition="releng"/>
        <vers num="5.0" edition="alpha"/>
        <vers num="5.0" edition="release_p14"/>
        <vers num="5.0" edition="releng"/>
        <vers num="5.1" edition="alpha"/>
        <vers num="5.1" edition="release"/>
        <vers num="5.1" edition="release_p5"/>
        <vers num="5.1" edition="releng"/>
        <vers num="5.2"/>
        <vers num="5.2.1" edition="release"/>
        <vers num="5.2.1" edition="releng"/>
        <vers num="5.3" edition="release"/>
        <vers num="5.3" edition="releng"/>
        <vers num="5.3" edition="stable"/>
        <vers num="5.4" edition="pre-release"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation_ia64"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":advanced_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0"/>
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.7"/>
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.3"/>
        <vers num="7.1.3_up"/>
        <vers num="7.1.4"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":sparc"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86"/>
        <vers num="9.0" edition="x86_update_2"/>
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition=""/>
        <vers num="4.1" edition=":ppc"/>
        <vers num="4.1" edition=":ia64"/>
        <vers num="5.04" edition=""/>
        <vers num="5.04" edition=":i386"/>
        <vers num="5.04" edition=":powerpc"/>
        <vers num="5.04" edition=":amd64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0110" published="2005-01-14" name="CVE-2005-0110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110569119106172&amp;w=2" source="FULLDISC" adv="1">20050114 Internet Explorer (SP2) - Remote File Download</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0111" published="2005-01-13" name="CVE-2005-0111" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12265" source="BID">12265</ref>
      <ref url="http://securitytracker.com/id?1012893" source="SECTRACK">1012893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0112" published="2005-04-14" name="CVE-2005-0112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web-based administrative interface for 3Com OfficeConnect Wireless 11g Access Point (AP) 1.00.08, and possibly earlier versions before 1.03.07A, allows remote attackers to bypass authentication and obtain sensitive information by directly accessing the (1) config.bin (2) profile.wlp?PN=ggg or (3) event.logs URLs.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18994" source="XF" patch="1" adv="1">3com-officeconnect-information-disclosure(18994)</ref>
      <ref url="http://www.securityfocus.com/bid/12322" source="BID" patch="1" adv="1">12322</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=188&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050120 3Com OfficeConnect Wireless 11g AP Information Disclosure Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1012958" source="SECTRACK">1012958</ref>
      <ref url="http://secunia.com/advisories/13942" source="SECUNIA">13942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3crwe454g72">
        <vers num="1.0.2"/>
        <vers num="1.0.2.11"/>
        <vers num="1.0.3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0113" published="2005-01-14" name="CVE-2005-0113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18894" source="XF" adv="1">irix-inpview-gain-privileges(18894)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=182&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050113 SGI IRIX inpview Design Error Vulnerability</ref>
      <ref url="http://secunia.com/advisories/13858" source="SECUNIA" adv="1">13858</ref>
      <ref url="http://www.securityfocus.com/bid/12259" source="BID">12259</ref>
      <ref url="http://www.osvdb.org/12915" source="OSVDB">12915</ref>
      <ref url="http://securitytracker.com/id?1012894" source="SECTRACK">1012894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0114" published="2005-02-11" name="CVE-2005-0114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=199&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050211 ZoneAlarm 5.1 Invalid Pointer Dereference Vulnerability</ref>
      <ref url="http://download.zonelabs.com/bin/free/securityAlert/19.html" source="CONFIRM" patch="1" adv="1">http://download.zonelabs.com/bin/free/securityAlert/19.html</ref>
      <ref url="http://www.securityfocus.com/bid/12531" source="BID">12531</ref>
      <ref url="http://secunia.com/advisories/14256" source="SECUNIA">14256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="check_point_integrity_client">
        <vers num="4.5.122.000"/>
        <vers prev="1" num="5.1.556.166"/>
      </prod>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="5.5.062.011"/>
      </prod>
      <prod vendor="zonelabs" name="zonealarm_wireless_security">
        <vers prev="1" num="5.5.080.000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0115" published="2005-01-24" name="CVE-2005-0115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19042" source="XF" patch="1" adv="1">database-ida-portable-executable-bo(19042)</ref>
      <ref url="http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html" source="CONFIRM" patch="1" adv="1">http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12353" source="BID">12353</ref>
      <ref url="http://securitytracker.com/id?1012975" source="SECTRACK">1012975</ref>
      <ref url="http://secunia.com/advisories/13980" source="SECUNIA">13980</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datarescue" name="ida">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0116" published="2005-01-18" name="CVE-2005-0116" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/272296" source="CERT-VN" patch="1" adv="1">VU#272296</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=185&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20050117 AWStats Remote Command Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/13893/" source="SECUNIA" patch="1" adv="1">13893</ref>
      <ref url="http://awstats.sourceforge.net/docs/awstats_changelog.txt" source="CONFIRM" patch="1" adv="1">http://awstats.sourceforge.net/docs/awstats_changelog.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12298" source="BID">12298</ref>
      <ref url="http://www.osvdb.org/13002" source="OSVDB">13002</ref>
      <ref url="http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf" source="MISC">http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers prev="1" num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0117" published="2005-01-11" name="CVE-2005-0117" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784" source="MISC" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xshisen" name="xshisen">
        <vers prev="1" num="1.36"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0118" published="2005-05-02" name="CVE-2005-0118" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helvis" name="helvis">
        <vers prev="1" num="1.8h2_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0119" published="2005-05-02" name="CVE-2005-0119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html" source="CONFIRM">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helvis" name="helvis">
        <vers prev="1" num="1.8h2_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0120" published="2005-05-02" name="CVE-2005-0120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt" source="MISC" adv="1">http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0121" published="2005-05-02" name="CVE-2005-0121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19040" source="XF">golddig-long-username-bo(19040)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19039" source="XF">golddig-long-mapname-bo(19039)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_siegel" name="golddig">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0122" reject="1" published="2005-04-14" name="CVE-2005-0122" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0975.  Reason: This candidate is a duplicate of CVE-2005-0975.  Notes: All CVE users should reference CVE-2005-0975 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0124" published="2005-04-14" name="CVE-2005-0124" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://seclists.org/lists/linux-kernel/2005/Jan/2020.html" source="MLIST">[linux-kernel] 20050107 [PATCH 2.6.10-mm2] fs/coda Re: [Coverity] Untrusted user data in kernel</ref>
      <ref url="http://seclists.org/lists/linux-kernel/2005/Jan/2018.html" source="MLIST" adv="1">[linux-kernel] 20050107 [PATCH 2.4.29-pre3-bk4] fs/coda Re: [Coverity] Untrusted user data in kernel</ref>
      <ref url="http://seclists.org/lists/linux-kernel/2005/Jan/1089.html" source="MLIST">[linux-kernel] 20050105 Re: [Coverity] Untrusted user data in kernel</ref>
      <ref url="http://seclists.org/lists/linux-kernel/2004/Dec/3914.html" source="MLIST">[linux-kernel] 20041216 [Coverity] Untrusted user data in kernel</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11690" source="OVAL">oval:org.mitre.oval:def:11690</ref>
      <ref url="http://www.securityfocus.com/bid/14967" source="BID">14967</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded" source="FEDORA">FLSA:157459-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0191.html" source="REDHAT">RHSA-2006:0191</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://securitytracker.com/id?1013018" source="SECTRACK">1013018</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA">19374</ref>
      <ref url="http://secunia.com/advisories/18684" source="SECUNIA">18684</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.6.9" edition="2.6.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0125" published="2005-05-02" name="CVE-2005-0125" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/678150" source="CERT-VN" patch="1" adv="1">VU#678150</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-01-25</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18981" source="XF" adv="1">macos-at-gain-privileges(18981)</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0127a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0127a].txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685027017411&amp;w=2" source="BUGTRAQ" adv="1">20050127 DMA[2005-0127a] - 'Apple OSX batch family poor use of setuid'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.4"/>
        <vers num="10.3.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0126" published="2005-05-02" name="CVE-2005-0126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/980078" source="CERT-VN" patch="1" adv="1">VU#980078</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19083" source="XF" patch="1" adv="1">macos-icc-profile-bo(19083)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-01-25</ref>
      <ref url="http://www.securityfocus.com/bid/12367" source="BID">12367</ref>
      <ref url="http://securitytracker.com/id?1013000" source="SECTRACK">1013000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8"/>
        <vers num="10.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0127" published="2005-05-02" name="CVE-2005-0127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/464662" source="CERT-VN" patch="1" adv="1">VU#464662</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19085" source="XF" patch="1" adv="1">macos-ethernet-address-disclosure(19085)</ref>
      <ref url="http://secunia.com/advisories/14005" source="SECUNIA" patch="1" adv="1">14005</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-01-25</ref>
      <ref url="http://securitytracker.com/id?1013001" source="SECTRACK">1013001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0129" published="2005-04-14" name="CVE-2005-0129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19025" source="XF" adv="1">konversation-expansion-execute-code(19025)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" source="FULLDISC">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://www.securityfocus.com/bid/12312" source="BID">12312</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050121-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20050121-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" source="GENTOO">GLSA-200501-34</ref>
      <ref url="http://securitytracker.com/id?1012972" source="SECTRACK">1012972</ref>
      <ref url="http://secunia.com/advisories/13989" source="SECUNIA">13989</ref>
      <ref url="http://secunia.com/advisories/13919" source="SECUNIA">13919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berlios" name="konversation">
        <vers num="0.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0130" published="2005-04-14" name="CVE-2005-0130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC sripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19008" source="XF" adv="1">konversation-perlscript-execute-code(19008)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" source="FULLDISC">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://www.securityfocus.com/bid/12312" source="BID">12312</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050121-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20050121-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" source="GENTOO">GLSA-200501-34</ref>
      <ref url="http://securitytracker.com/id?1012972" source="SECTRACK">1012972</ref>
      <ref url="http://secunia.com/advisories/13989" source="SECUNIA">13989</ref>
      <ref url="http://secunia.com/advisories/13919" source="SECUNIA">13919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berlios" name="konversation">
        <vers num="0.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0131" published="2005-04-14" name="CVE-2005-0131" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19038" source="XF">konversation-nick-password-information-disclosure(19038)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" source="FULLDISC">20050119 Multiple vulnerabilities in Konversation</ref>
      <ref url="http://www.securityfocus.com/bid/12312" source="BID">12312</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050121-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20050121-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" source="GENTOO">GLSA-200501-34</ref>
      <ref url="http://securitytracker.com/id?1012972" source="SECTRACK">1012972</ref>
      <ref url="http://secunia.com/advisories/13989" source="SECUNIA">13989</ref>
      <ref url="http://secunia.com/advisories/13919" source="SECUNIA">13919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berlios" name="konversation">
        <vers num="0.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0133" published="2005-05-02" name="CVE-2005-0133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-46</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=300116" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=300116</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000928" source="CONECTIVA" patch="1" adv="1">CLA-2005:928</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025" source="MANDRAKE">MDKSA-2005:025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.51"/>
        <vers num="0.52"/>
        <vers num="0.53"/>
        <vers num="0.54"/>
        <vers num="0.60"/>
        <vers num="0.65"/>
        <vers num="0.67"/>
        <vers num="0.68"/>
        <vers num="0.68.1"/>
        <vers num="0.80"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0134" published="2005-05-18" name="CVE-2005-0134" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The X server in SCO UnixWare 7.1.1, 7.1.3, and 7.1.4 does not properly create socket directories in /tmp, which could allow attackers to hijack local sockets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.8/SCOSA-2005.8.txt" source="SCO" patch="1">SCOSA-2005.8</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0077" source="VUPEN">ADV-2005-0077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0135" published="2005-05-02" name="CVE-2005-0135" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT" patch="1" adv="1">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" patch="1" adv="1">RHSA-2005:284</ref>
      <ref url="http://secunia.com/advisories/15019" source="SECUNIA" patch="1" adv="1">15019</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9040" source="OVAL">oval:org.mitre.oval:def:9040</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg</ref>
      <ref url="http://www.securityfocus.com/bid/13266" source="BID">13266</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0136" published="2005-12-31" name="CVE-2005-0136" modified="2011-03-07" discovered="2005-09-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283" source="MISC" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862" source="MISC" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT" patch="1">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-420.html" source="REDHAT" patch="1">RHSA-2005:420</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11</ref>
      <ref url="http://www.gelato.unsw.edu.au/archives/linux-ia64/0409/11073.html" source="MLIST" patch="1">[linux-ia64] 20040916 Re: [Patch] Per CPU MCA/INIT data save areas</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA" patch="1" adv="1">17002</ref>
      <ref url="http://openvz.org/news/updates/kernel-022stab045.1-released" source="MISC" patch="1">http://openvz.org/news/updates/kernel-022stab045.1-released</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11628" source="OVAL">oval:org.mitre.oval:def:11628</ref>
      <ref url="http://lists.alioth.debian.org/pipermail/kernel-svn-changes/2005-August/002597.html" source="MLIST">[kernel-svn-changes] 20050816 r3920 - in branches/dist/sarge-security: . kernel kernel/i386 kernel/source kernel/source/kernel-source-2.6.8-2.6.8/debian</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" edition="rc1"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.10" edition="rc3"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8" edition="rc4"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.8.1.5" edition=""/>
        <vers num="2.6.8.1.5" edition=":power4"/>
        <vers num="2.6.8.1.5" edition=":amd64"/>
        <vers num="2.6.8.1.5" edition=":amd64_xeon"/>
        <vers num="2.6.8.1.5" edition=":k7_smp"/>
        <vers num="2.6.8.1.5" edition=":386"/>
        <vers num="2.6.8.1.5" edition=":amd64_k8"/>
        <vers num="2.6.8.1.5" edition=":686"/>
        <vers num="2.6.8.1.5" edition=":power3_smp"/>
        <vers num="2.6.8.1.5" edition=":powerpc_smp"/>
        <vers num="2.6.8.1.5" edition=":power4_smp"/>
        <vers num="2.6.8.1.5" edition=":k7"/>
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp"/>
        <vers num="2.6.8.1.5" edition=":686_smp"/>
        <vers num="2.6.8.1.5" edition=":powerpc"/>
        <vers num="2.6.8.1.5" edition=":power3"/>
        <vers num="2.6.9" edition="2.6.20"/>
        <vers num="2.6.9" edition="final"/>
        <vers num="2.6.9" edition="rc1"/>
        <vers num="2.6.9" edition="rc2"/>
        <vers num="2.6.9" edition="rc3"/>
        <vers num="2.6.9" edition="rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0137" published="2005-05-02" name="CVE-2005-0137" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT" patch="1" adv="1">RHSA-2005:293</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" patch="1" adv="1">RHSA-2005:284</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11039" source="OVAL">oval:org.mitre.oval:def:11039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0138" published="2005-09-21" name="CVE-2005-0138" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined.  NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/p-214.shtml" source="CIAC" adv="1">P-214</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0702" source="VUPEN">ADV-2005-0702</ref>
      <ref url="http://secunia.com/advisories/15619" source="SECUNIA">15619</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.25"/>
        <vers num="6.5.26"/>
        <vers num="6.5.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0139" published="2005-09-21" name="CVE-2005-0139" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/p-214.shtml" source="CIAC" adv="1">P-214</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0702" source="VUPEN">ADV-2005-0702</ref>
      <ref url="http://secunia.com/advisories/15619" source="SECUNIA">15619</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.25"/>
        <vers num="6.5.26"/>
        <vers num="6.5.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0140" published="2005-05-02" name="CVE-2005-0140" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PeID allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19042" source="XF" patch="1" adv="1">database-ida-portable-executable-bo(19042)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12355" source="BID">12355</ref>
      <ref url="http://secunia.com/advisories/13984" source="SECUNIA">13984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peid" name="peid">
        <vers num="0.92"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0141" published="2005-05-02" name="CVE-2005-0141" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19168" source="XF" patch="1" adv="1">mozilla-firefox-file-upload(19168)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=249332" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=249332</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-01.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10756" source="OVAL">oval:org.mitre.oval:def:10756</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100057" source="OVAL" sig="1">oval:org.mitre.oval:def:100057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0142" published="2005-05-02" name="CVE-2005-0142" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17832" source="XF" patch="1" adv="1">mozilla-world-readable(17832)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=251297" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=251297</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-02.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-02.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9543" source="OVAL">oval:org.mitre.oval:def:9543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100056" source="OVAL" sig="1">oval:org.mitre.oval:def:100056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.9"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0143" published="2005-03-23" name="CVE-2005-0143" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=257308" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=257308</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19166" source="XF" patch="1" adv="1">mozilla-ssl-spoofing(19166)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-03.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-03.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11297" source="OVAL">oval:org.mitre.oval:def:11297</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100055" source="OVAL" sig="1">oval:org.mitre.oval:def:100055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8"/>
        <vers num="0.9.2"/>
        <vers num="0.9.2.1"/>
        <vers num="0.9.3"/>
        <vers num="0.9.35"/>
        <vers num="0.9.4"/>
        <vers num="0.9.4.1"/>
        <vers num="0.9.48"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.2" edition="alpha"/>
        <vers num="1.2" edition="beta"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4" edition="beta"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.4"/>
        <vers num="1.5" edition="alpha"/>
        <vers num="1.5" edition="rc1"/>
        <vers num="1.5" edition="rc2"/>
        <vers num="1.5.1"/>
        <vers num="1.6" edition="alpha"/>
        <vers num="1.6" edition="beta"/>
        <vers num="1.7" edition="alpha"/>
        <vers num="1.7" edition="beta"/>
        <vers num="1.7" edition="rc1"/>
        <vers num="1.7" edition="rc2"/>
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.5"/>
        <vers num="1.8" edition="alpha2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0144" published="2005-05-02" name="CVE-2005-0144" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19169" source="XF" patch="1" adv="1">mozilla-ssl-view-source-spoofing(19169)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=262689" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=262689</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-04.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-04.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11016" source="OVAL">oval:org.mitre.oval:def:11016</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100054" source="OVAL" sig="1">oval:org.mitre.oval:def:100054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0145" published="2005-01-24" name="CVE-2005-0145" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=265176" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=265176</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19170" source="XF" patch="1" adv="1">mozilla-script-click-event-bypass(19170)</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-07.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-07.html</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100051" source="OVAL" sig="1">oval:org.mitre.oval:def:100051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0146" published="2005-05-02" name="CVE-2005-0146" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=265728" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=265728</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19171" source="XF">mozilla-middle-click-information-disclosure(19171)</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-08.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-08.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10362" source="OVAL">oval:org.mitre.oval:def:10362</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0147" published="2005-05-02" name="CVE-2005-0147" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19174" source="XF" patch="1" adv="1">mozilla-407-proxy-obtain-information(19174)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=267263" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=267263</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-09.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-09.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9578" source="OVAL">oval:org.mitre.oval:def:9578</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100049" source="OVAL" sig="1">oval:org.mitre.oval:def:100049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0148" published="2005-05-02" name="CVE-2005-0148" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system.  NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <env/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19173" source="XF" patch="1" adv="1">thunderbird-javascript-handler-launch(19173)</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=263546" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=263546</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-10.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-10.html</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100048" source="OVAL" sig="1">oval:org.mitre.oval:def:100048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0149" published="2005-02-15" name="CVE-2005-0149" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=268107" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=268107</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19172" source="XF" patch="1" adv="1">mozilla-cookie-policy-bypass(19172)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-094.html" source="REDHAT" patch="1" adv="1">RHSA-2005:094</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-11.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-11.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11407" source="OVAL">oval:org.mitre.oval:def:11407</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100047" source="OVAL" sig="1">oval:org.mitre.oval:def:100047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="alpha"/>
        <vers num="1.7" edition="beta"/>
        <vers num="1.7" edition="rc1"/>
        <vers num="1.7" edition="rc2"/>
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0150" published="2005-05-26" name="CVE-2005-0150" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=265668" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=265668</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19187" source="XF" patch="1" adv="1">mozilla-firefox-livefeed-xss(19187)</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-12.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-12.html</ref>
      <ref url="http://www.securityfocus.com/bid/12407" source="BID">12407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100046" source="OVAL" sig="1">oval:org.mitre.oval:def:100046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0151" published="2005-06-13" name="CVE-2005-0151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/331688.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/331688.html</ref>
      <ref url="http://securitytracker.com/id?1014170" source="SECTRACK">1014170</ref>
      <ref url="http://securitytracker.com/id?1014169" source="SECTRACK">1014169</ref>
      <ref url="http://securitytracker.com/id?1014168" source="SECTRACK">1014168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="creative_suite">
        <vers num="1.0"/>
      </prod>
      <prod vendor="adobe" name="photoshop">
        <vers num="8.0"/>
      </prod>
      <prod vendor="adobe" name="premiere">
        <vers num="1.5" edition=""/>
        <vers num="1.5" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0152" published="2005-02-02" name="CVE-2005-0152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/203214" source="CERT-VN" patch="1" adv="1">VU#203214</ref>
      <ref url="http://www.debian.org/security/2005/dsa-662" source="DEBIAN" patch="1" adv="1">DSA-662</ref>
      <ref url="http://secunia.com/advisories/14096" source="SECUNIA" patch="1" adv="1">14096</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0155" published="2005-05-02" name="CVE-2005-0155" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19207" source="XF" patch="1" adv="1">perl-perliodebug-file-overwrite(19207)</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1">2005-0003</ref>
      <ref url="http://www.securityfocus.com/bid/12426" source="BID" patch="1" adv="1">12426</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-105.html" source="REDHAT" patch="1" adv="1">RHSA-2005:105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-103.html" source="REDHAT" patch="1" adv="1">RHSA-2005:103</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-13</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779723332339&amp;w=2" source="FULLDISC" patch="1" adv="1">20050207 DMA[2005-0131a] - 'Setuid Perl PERLIO_DEBUG root owned file creation'</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050202 [USN-72-1] Perl vulnerabilities</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0131a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0131a].txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10404" source="OVAL">oval:org.mitre.oval:def:10404</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031" source="MANDRAKE">MDKSA-2005:031</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm</ref>
      <ref url="http://secunia.com/advisories/21646" source="SECUNIA">21646</ref>
      <ref url="http://secunia.com/advisories/14120" source="SECUNIA">14120</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056" source="CONECTIVA">CLSA-2006:1056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0156" published="2005-02-07" name="CVE-2005-0156" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19208" source="XF" patch="1" adv="1">perl-perliodebug-bo(19208)</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.securityfocus.com/bid/12426" source="BID" patch="1" adv="1">12426</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-105.html" source="REDHAT" patch="1" adv="1">RHSA-2005:105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-103.html" source="REDHAT" patch="1" adv="1">RHSA-2005:103</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml" source="GENTOO" adv="1">GLSA-200502-13</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0131b].txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10803" source="OVAL">oval:org.mitre.oval:def:10803</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779721503111&amp;w=2" source="FULLDISC" adv="1">20050207 DMA[2005-0131b] - 'Setuid Perl PERLIO_DEBUG</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2" source="BUGTRAQ" adv="1">20050202 [USN-72-1] Perl vulnerabilities</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031" source="MANDRAKE">MDKSA-2005:031</ref>
      <ref url="http://secunia.com/advisories/14120" source="SECUNIA">14120</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056" source="CONECTIVA">CLSA-2006:1056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.8.0"/>
        <vers num="5.8.1"/>
        <vers num="5.8.3"/>
        <vers num="5.8.4"/>
        <vers num="5.8.4.1"/>
        <vers num="5.8.4.2"/>
        <vers num="5.8.4.2.3"/>
        <vers num="5.8.4.3"/>
        <vers num="5.8.4.4"/>
        <vers num="5.8.4.5"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0"/>
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="5.2"/>
        <vers num="5.3"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition=""/>
        <vers num="4.1" edition=":ia64"/>
        <vers num="4.1" edition=":ppc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0157" published="2005-05-03" name="CVE-2005-0157" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-720" source="DEBIAN" patch="1">DSA-720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartlist" name="smartlist">
        <vers prev="1" num="3.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0158" published="2005-05-02" name="CVE-2005-0158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-06.xml" source="GENTOO" patch="1">GLSA-200503-06</ref>
      <ref url="http://www.debian.org/security/2005/dsa-687" source="DEBIAN" patch="1" adv="1">DSA-687</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bidwatcher" name="bidwatcher">
        <vers num="1.0.5"/>
        <vers num="1.1.2"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.9.1"/>
        <vers num="1.1.9.2"/>
        <vers num="1.2.0"/>
        <vers num="1.3.0_beta"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.3.14"/>
        <vers num="1.3.15"/>
        <vers num="1.3.16"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0159" published="2005-04-27" name="CVE-2005-0159" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12540" source="BID" patch="1" adv="1">12540</ref>
      <ref url="http://www.debian.org/security/2005/dsa-679" source="DEBIAN" patch="1" adv="1">DSA-679</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19317" source="XF">toolchain-source-symlink(19317)</ref>
      <ref url="http://secunia.com/advisories/14277" source="SECUNIA">14277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="toolchain-source">
        <vers num="3.0.3-1"/>
        <vers num="3.0.3-2"/>
        <vers num="3.0.3-3"/>
        <vers num="3.0.4"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":sparc"/>
        <vers num="3.0" edition=":ppc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0160" published="2005-02-22" name="CVE-2005-0160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/215006" source="CERT-VN">VU#215006</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_sr.html" source="SUSE">SUSE-SR:2005:016</ref>
      <ref url="http://secunia.com/advisories/14359" source="SECUNIA" adv="1">14359</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html" source="FULLDISC" adv="1">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref>
      <ref url="http://www.securityfocus.com/bid/12630" source="BID">12630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-merge" name="unace">
        <vers num="1.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0161" published="2005-02-22" name="CVE-2005-0161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_sr.html" source="SUSE">SUSE-SR:2005:016</ref>
      <ref url="http://secunia.com/advisories/14359" source="SECUNIA" adv="1">14359</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html" source="FULLDISC" adv="1">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref>
      <ref url="http://www.securityfocus.com/bid/12628" source="BID">12628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-merge" name="unace">
        <vers num="1.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0162" published="2005-01-26" name="CVE-2005-0162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19078" source="XF" patch="1" adv="1">openswan-xauth-pam-bo(19078)</ref>
      <ref url="http://www.openswan.org/support/vuln/IDEF0785/" source="CONFIRM" patch="1" adv="1">http://www.openswan.org/support/vuln/IDEF0785/</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=190&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050126 Openswan XAUTH/PAM Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12377" source="BID">12377</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00103.html" source="FEDORA">FEDORA-2005-082</ref>
      <ref url="http://www.osvdb.org/13195" source="OSVDB">13195</ref>
      <ref url="http://securitytracker.com/id?1013014" source="SECTRACK">1013014</ref>
      <ref url="http://secunia.com/advisories/14062" source="SECUNIA">14062</ref>
      <ref url="http://secunia.com/advisories/14038" source="SECUNIA">14038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openswan" name="openswan">
        <vers prev="1" num="1.0.9"/>
        <vers num="2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0173" published="2005-05-02" name="CVE-2005-0173" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/924198" source="CERT-VN" patch="1" adv="1">VU#924198</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://www.debian.org/security/2005/dsa-667" source="DEBIAN" patch="1" adv="1">DSA-667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" patch="1">CLA-2005:923</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1187" source="CONFIRM">http://www.squid-cache.org/bugs/show_bug.cgi?id=1187</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10251" source="OVAL">oval:org.mitre.oval:def:10251</ref>
      <ref url="http://www.securityfocus.com/bid/12431" source="BID">12431</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" source="MANDRAKE">MDKSA-2005:034</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0.patch1"/>
        <vers num="2.0.patch2"/>
        <vers num="2.0.pre1"/>
        <vers num="2.0.release"/>
        <vers num="2.1.patch1"/>
        <vers num="2.1.patch2"/>
        <vers num="2.1.pre1"/>
        <vers num="2.1.pre3"/>
        <vers num="2.1.pre4"/>
        <vers num="2.1.release"/>
        <vers num="2.2.devel3"/>
        <vers num="2.2.devel4"/>
        <vers num="2.2.pre1"/>
        <vers num="2.2.pre2"/>
        <vers num="2.2.stable1"/>
        <vers num="2.2.stable2"/>
        <vers num="2.2.stable3"/>
        <vers num="2.2.stable4"/>
        <vers num="2.2.stable5"/>
        <vers num="2.3.devel2"/>
        <vers num="2.3.devel3"/>
        <vers num="2.3.stable1"/>
        <vers num="2.3.stable2"/>
        <vers num="2.3.stable3"/>
        <vers num="2.3.stable4"/>
        <vers num="2.3.stable5"/>
        <vers num="2.4.stable1"/>
        <vers num="2.4.stable2"/>
        <vers num="2.4.stable3"/>
        <vers num="2.4.stable4"/>
        <vers num="2.4.stable6"/>
        <vers num="2.4.stable7"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0174" published="2005-02-07" name="CVE-2005-0174" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/768702" source="CERT-VN" adv="1">VU#768702</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1">RHSA-2005:060</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html" source="FEDORA">FEDORA-2005-373</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10656" source="OVAL">oval:org.mitre.oval:def:10656</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" source="BUGTRAQ" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" adv="1">CLA-2005:931</ref>
      <ref url="http://www.securityfocus.com/bid/12412" source="BID">12412</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" source="MANDRAKE">MDKSA-2005:034</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.6"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
        <vers num="2.5.stable7"/>
        <vers num="2.5_.stable1"/>
        <vers num="2.5_.stable3"/>
        <vers num="2.5_.stable4"/>
        <vers num="2.5_.stable5"/>
        <vers num="2.5_.stable6"/>
        <vers num="2.5_stable3"/>
        <vers num="2.5_stable4"/>
        <vers num="2.5_stable9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0175" published="2005-02-07" name="CVE-2005-0175" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/625878" source="CERT-VN" patch="1" adv="1">VU#625878</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://www.debian.org/security/2005/dsa-667" source="DEBIAN" patch="1" adv="1">DSA-667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" patch="1" adv="1">CLA-2005:931</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2005_5.txt" source="CONFIRM" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_5.txt</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html" source="FEDORA">FEDORA-2005-373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11605" source="OVAL">oval:org.mitre.oval:def:11605</ref>
      <ref url="http://www.securityfocus.com/bid/12433" source="BID">12433</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" source="MANDRAKE">MDKSA-2005:034</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.6"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
        <vers num="2.5.stable7"/>
        <vers num="2.5_.stable1"/>
        <vers num="2.5_.stable3"/>
        <vers num="2.5_.stable4"/>
        <vers num="2.5_.stable5"/>
        <vers num="2.5_.stable6"/>
        <vers num="2.5_stable3"/>
        <vers num="2.5_stable4"/>
        <vers num="2.5_stable9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0176" published="2005-02-15" name="CVE-2005-0176" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" adv="1">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8778" source="OVAL">oval:org.mitre.oval:def:8778</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" source="BUGTRAQ" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-472.html" source="REDHAT">RHSA-2005:472</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1225" source="OVAL" sig="1">oval:org.mitre.oval:def:1225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.9" edition="2.6.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0177" published="2005-03-07" name="CVE-2005-0177" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ" source="CONFIRM" patch="1" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" patch="1" adv="1">CLA-2005:930</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10298" source="OVAL">oval:org.mitre.oval:def:10298</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" source="BUGTRAQ" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0178" published="2005-03-07" name="CVE-2005-0178" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A" source="CONFIRM" patch="1" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10647" source="OVAL">oval:org.mitre.oval:def:10647</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" source="BUGTRAQ" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netkit" name="linux_netkit">
        <vers num="0.17"/>
        <vers num="0.17.17"/>
      </prod>
      <prod vendor="vserver" name="linux-vserver">
        <vers num="1.20"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.23"/>
        <vers num="1.24"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.2"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.3"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.9.9"/>
        <vers num="2.1"/>
        <vers num="2.1.89"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.15_pre20"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21"/>
        <vers num="2.2.22"/>
        <vers num="2.2.23"/>
        <vers num="2.2.24"/>
        <vers num="2.2.25"/>
        <vers num="2.2.27" edition="rc2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.99" edition="pre1"/>
        <vers num="2.3.99" edition="pre2"/>
        <vers num="2.3.99" edition="pre3"/>
        <vers num="2.3.99" edition="pre4"/>
        <vers num="2.3.99" edition="pre5"/>
        <vers num="2.3.99" edition="pre6"/>
        <vers num="2.3.99" edition="pre7"/>
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.30" edition="rc2"/>
        <vers num="2.4.30" edition="rc3"/>
        <vers num="2.4.31" edition="pre1"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.2"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.3"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.4"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.5"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.6"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.2"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0179" published="2005-03-07" name="CVE-2005-0179" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9890" source="OVAL">oval:org.mitre.oval:def:9890</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" source="FULLDISC" adv="1">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.30" edition="rc2"/>
        <vers num="2.4.30" edition="rc3"/>
        <vers num="2.4.31" edition="pre1"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="2.6.20"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0180" published="2005-03-07" name="CVE-2005-0180" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10667" source="OVAL">oval:org.mitre.oval:def:10667</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" source="FULLDISC" adv="1">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
      <ref url="http://www.securityfocus.com/bid/12198" source="BID">12198</ref>
      <ref url="http://www.securityfocus.com/archive/1/386374" source="BUGTRAQ">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" source="MANDRAKE">MDKSA-2005:218</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="2.6.20"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0182" published="2005-01-06" name="CVE-2005-0182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18765" source="XF" adv="1">moddosevasive-symlink(18765)</ref>
      <ref url="http://www.securityfocus.com/bid/12181" source="BID" adv="1">12181</ref>
      <ref url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01" source="MISC" adv="1">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547469530582&amp;w=2" source="BUGTRAQ" adv="1">20050111 Mod_dosevasive symlink and race vulnerability</ref>
      <ref url="http://secunia.com/advisories/13725" source="SECUNIA">13725</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_dosevasive" name="mod_dosevasive">
        <vers num="1.8"/>
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0183" published="2005-05-02" name="CVE-2005-0183" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18855" source="XF" adv="1">vacation-ftpfile-command-execution(18855)</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03" source="MISC">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2" source="BUGTRAQ" adv="1">20050111 Squirrelmail vacation v0.15 local root exploit</ref>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=51" source="CONFIRM">http://www.squirrelmail.org/plugin_view.php?id=51</ref>
      <ref url="http://www.securityfocus.com/bid/12222" source="BID">12222</ref>
      <ref url="http://securitytracker.com/id?1012866" source="SECTRACK">1012866</ref>
      <ref url="http://secunia.com/advisories/13791" source="SECUNIA">13791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="vacation_plugin">
        <vers prev="1" num="0.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0184" published="2005-05-02" name="CVE-2005-0184" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18856" source="XF" adv="1">vacation-ftpfile-directory-traversal(18856)</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03" source="MISC" adv="1">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2" source="BUGTRAQ" adv="1">20050111 Squirrelmail vacation v0.15 local root exploit</ref>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=51" source="CONFIRM">http://www.squirrelmail.org/plugin_view.php?id=51</ref>
      <ref url="http://www.securityfocus.com/bid/12222" source="BID">12222</ref>
      <ref url="http://securitytracker.com/id?1012866" source="SECTRACK">1012866</ref>
      <ref url="http://secunia.com/advisories/13791" source="SECUNIA">13791</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0185" published="2005-05-02" name="CVE-2005-0185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18937" source="XF" adv="1">nodemanager-linkdown-bo(18937)</ref>
      <ref url="http://www.security.org.sg/vuln/nodemanager200.html" source="MISC" adv="1">http://www.security.org.sg/vuln/nodemanager200.html</ref>
      <ref url="http://secunia.com/advisories/13881/" source="SECUNIA" adv="1">13881</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599796118583&amp;w=2" source="BUGTRAQ" adv="1">20050117 [SIG^2 G-TEC] NodeManager Professional V2.00 Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12283" source="BID">12283</ref>
      <ref url="http://securitytracker.com/id?1012915" source="SECTRACK">1012915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnet_soft_factory" name="nodemanager_professional">
        <vers num="2.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0186" published="2005-01-19" name="CVE-2005-0186" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18956" source="XF" patch="1" adv="1">cisco-ios-sccp-dos(18956)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml" source="CISCO" adv="1">20050119 Vulnerability in Cisco IOS Embedded Call Processing Solutions</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4849" source="OVAL">oval:org.mitre.oval:def:4849</ref>
      <ref url="http://securitytracker.com/id?1012945" source="SECTRACK">1012945</ref>
      <ref url="http://secunia.com/advisories/13913" source="SECUNIA">13913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1yd"/>
        <vers num="12.2t"/>
        <vers num="12.3"/>
        <vers num="12.3t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0187" published="2005-05-02" name="CVE-2005-0187" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17627" source="XF">athoc-toolbar-bo(17627)</ref>
      <ref url="http://www.securityfocus.com/bid/11341" source="BID">11341</ref>
      <ref url="http://www.ngssoftware.com/advisories/athoc-01full.txt" source="MISC" adv="1">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2" source="BUGTRAQ" adv="1">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2" source="BUGTRAQ" adv="1">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="athoc" name="athoc_toolbar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0188" published="2004-10-06" name="CVE-2005-0188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17628" source="XF">athoc-toolbar-format-string(17628)</ref>
      <ref url="http://www.securityfocus.com/bid/11341" source="BID">11341</ref>
      <ref url="http://www.ngssoftware.com/advisories/athoc-01full.txt" source="MISC">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2" source="BUGTRAQ" adv="1">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2" source="BUGTRAQ" adv="1">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="athoc" name="athoc_toolbar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0189" published="2004-10-06" name="CVE-2005-0189" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/698390" source="CERT-VN" patch="1" adv="1">VU#698390</ref>
      <ref url="http://www.securityfocus.com/bid/12311" source="BID" patch="1" adv="1">12311</ref>
      <ref url="http://service.real.com/help/faq/security/040928_player/EN/" source="MISC" patch="1" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2005-q1/0046.html" source="NTBUGTRAQ" patch="1" adv="1">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" source="BUGTRAQ">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":german"/>
        <vers num="10.0" edition=":"/>
        <vers num="10.0" edition="::english"/>
        <vers num="10.0" edition="::japanese"/>
        <vers num="10.0_6.0.12.690"/>
        <vers num="10.0_beta"/>
        <vers num="10.5"/>
        <vers num="10.5_6.0.12.1016_beta"/>
        <vers num="10.5_6.0.12.1040"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0190" published="2004-09-29" name="CVE-2005-0190" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17551" source="XF" patch="1" adv="1">realplayer-media-file-deletion(17551)</ref>
      <ref url="http://www.securityfocus.com/bid/11308" source="BID" patch="1" adv="1">11308</ref>
      <ref url="http://www.ngssoftware.com/advisories/real-02full.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/real-02full.txt</ref>
      <ref url="http://service.real.com/help/faq/security/040928_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://secunia.com/advisories/12672/" source="SECUNIA" patch="1" adv="1">12672</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2" source="BUGTRAQ" adv="1">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" source="BUGTRAQ" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":german"/>
        <vers num="10.0" edition=":"/>
        <vers num="10.0" edition="::english"/>
        <vers num="10.0" edition="::japanese"/>
        <vers num="10.0_6.0.12.690"/>
        <vers num="10.0_beta"/>
        <vers num="10.5"/>
        <vers num="10.5_6.0.12.1016_beta"/>
        <vers num="10.5_6.0.12.1040"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0191" published="2005-01-19" name="CVE-2005-0191" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18982" source="XF" patch="1" adv="1">realplayer-long-filename-offbyone-bo(18982)</ref>
      <ref url="http://www.ngssoftware.com/advisories/real-03full.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/real-03full.txt</ref>
      <ref url="http://service.real.com/help/faq/security/040928_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":german"/>
        <vers num="10.0" edition=":"/>
        <vers num="10.0" edition="::english"/>
        <vers num="10.0" edition="::japanese"/>
        <vers num="10.0_6.0.12.690"/>
        <vers num="10.0_beta"/>
        <vers num="10.5"/>
        <vers num="10.5_6.0.12.1016_beta"/>
        <vers num="10.5_6.0.12.1040"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0192" published="2004-10-06" name="CVE-2005-0192" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18984" source="XF" patch="1" adv="1">realplayer-rjs-filenane-directory-traversal(18984)</ref>
      <ref url="http://www.ngssoftware.com/advisories/real-03full.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/real-03full.txt</ref>
      <ref url="http://service.real.com/help/faq/security/040928_player/EN/" source="MISC" patch="1" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":german"/>
        <vers num="10.0" edition=":"/>
        <vers num="10.0" edition="::english"/>
        <vers num="10.0" edition="::japanese"/>
        <vers num="10.0_6.0.12.690"/>
        <vers num="10.0_beta"/>
        <vers num="10.5"/>
        <vers num="10.5_6.0.12.1016_beta"/>
        <vers num="10.5_6.0.12.1040"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0193" published="2005-01-22" name="CVE-2005-0193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19011" source="XF" adv="1">isync-mrouter-bo(19011)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642400018425&amp;w=2" source="BUGTRAQ" adv="1">20050122 Mac OS X 10.3 iSync Privilege Escalation</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00001.html" source="APPLE" adv="1">APPLE-SA-2005-04-19</ref>
      <ref url="http://www.securityfocus.com/bid/12334" source="BID">12334</ref>
      <ref url="http://securitytracker.com/id?1012974" source="SECTRACK">1012974</ref>
      <ref url="http://secunia.com/advisories/13965" source="SECUNIA">13965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isync" name="mrouter">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0194" published="2005-05-02" name="CVE-2005-0194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/260421" source="CERT-VN" patch="1" adv="1">VU#260421</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls</ref>
      <ref url="http://www.debian.org/security/2005/dsa-667" source="DEBIAN" patch="1" adv="1">DSA-667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901183320453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050221 [USN-84-1] Squid vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" source="CONECTIVA" patch="1">CLA-2005:923</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1166" source="CONFIRM" adv="1">http://www.squid-cache.org/bugs/show_bug.cgi?id=1166</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0.patch1"/>
        <vers num="2.0.patch2"/>
        <vers num="2.0.pre1"/>
        <vers num="2.0.release"/>
        <vers num="2.1.patch1"/>
        <vers num="2.1.patch2"/>
        <vers num="2.1.pre1"/>
        <vers num="2.1.pre3"/>
        <vers num="2.1.pre4"/>
        <vers num="2.1.release"/>
        <vers num="2.2.devel3"/>
        <vers num="2.2.devel4"/>
        <vers num="2.2.pre1"/>
        <vers num="2.2.pre2"/>
        <vers num="2.2.stable1"/>
        <vers num="2.2.stable2"/>
        <vers num="2.2.stable3"/>
        <vers num="2.2.stable4"/>
        <vers num="2.2.stable5"/>
        <vers num="2.3.devel2"/>
        <vers num="2.3.devel3"/>
        <vers num="2.3.stable1"/>
        <vers num="2.3.stable2"/>
        <vers num="2.3.stable3"/>
        <vers num="2.3.stable4"/>
        <vers num="2.3.stable5"/>
        <vers num="2.4.stable1"/>
        <vers num="2.4.stable2"/>
        <vers num="2.4.stable3"/>
        <vers num="2.4.stable4"/>
        <vers num="2.4.stable6"/>
        <vers num="2.4.stable7"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0195" published="2005-05-02" name="CVE-2005-0195" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" source="CERT" patch="1" adv="1">TA05-026A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/472582" source="CERT-VN" patch="1" adv="1">VU#472582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19072" source="XF" patch="1" adv="1">cisco-ios-ipv6-dos(19072)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-ipv6.shtml" source="CISCO" patch="1" adv="1">20050126 Multiple Crafted IPv6 Packets Cause Reload</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5813" source="OVAL">oval:org.mitre.oval:def:5813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0s"/>
        <vers num="12.0sx"/>
        <vers num="12.0sz"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bx"/>
        <vers num="12.2bz"/>
        <vers num="12.2cx"/>
        <vers num="12.2cz"/>
        <vers num="12.2ew"/>
        <vers num="12.2ewa"/>
        <vers num="12.2jk"/>
        <vers num="12.2mc"/>
        <vers num="12.2s"/>
        <vers num="12.2se"/>
        <vers num="12.2su"/>
        <vers num="12.2sv"/>
        <vers num="12.2sw"/>
        <vers num="12.2sx"/>
        <vers num="12.2sxa"/>
        <vers num="12.2sxb"/>
        <vers num="12.2sxd"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yz"/>
        <vers num="12.2zc"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zi"/>
        <vers num="12.2zj"/>
        <vers num="12.2zl"/>
        <vers num="12.2zn"/>
        <vers num="12.2zo"/>
        <vers num="12.2zp"/>
        <vers num="12.3"/>
        <vers num="12.3b"/>
        <vers num="12.3bc"/>
        <vers num="12.3bw"/>
        <vers num="12.3j"/>
        <vers num="12.3ja"/>
        <vers num="12.3t"/>
        <vers num="12.3xa"/>
        <vers num="12.3xb"/>
        <vers num="12.3xc"/>
        <vers num="12.3xd"/>
        <vers num="12.3xe"/>
        <vers num="12.3xf"/>
        <vers num="12.3xg"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xk"/>
        <vers num="12.3xl"/>
        <vers num="12.3xm"/>
        <vers num="12.3xn"/>
        <vers num="12.3xq"/>
        <vers num="12.3xr"/>
        <vers num="12.3xs"/>
        <vers num="12.3xt"/>
        <vers num="12.3xu"/>
        <vers num="12.3xw"/>
        <vers num="12.3xx"/>
        <vers num="12.3xy"/>
        <vers num="12.3xz"/>
        <vers num="12.3ya"/>
        <vers num="12.3yd"/>
        <vers num="12.3ye"/>
        <vers num="12.3yf"/>
        <vers num="12.3yg"/>
        <vers num="12.3yh"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0196" published="2005-05-02" name="CVE-2005-0196" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" source="CERT" patch="1" adv="1">TA05-026A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/689326" source="CERT-VN" patch="1" adv="1">VU#689326</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19074" source="XF" patch="1" adv="1">cisco-ios-bgp-packetdos(19074)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-bgp.shtml" source="CISCO" patch="1" adv="1">20050126 Cisco IOS Misformed BGP Packet Causes Reload</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5652" source="OVAL">oval:org.mitre.oval:def:5652</ref>
      <ref url="http://securitytracker.com/id?1013013" source="SECTRACK">1013013</ref>
      <ref url="http://secunia.com/advisories/14034" source="SECUNIA">14034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0sy"/>
        <vers num="12.0sz"/>
        <vers num="12.0w5"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0wx"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xn"/>
        <vers num="12.0xp"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xt"/>
        <vers num="12.0xu"/>
        <vers num="12.0xv"/>
        <vers num="12.1"/>
        <vers num="12.1aa"/>
        <vers num="12.1ax"/>
        <vers num="12.1ay"/>
        <vers num="12.1az"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1e"/>
        <vers num="12.1ea"/>
        <vers num="12.1ec"/>
        <vers num="12.1eo"/>
        <vers num="12.1ev"/>
        <vers num="12.1ew"/>
        <vers num="12.1ex"/>
        <vers num="12.1ey"/>
        <vers num="12.1t"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xl"/>
        <vers num="12.1xm"/>
        <vers num="12.1xp"/>
        <vers num="12.1xq"/>
        <vers num="12.1xr"/>
        <vers num="12.1xt"/>
        <vers num="12.1xu"/>
        <vers num="12.1xv"/>
        <vers num="12.1ya"/>
        <vers num="12.1yb"/>
        <vers num="12.1yf"/>
        <vers num="12.1yh"/>
        <vers num="12.1yi"/>
        <vers num="12.1yj"/>
        <vers num="12.2"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2bx"/>
        <vers num="12.2by"/>
        <vers num="12.2bz"/>
        <vers num="12.2cz"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2ew"/>
        <vers num="12.2jk"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2mx"/>
        <vers num="12.2s"/>
        <vers num="12.2se"/>
        <vers num="12.2su"/>
        <vers num="12.2sw"/>
        <vers num="12.2sx"/>
        <vers num="12.2sxa"/>
        <vers num="12.2sxb"/>
        <vers num="12.2sxd"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2x"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xw"/>
        <vers num="12.2xz"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2ye"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zc"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zi"/>
        <vers num="12.2zj"/>
        <vers num="12.2zk"/>
        <vers num="12.2zl"/>
        <vers num="12.2zm"/>
        <vers num="12.2zn"/>
        <vers num="12.2zo"/>
        <vers num="12.2zp"/>
        <vers num="12.3"/>
        <vers num="12.3b"/>
        <vers num="12.3bw"/>
        <vers num="12.3t"/>
        <vers num="12.3xa"/>
        <vers num="12.3xb"/>
        <vers num="12.3xc"/>
        <vers num="12.3xd"/>
        <vers num="12.3xe"/>
        <vers num="12.3xf"/>
        <vers num="12.3xg"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xj"/>
        <vers num="12.3xk"/>
        <vers num="12.3xl"/>
        <vers num="12.3xn"/>
        <vers num="12.3xq"/>
        <vers num="12.3xr"/>
        <vers num="12.3xs"/>
        <vers num="12.3xu"/>
        <vers num="12.3xv"/>
        <vers num="12.3xx"/>
        <vers num="12.3ya"/>
        <vers num="12.3yc"/>
        <vers num="12.3yd"/>
        <vers num="12.3ye"/>
        <vers num="12.3yf"/>
        <vers num="12.3yh"/>
        <vers num="12.3yj"/>
        <vers num="12.3yl"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0197" published="2005-05-02" name="CVE-2005-0197" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_base_score="6.1">
    <desc>
      <descript source="cve">Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" source="CERT" patch="1" adv="1">TA05-026A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/583638" source="CERT-VN" patch="1" adv="1">VU#583638</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19071" source="XF" patch="1" adv="1">cisco-ios-mpls-dos(19071)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-les.shtml" source="CISCO" patch="1" adv="1">20050126 Crafted Packet Causes Reload on Cisco Routers</ref>
      <ref url="http://www.securityfocus.com/bid/12369" source="BID">12369</ref>
      <ref url="http://securitytracker.com/id?1013015" source="SECTRACK">1013015</ref>
      <ref url="http://secunia.com/advisories/14031" source="SECUNIA">14031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5662" source="OVAL">oval:org.mitre.oval:def:5662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1t"/>
        <vers num="12.2"/>
        <vers num="12.2t"/>
        <vers num="12.3"/>
        <vers num="12.3t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0198" published="2005-05-02" name="CVE-2005-0198" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-68QSL5" source="CONFIRM" patch="1">http://www.kb.cert.org/vuls/id/CRDY-68QSL5</ref>
      <ref url="http://www.kb.cert.org/vuls/id/702777" source="CERT-VN" adv="1">VU#702777</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-128.html" source="REDHAT" patch="1" adv="1">RHSA-2005:128</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-02.xml" source="GENTOO" patch="1">GLSA-200502-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11306" source="OVAL">oval:org.mitre.oval:def:11306</ref>
      <ref url="http://www.securityfocus.com/bid/12391" source="BID">12391</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:026" source="MANDRAKE">MDKSA-2005:026</ref>
      <ref url="http://securitytracker.com/id?1013037" source="SECTRACK">1013037</ref>
      <ref url="http://secunia.com/advisories/14097" source="SECUNIA">14097</ref>
      <ref url="http://secunia.com/advisories/14057" source="SECUNIA">14057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="uw-imap">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0199" published="2005-05-02" name="CVE-2005-0199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19143" source="XF" patch="1" adv="1">ngircd-listmakemask-bo(19143)</ref>
      <ref url="http://www.securityfocus.com/bid/12397" source="BID" patch="1">12397</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-40.xml" source="GENTOO" patch="1">GLSA-200501-40</ref>
      <ref url="http://arthur.ath.cx/pipermail/ngircd-ml/2005-January/000228.html" source="MLIST" patch="1">[ngIRCd-ML] 20050126 ngIRCd 0.8.2</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=79705" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=79705</ref>
      <ref url="http://securitytracker.com/id?1013047" source="SECTRACK">1013047</ref>
      <ref url="http://secunia.com/advisories/14059" source="SECUNIA">14059</ref>
      <ref url="http://secunia.com/advisories/14056" source="SECUNIA">14056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ngircd" name="ngircd">
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.5"/>
        <vers num="0.7.6"/>
        <vers num="0.7.7"/>
        <vers num="0.8"/>
        <vers num="0.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0200" published="2005-05-02" name="CVE-2005-0200" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-41.xml" source="GENTOO" patch="1">GLSA-200501-41</ref>
      <ref url="http://tikiwiki.org/art102" source="CONFIRM" patch="1">http://tikiwiki.org/art102</ref>
      <ref url="http://secunia.com/advisories/13948" source="SECUNIA">13948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tiki" name="tikiwiki_cms/groupware">
        <vers prev="1" num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0201" published="2005-06-29" name="CVE-2005-0201" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-102.html" source="REDHAT" patch="1" adv="1">RHSA-2005:102</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:105" source="MANDRAKE" patch="1" adv="1">MDKSA-2005:105</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-144-1" source="UBUNTU">USN-144-1</ref>
      <ref url="http://www.auscert.org.au/render.html?it=5156" source="AUSCERT" adv="1">ESB-2005.0435</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10973" source="OVAL">oval:org.mitre.oval:def:10973</ref>
      <ref url="http://www.securityfocus.com/bid/12435" source="BID">12435</ref>
      <ref url="http://securitytracker.com/id?1013075" source="SECTRACK">1013075</ref>
      <ref url="http://secunia.com/advisories/15844" source="SECUNIA">15844</ref>
      <ref url="http://secunia.com/advisories/15833" source="SECUNIA">15833</ref>
      <ref url="http://secunia.com/advisories/15638" source="SECUNIA">15638</ref>
      <ref url="http://secunia.com/advisories/14119" source="SECUNIA">14119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-bus" name="d-bus">
        <vers prev="1" num="0.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0202" published="2005-05-02" name="CVE-2005-0202" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-137.html" source="REDHAT" patch="1" adv="1">RHSA-2005:137</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-136.html" source="REDHAT" patch="1" adv="1">RHSA-2005:136</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-11.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-11</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805795122386&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050209 [USN-78-1] Mailman vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://www.debian.org/security/2005/dsa-674" source="DEBIAN">DSA-674</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10657" source="OVAL">oval:org.mitre.oval:def:10657</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031562.html" source="FULLDISC" adv="1">20050209 Administrivia: List Compromised due to Mailman Vulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_07_mailman.html" source="SUSE">SUSE-SA:2005:007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:037" source="MANDRAKE">MDKSA-2005:037</ref>
      <ref url="http://securitytracker.com/id?1013145" source="SECTRACK">1013145</ref>
      <ref url="http://secunia.com/advisories/14211" source="SECUNIA">14211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0203" reject="1" published="2005-06-09" name="CVE-2005-0203" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0204" published="2005-05-02" name="CVE-2005-0204" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT" patch="1" adv="1">RHSA-2005:092</ref>
      <ref url="http://www.trustix.org/errata/2006/0006" source="TRUSTIX">2006-0006</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://secunia.com/advisories/18784" source="SECUNIA" adv="1">18784</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10320" source="OVAL">oval:org.mitre.oval:def:10320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0205" published="2005-05-02" name="CVE-2005-0205" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-175.html" source="REDHAT" patch="1" adv="1">RHSA-2005:175</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050228-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050228-1.txt</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=208&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050228 KPPP Privileged File Descriptor Leak Vulnerability</ref>
      <ref url="http://www.debian.org/security/2005/dsa-692" source="DEBIAN" patch="1" adv="1">DSA-692</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000934" source="CONECTIVA" patch="1">CLA-2005:934</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9596" source="OVAL">oval:org.mitre.oval:def:9596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bernd_wuebben" name="kppp">
        <vers num="2.1.2"/>
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0206" published="2005-04-27" name="CVE-2005-0206" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11501" source="BID" patch="1" adv="1">11501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-213.html" source="REDHAT" patch="1" adv="1">RHSA-2005:213</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17818" source="XF">xpdf-pdf-bo(17818)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-132.html" source="REDHAT">RHSA-2005:132</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-057.html" source="REDHAT">RHSA-2005:057</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-034.html" source="REDHAT">RHSA-2005:034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11107" source="OVAL">oval:org.mitre.oval:def:11107</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:056" source="MANDRAKE">MDKSA-2005:056</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052" source="MANDRAKE">MDKSA-2005:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:044" source="MANDRAKE">MDKSA-2005:044</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:043" source="MANDRAKE">MDKSA-2005:043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:042" source="MANDRAKE">MDKSA-2005:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:041" source="MANDRAKE">MDKSA-2005:041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ascii" name="ptex">
        <vers num="3.1.4"/>
      </prod>
      <prod vendor="cstex" name="cstetex">
        <vers num="2.0.2"/>
      </prod>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4"/>
        <vers num="1.0.4_8"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.19_rc5"/>
        <vers num="1.1.20"/>
        <vers num="1.1.4"/>
        <vers num="1.1.4_2"/>
        <vers num="1.1.4_3"/>
        <vers num="1.1.4_5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
      </prod>
      <prod vendor="gnome" name="gpdf">
        <vers num="0.110"/>
        <vers num="0.112"/>
        <vers num="0.131"/>
      </prod>
      <prod vendor="kde" name="koffice">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3_beta1"/>
        <vers num="1.3_beta2"/>
        <vers num="1.3_beta3"/>
      </prod>
      <prod vendor="kde" name="kpdf">
        <vers num="3.2"/>
      </prod>
      <prod vendor="pdftohtml" name="pdftohtml">
        <vers num="0.32a"/>
        <vers num="0.32b"/>
        <vers num="0.33"/>
        <vers num="0.33a"/>
        <vers num="0.34"/>
        <vers num="0.35"/>
        <vers num="0.36"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0"/>
      </prod>
      <prod vendor="tetex" name="tetex">
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.90"/>
        <vers num="0.91"/>
        <vers num="0.92"/>
        <vers num="0.93"/>
        <vers num="1.0"/>
        <vers num="1.0a"/>
        <vers num="1.1"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.3"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":ppc"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":sparc"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num=""/>
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":x86_64"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation_ia64"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation"/>
        <vers num="3.0" edition=":advanced_servers"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0"/>
        <vers num="core_2.0"/>
        <vers num="core_3.0"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":itanium_processor"/>
        <vers num="2.1" edition=":ia64"/>
      </prod>
      <prod vendor="sgi" name="advanced_linux_environment">
        <vers num="3.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1" edition="alpha"/>
        <vers num="6.2"/>
        <vers num="6.3" edition=""/>
        <vers num="6.3" edition=":ppc"/>
        <vers num="6.3" edition="alpha"/>
        <vers num="6.4" edition=""/>
        <vers num="6.4" edition=":i386"/>
        <vers num="6.4" edition=":ppc"/>
        <vers num="6.4" edition="alpha"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":sparc"/>
        <vers num="7.0" edition=":i386"/>
        <vers num="7.0" edition=":ppc"/>
        <vers num="7.0" edition="alpha"/>
        <vers num="7.1" edition=""/>
        <vers num="7.1" edition=":sparc"/>
        <vers num="7.1" edition=":spa"/>
        <vers num="7.1" edition=":x86"/>
        <vers num="7.1" edition="alpha"/>
        <vers num="7.2" edition=""/>
        <vers num="7.2" edition=":i386"/>
        <vers num="7.3" edition=""/>
        <vers num="7.3" edition=":ppc"/>
        <vers num="7.3" edition=":i386"/>
        <vers num="7.3" edition=":sparc"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":x86_64"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":x86_64"/>
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition=""/>
        <vers num="4.1" edition=":ppc"/>
        <vers num="4.1" edition=":ia64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0207" published="2005-05-02" name="CVE-2005-0207" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12330" source="BID" patch="1">12330</ref>
      <ref url="http://www.securityfocus.com/advisories/7880" source="SUSE" patch="1" adv="1">SUSE-SA:2005:003</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000930" source="CONECTIVA" patch="1">CLA-2005:930</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11001" source="OVAL">oval:org.mitre.oval:def:11001</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.2"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.3"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.4"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.5"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.6"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.9" edition="2.6.20"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":advanced_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":desktop"/>
        <vers num="8" edition=""/>
        <vers num="8" edition=":enterprise_server"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":enterprise_server"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0208" published="2005-05-02" name="CVE-2005-0208" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0473.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/795812" source="CERT-VN" patch="1" adv="1">VU#795812</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-215.html" source="REDHAT" patch="1" adv="1">RHSA-2005:215</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-03</ref>
      <ref url="http://secunia.com/advisories/14386" source="SECUNIA" patch="1" adv="1">14386</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050225 [USN-85-1] Gaim vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933" source="CONECTIVA" patch="1">CLA-2005:933</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10477" source="OVAL">oval:org.mitre.oval:def:10477</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=12" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/?id=12</ref>
      <ref url="http://www.securityfocus.com/bid/12660" source="BID">12660</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049" source="MANDRAKE">MDKSA-2005:049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0209" published="2005-05-02" name="CVE-2005-0209" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945" source="CONECTIVA" patch="1">CLA-2005:945</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-420.html" source="REDHAT">RHSA-2005:420</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11855" source="OVAL">oval:org.mitre.oval:def:11855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0210" published="2005-05-02" name="CVE-2005-0210" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945" source="CONECTIVA" patch="1">CLA-2005:945</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.securityfocus.com/bid/12816" source="BID">12816</ref>
      <ref url="http://www.osvdb.org/14966" source="OSVDB">14966</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" source="MANDRAKE">MDKSA-2005:218</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://secunia.com/advisories/14295" source="SECUNIA">14295</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10275" source="OVAL">oval:org.mitre.oval:def:10275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0211" published="2005-05-02" name="CVE-2005-0211" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/886006" source="CERT-VN" patch="1" adv="1">VU#886006</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://www.debian.org/security/2005/dsa-667" source="DEBIAN" patch="1" adv="1">DSA-667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9573" source="OVAL">oval:org.mitre.oval:def:9573</ref>
      <ref url="http://www.securityfocus.com/bid/12432" source="BID">12432</ref>
      <ref url="http://www.osvdb.org/13319" source="OSVDB">13319</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" source="MANDRAKE">MDKSA-2005:034</ref>
      <ref url="http://securitytracker.com/id?1013045" source="SECTRACK">1013045</ref>
      <ref url="http://secunia.com/advisories/14076" source="SECUNIA">14076</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0212" published="2005-05-02" name="CVE-2005-0212" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Amp II engine as used by Gore: Ultimate Soldier 1.50 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero byte UDP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18789" source="XF">amp-3d-socket-dos(18789)</ref>
      <ref url="http://www.securityfocus.com/bid/12192" source="BID">12192</ref>
      <ref url="http://aluigi.altervista.org/adv/amp2zero-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/amp2zero-adv.txt</ref>
      <ref url="http://secunia.com/advisories/13754" source="SECUNIA">13754</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110503597505648&amp;w=2" source="BUGTRAQ">20050106 Socket unreacheable in Amp II engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amp" name="amp_ii_3d_game_engine">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0213" published="2005-05-02" name="CVE-2005-0213" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18798" source="XF">winhki-zip-directory-traversal(18798)</ref>
      <ref url="http://www.securityfocus.com/bid/12176" source="BID">12176</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110505334903257&amp;w=2" source="BUGTRAQ" adv="1">20050106 WinAc AND WinHKI ZIP File Directory Transversal </ref>
      <ref url="http://securitytracker.com/id?1012798" source="SECTRACK">1012798</ref>
      <ref url="http://secunia.com/advisories/13738" source="SECUNIA">13738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webtoolmaster_software" name="winhki">
        <vers num="1.4d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0214" published="2005-05-02" name="CVE-2005-0214" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12193" source="BID" patch="1">12193</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18802" source="XF">sphp-dotdot-directory-traversal(18802)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512850603989&amp;w=2" source="BUGTRAQ" adv="1">20050107 Simple PHP Blog directory traversal vulnerability </ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-01/0210.html" source="FULLDISC" adv="1">20050107 Simple PHP Blog directory traversal vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_palmo" name="simple_php_blog">
        <vers num="0.3.7c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0215" published="2005-05-02" name="CVE-2005-0215" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a large (1) height or (2) width value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512665029209&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050107 Mozilla XBM Image Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18803" source="XF">mozilla-xbm-dos(18803)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0216" published="2005-05-02" name="CVE-2005-0216" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web sript and HTML via the userid parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18814" source="XF">wbb-formmail-userid-xss(18814)</ref>
      <ref url="http://www.securityfocus.com/bid/12199" source="BID">12199</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110537385427004&amp;w=2" source="BUGTRAQ" adv="1">20050108 Security Advisory: Woltlab Burning Board Lite formmail.php XSS </ref>
      <ref url="http://secunia.com/advisories/13782" source="SECUNIA">13782</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0217" published="2005-05-02" name="CVE-2005-0217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18815" source="XF">icb-sql-injection(18815)</ref>
      <ref url="http://www.securityfocus.com/bid/12205" source="BID">12205</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110538277223800&amp;w=2" source="BUGTRAQ" adv="1">20050109 SQL Injection Vulnerability in Invision Community Blog</ref>
      <ref url="http://www.osvdb.org/12817" source="OSVDB">12817</ref>
      <ref url="http://securitytracker.com/id?1012831" source="SECTRACK">1012831</ref>
      <ref url="http://secunia.com/advisories/13783" source="SECUNIA">13783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_community_blog">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0218" published="2005-05-02" name="CVE-2005-0218" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml" source="GENTOO" patch="1">GLSA-200501-46</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=300116" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=300116</ref>
      <ref url="http://secunia.com/advisories/13900/" source="SECUNIA" adv="1">13900</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025" source="MANDRAKE">MDKSA-2005:025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.51"/>
        <vers num="0.52"/>
        <vers num="0.53"/>
        <vers num="0.54"/>
        <vers num="0.60"/>
        <vers num="0.65"/>
        <vers num="0.67"/>
        <vers num="0.68"/>
        <vers num="0.68.1"/>
        <vers num="0.80"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0219" published="2005-05-02" name="CVE-2005-0219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8) username field in search.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" source="CONFIRM" patch="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18938" source="XF">gallery-multiple-xss(18938)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" source="BUGTRAQ" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html" source="VULNWATCH">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43473" source="XF">gallery-multiple-scripts-xss(43473)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.3.4_pl1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0220" published="2005-05-02" name="CVE-2005-0220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13887/" source="SECUNIA" patch="1">13887</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" source="CONFIRM" patch="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18938" source="XF">gallery-multiple-xss(18938)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-45.xml" source="GENTOO">GLSA-200501-45</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" source="BUGTRAQ" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.4.4_pl2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0221" published="2005-01-17" name="CVE-2005-0221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18938" source="XF" patch="1" adv="1">gallery-multiple-xss(18938)</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" source="CONFIRM" patch="1" adv="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
      <ref url="http://theinsider.deep-ice.com/texts/advisory69.txt" source="MISC" adv="1">http://theinsider.deep-ice.com/texts/advisory69.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" source="BUGTRAQ" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html" source="VULNWATCH" adv="1">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43472" source="XF">gallery-g2formsubject-xss(43472)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="2.0_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0222" published="2005-05-02" name="CVE-2005-0222" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18940" source="XF">gallery-mainphp-obtain-information(18940)</ref>
      <ref url="http://theinsider.deep-ice.com/texts/advisory69.txt" source="MISC" adv="1">http://theinsider.deep-ice.com/texts/advisory69.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" source="BUGTRAQ" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" source="CONFIRM">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html" source="VULNWATCH">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="2.0_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0223" published="2005-05-02" name="CVE-2005-0223" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserialization.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110719624029320&amp;w=2" source="HP" patch="1" adv="1">SSRT4875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="rte">
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0224" published="2005-01-31" name="CVE-2005-0224" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14082/" source="SECUNIA" patch="1" adv="1">14082</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726808700080&amp;w=2" source="HP" adv="1">SSRT5900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="virtualvault">
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0225" published="2005-05-02" name="CVE-2005-0225" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">firehol.sh in FireHOL before 1.224 creates temporary files with predictable file names, which could allow local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-01.xml" source="GENTOO">GLSA-200502-01</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/firehol/firehol/firehol.sh" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/firehol/firehol/firehol.sh</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19032" source="XF">firehol-symlink(19032)</ref>
      <ref url="http://www.securityfocus.com/bid/12336" source="BID">12336</ref>
      <ref url="http://www.osvdb.org/13137" source="OSVDB">13137</ref>
      <ref url="http://securitytracker.com/id?1012969" source="SECTRACK">1012969</ref>
      <ref url="http://secunia.com/advisories/14102" source="SECUNIA">14102</ref>
      <ref url="http://secunia.com/advisories/13970" source="SECUNIA">13970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firehol" name="firehol">
        <vers num="1.1"/>
        <vers num="1.1.1.1"/>
        <vers num="1.10"/>
        <vers num="1.100"/>
        <vers num="1.101"/>
        <vers num="1.102"/>
        <vers num="1.103"/>
        <vers num="1.104"/>
        <vers num="1.105"/>
        <vers num="1.106"/>
        <vers num="1.107"/>
        <vers num="1.108"/>
        <vers num="1.109"/>
        <vers num="1.11"/>
        <vers num="1.110"/>
        <vers num="1.111"/>
        <vers num="1.112"/>
        <vers num="1.113"/>
        <vers num="1.114"/>
        <vers num="1.115"/>
        <vers num="1.116"/>
        <vers num="1.117"/>
        <vers num="1.118"/>
        <vers num="1.119"/>
        <vers num="1.12"/>
        <vers num="1.120"/>
        <vers num="1.121"/>
        <vers num="1.122"/>
        <vers num="1.123"/>
        <vers num="1.124"/>
        <vers num="1.125"/>
        <vers num="1.126"/>
        <vers num="1.127"/>
        <vers num="1.128"/>
        <vers num="1.129"/>
        <vers num="1.13"/>
        <vers num="1.130"/>
        <vers num="1.131"/>
        <vers num="1.132"/>
        <vers num="1.133"/>
        <vers num="1.134"/>
        <vers num="1.135"/>
        <vers num="1.136"/>
        <vers num="1.137"/>
        <vers num="1.138"/>
        <vers num="1.139"/>
        <vers num="1.14"/>
        <vers num="1.140"/>
        <vers num="1.141"/>
        <vers num="1.142"/>
        <vers num="1.143"/>
        <vers num="1.144"/>
        <vers num="1.145"/>
        <vers num="1.146"/>
        <vers num="1.147"/>
        <vers num="1.148"/>
        <vers num="1.149"/>
        <vers num="1.15"/>
        <vers num="1.150"/>
        <vers num="1.151"/>
        <vers num="1.152"/>
        <vers num="1.153"/>
        <vers num="1.154"/>
        <vers num="1.155"/>
        <vers num="1.156"/>
        <vers num="1.157"/>
        <vers num="1.158"/>
        <vers num="1.159"/>
        <vers num="1.16"/>
        <vers num="1.160"/>
        <vers num="1.161"/>
        <vers num="1.162"/>
        <vers num="1.163"/>
        <vers num="1.164"/>
        <vers num="1.165"/>
        <vers num="1.166"/>
        <vers num="1.167"/>
        <vers num="1.168"/>
        <vers num="1.169"/>
        <vers num="1.17"/>
        <vers num="1.170"/>
        <vers num="1.171"/>
        <vers num="1.172"/>
        <vers num="1.173"/>
        <vers num="1.174"/>
        <vers num="1.175"/>
        <vers num="1.176"/>
        <vers num="1.177"/>
        <vers num="1.178"/>
        <vers num="1.179"/>
        <vers num="1.18"/>
        <vers num="1.180"/>
        <vers num="1.181"/>
        <vers num="1.182"/>
        <vers num="1.183"/>
        <vers num="1.184"/>
        <vers num="1.185"/>
        <vers num="1.186"/>
        <vers num="1.187"/>
        <vers num="1.188"/>
        <vers num="1.189"/>
        <vers num="1.19"/>
        <vers num="1.190"/>
        <vers num="1.191"/>
        <vers num="1.192"/>
        <vers num="1.193"/>
        <vers num="1.194"/>
        <vers num="1.195"/>
        <vers num="1.196"/>
        <vers num="1.197"/>
        <vers num="1.198"/>
        <vers num="1.199"/>
        <vers num="1.2"/>
        <vers num="1.20"/>
        <vers num="1.200"/>
        <vers num="1.201"/>
        <vers num="1.202"/>
        <vers num="1.203"/>
        <vers num="1.204"/>
        <vers num="1.205"/>
        <vers num="1.206"/>
        <vers num="1.207"/>
        <vers num="1.208"/>
        <vers num="1.209"/>
        <vers num="1.21"/>
        <vers num="1.210"/>
        <vers num="1.211"/>
        <vers num="1.212"/>
        <vers num="1.213"/>
        <vers num="1.214"/>
        <vers num="1.215"/>
        <vers num="1.216"/>
        <vers num="1.217"/>
        <vers num="1.218"/>
        <vers num="1.219"/>
        <vers num="1.22"/>
        <vers num="1.220"/>
        <vers num="1.221"/>
        <vers num="1.222"/>
        <vers num="1.223"/>
        <vers num="1.224"/>
        <vers num="1.23"/>
        <vers num="1.24"/>
        <vers num="1.25"/>
        <vers num="1.26"/>
        <vers num="1.27"/>
        <vers num="1.28"/>
        <vers num="1.29"/>
        <vers num="1.3"/>
        <vers num="1.30"/>
        <vers num="1.31"/>
        <vers num="1.32"/>
        <vers num="1.33"/>
        <vers num="1.34"/>
        <vers num="1.35"/>
        <vers num="1.36"/>
        <vers num="1.37"/>
        <vers num="1.38"/>
        <vers num="1.39"/>
        <vers num="1.4"/>
        <vers num="1.40"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
        <vers num="1.48"/>
        <vers num="1.49"/>
        <vers num="1.5"/>
        <vers num="1.50"/>
        <vers num="1.51"/>
        <vers num="1.52"/>
        <vers num="1.53"/>
        <vers num="1.54"/>
        <vers num="1.55"/>
        <vers num="1.56"/>
        <vers num="1.57"/>
        <vers num="1.58"/>
        <vers num="1.59"/>
        <vers num="1.6"/>
        <vers num="1.60"/>
        <vers num="1.61"/>
        <vers num="1.62"/>
        <vers num="1.63"/>
        <vers num="1.64"/>
        <vers num="1.65"/>
        <vers num="1.66"/>
        <vers num="1.67"/>
        <vers num="1.68"/>
        <vers num="1.69"/>
        <vers num="1.7"/>
        <vers num="1.70"/>
        <vers num="1.71"/>
        <vers num="1.72"/>
        <vers num="1.73"/>
        <vers num="1.74"/>
        <vers num="1.75"/>
        <vers num="1.76"/>
        <vers num="1.77"/>
        <vers num="1.78"/>
        <vers num="1.79"/>
        <vers num="1.8"/>
        <vers num="1.80"/>
        <vers num="1.81"/>
        <vers num="1.82"/>
        <vers num="1.83"/>
        <vers num="1.84"/>
        <vers num="1.85"/>
        <vers num="1.86"/>
        <vers num="1.87"/>
        <vers num="1.88"/>
        <vers num="1.89"/>
        <vers num="1.9"/>
        <vers num="1.90"/>
        <vers num="1.91"/>
        <vers num="1.92"/>
        <vers num="1.93"/>
        <vers num="1.94"/>
        <vers num="1.95"/>
        <vers num="1.96"/>
        <vers num="1.97"/>
        <vers num="1.98"/>
        <vers num="1.99"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0226" published="2005-02-03" name="CVE-2005-0226" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.nosystem.com.ar/advisories/advisory-11.txt" source="MISC" patch="1" adv="1">http://www.nosystem.com.ar/advisories/advisory-11.txt</ref>
      <ref url="http://secunia.com/advisories/14114/" source="SECUNIA" patch="1" adv="1">14114</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746413108183&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050203 ngIRCd &lt;= v0.8.2 Format String Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12434" source="BID">12434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ngircd" name="ngircd">
        <vers num="0.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0227" published="2005-05-02" name="CVE-2005-0227" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX" patch="1" adv="1">2005-0003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-150.html" source="REDHAT" patch="1" adv="1">RHSA-2005:150</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://www.debian.org/security/2005/dsa-668" source="DEBIAN" patch="1" adv="1">DSA-668</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-08.xml" source="GENTOO" patch="1">200502-08</ref>
      <ref url="http://secunia.com/advisories/12948" source="SECUNIA" patch="1" adv="1">12948</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726899107148&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050201 [USN-71-1] PostgreSQL vulnerability</ref>
      <ref url="http://archives.postgresql.org/pgsql-announce/2005-02/msg00000.php" source="MLIST" patch="1">[pgsql-announce] 20050201 PostgreSQL Security Release</ref>
      <ref url="http://www.securityfocus.com/bid/12411" source="BID">12411</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10234" source="OVAL">oval:org.mitre.oval:def:10234</ref>
      <ref url="http://archives.postgresql.org/pgsql-bugs/2005-01/msg00269.php" source="MLIST" adv="1">[pgsql-bugs] 20050121 Privilege escalation via LOAD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="7.2.6"/>
        <vers num="7.2.7"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.4.6"/>
        <vers num="7.4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0228" reject="1" published="2005-05-02" name="CVE-2005-0228" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1388.  Reason: This candidate is a duplicate of CVE-2004-1388.  Notes: All CVE users should reference CVE-2004-1388 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0229" published="2005-04-27" name="CVE-2005-0229" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12402" source="BID" patch="1" adv="1">12402</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110824766519417&amp;w=2" source="FULLDISC" patch="1" adv="1">20050212 Credit Card data disclosure in CitrusDB</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19145" source="XF">citrus-information-disclosure(19145)</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-001.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-001.txt</ref>
      <ref url="http://www.citrusdb.org/forums/viewtopic.php?t=49" source="CONFIRM">http://www.citrusdb.org/forums/viewtopic.php?t=49</ref>
      <ref url="http://securitytracker.com/id?1013040" source="SECTRACK">1013040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb_customer_database">
        <vers num="0.1.2"/>
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.3"/>
        <vers num="0.3.1"/>
        <vers num="0.3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0230" published="2005-05-02" name="CVE-2005-0230" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-25.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/mfsa2005-25.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=279945" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=279945</ref>
      <ref url="http://www.securityfocus.com/bid/12468" source="BID">12468</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mikx.de/firedragging/" source="MISC">http://www.mikx.de/firedragging/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780995232064&amp;w=2" source="BUGTRAQ" adv="1">20050207 Firedragging [Firefox 1.0]</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100033" source="OVAL" sig="1">oval:org.mitre.oval:def:100033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0231" published="2005-02-07" name="CVE-2005-0231" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=280056" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=280056</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19264" source="XF" patch="1" adv="1">mozilla-firefox-tab-gain-access(19264)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:016</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-26.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-26.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.mikx.de/firetabbing/" source="MISC" adv="1">http://www.mikx.de/firetabbing/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10079" source="OVAL">oval:org.mitre.oval:def:10079</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781134617144&amp;w=2" source="BUGTRAQ" adv="1">20050207 Firetabbing [Firefox 1.0]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100032" source="OVAL" sig="1">oval:org.mitre.oval:def:100032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0232" published="2005-05-02" name="CVE-2005-0232" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19266" source="XF" patch="1">mozilla-firefox-aboutconfig-modify(19266)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:016</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=280664" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=280664</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-27.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-27.html</ref>
      <ref url="http://www.mikx.de/fireflashing/" source="MISC">http://www.mikx.de/fireflashing/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10967" source="OVAL">oval:org.mitre.oval:def:10967</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781055630856&amp;w=2" source="BUGTRAQ" adv="1">20050207 Fireflashing [Firefox 1.0]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0233" published="2005-02-08" name="CVE-2005-0233" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1" adv="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:016</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-29.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-29.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC" adv="1">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC" adv="1">http://www.shmoo.com/idn</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11229" source="OVAL">oval:org.mitre.oval:def:11229</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" source="BUGTRAQ" adv="1">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100029" source="OVAL" sig="1">oval:org.mitre.oval:def:100029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="camino">
        <vers num="0.8.5"/>
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8"/>
        <vers num="0.9.2"/>
        <vers num="0.9.2.1"/>
        <vers num="0.9.3"/>
        <vers num="0.9.35"/>
        <vers num="0.9.4"/>
        <vers num="0.9.4.1"/>
        <vers num="0.9.48"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.2" edition="alpha"/>
        <vers num="1.2" edition="beta"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4" edition="beta"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.4"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.6"/>
      </prod>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5"/>
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.54"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0234" published="2005-05-02" name="CVE-2005-0234" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC" adv="1">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC">http://www.shmoo.com/idn</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" source="BUGTRAQ">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0235" published="2005-05-02" name="CVE-2005-0235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Opera 7.54 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC">http://www.shmoo.com/idn</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" source="BUGTRAQ">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_31_opera.html" source="SUSE">SUSE-SA:2005:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.54"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0236" published="2005-05-02" name="CVE-2005-0236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC">http://www.shmoo.com/idn</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" source="BUGTRAQ">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0237" published="2005-05-02" name="CVE-2005-0237" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.kde.org/info/security/advisory-20050316-2.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050316-2.txt</ref>
      <ref url="http://secunia.com/advisories/14162" source="SECUNIA" patch="1" adv="1">14162</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC">http://www.shmoo.com/idn</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10671" source="OVAL">oval:org.mitre.oval:def:10671</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031460.html" source="FULLDISC" adv="1">20050206 Re: state of homograph attacks</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" source="FEDORA">FLSA:178606</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-325.html" source="REDHAT">RHSA-2005:325</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058" source="MANDRAKE">MDKSA-2005:058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.2.1"/>
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0238" published="2005-05-02" name="CVE-2005-0238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/beta/show_bug.cgi?id=147399" source="CONFIRM" patch="1" adv="1">https://bugzilla.redhat.com/beta/show_bug.cgi?id=147399</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19236" source="XF" patch="1" adv="1">multiple-browsers-idn-spoof(19236)</ref>
      <ref url="http://www.shmoo.com/idn/homograph.txt" source="MISC" adv="1">http://www.shmoo.com/idn/homograph.txt</ref>
      <ref url="http://www.shmoo.com/idn" source="MISC" adv="1">http://www.shmoo.com/idn</ref>
      <ref url="http://www.securityfocus.com/bid/12461" source="BID">12461</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" source="FULLDISC" adv="1">20050206 state of homograph attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="epiphany">
        <vers num=""/>
      </prod>
      <prod vendor="mozilla" name="camino">
        <vers num="0.8.5"/>
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8"/>
        <vers num="0.9.2"/>
        <vers num="0.9.2.1"/>
        <vers num="0.9.3"/>
        <vers num="0.9.35"/>
        <vers num="0.9.4"/>
        <vers num="0.9.4.1"/>
        <vers num="0.9.48"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.2" edition="alpha"/>
        <vers num="1.2" edition="beta"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4" edition="beta"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.4"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.6"/>
      </prod>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5"/>
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.54"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0239" published="2005-05-02" name="CVE-2005-0239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/502328" source="CERT-VN" patch="1" adv="1">VU#502328</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19242" source="XF" patch="1">squirrelmail-smime-command-execution(19242)</ref>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=54" source="CONFIRM">http://www.squirrelmail.org/plugin_view.php?id=54</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=191&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" adv="1">20050207 SquirrelMail S/MIME Plugin Command Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="s_mime_plugin">
        <vers num="0.4"/>
        <vers num="0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0240" published="2005-05-02" name="CVE-2005-0240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19244" source="XF">aix-chdev-format-string(19244)</ref>
      <ref url="http://www.idefense.com/application/poi/display?type=vulnerabilities" source="IDEFENSE">20050207 IBM AIX chdev Local Format String Vulnerability</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67654" source="AIXAPAR" adv="1">IY67654</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67455" source="AIXAPAR" adv="1">IY67455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0241" published="2005-05-02" name="CVE-2005-0241" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/823350" source="CERT-VN" patch="1" adv="1">VU#823350</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19060" source="XF" patch="1">squid-http-cache-poisoning(19060)</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1216" source="CONFIRM" patch="1">http://www.squid-cache.org/bugs/show_bug.cgi?id=1216</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-061.html" source="REDHAT" patch="1" adv="1">RHSA-2005:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-060.html" source="REDHAT" patch="1" adv="1">RHSA-2005:060</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:006</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" patch="1">CLA-2005:931</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10998" source="OVAL">oval:org.mitre.oval:def:10998</ref>
      <ref url="http://www.securityfocus.com/bid/12412" source="BID">12412</ref>
      <ref url="http://secunia.com/advisories/14091" source="SECUNIA">14091</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
        <vers num="2.5.stable7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0242" published="2005-02-18" name="CVE-2005-0242" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2004-6/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2004-6/advisory/</ref>
      <ref url="http://secunia.com/advisories/11815" source="SECUNIA" patch="1">11815</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers num="5.6.0.1351"/>
        <vers num="6.0"/>
        <vers num="6.0.0.1750"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0243" published="2005-02-17" name="CVE-2005-0243" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2005-2/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-2/advisory/</ref>
      <ref url="http://secunia.com/advisories/13712" source="SECUNIA" patch="1" adv="1">13712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers num="5.6.0.1351"/>
        <vers num="6.0"/>
        <vers num="6.0.0.1750"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0244" published="2005-05-02" name="CVE-2005-0244" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19184" source="XF" patch="1">postgresql-security-bypass(19184)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://secunia.com/advisories/12948" source="SECUNIA" patch="1" adv="1">12948</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/12417" source="BID">12417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10927" source="OVAL">oval:org.mitre.oval:def:10927</ref>
      <ref url="http://archives.postgresql.org/pgsql-hackers/2005-01/msg00922.php" source="MLIST" adv="1">[pgsql-hackers] 20050127 Permissions on aggregate component functions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="7.2.6"/>
        <vers num="7.2.7"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.3.3"/>
        <vers num="7.3.4"/>
        <vers num="7.3.5"/>
        <vers num="7.3.6"/>
        <vers num="7.3.7"/>
        <vers num="7.3.8"/>
        <vers num="7.3.9"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.4.6"/>
        <vers num="7.4.7"/>
        <vers num="8.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0245" published="2005-02-01" name="CVE-2005-0245" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19188" source="XF" patch="1" adv="1">postgresql-cursor-bo(19188)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-150.html" source="REDHAT" patch="1" adv="1">RHSA-2005:150</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://secunia.com/advisories/12948" source="SECUNIA" patch="1" adv="1">12948</ref>
      <ref url="http://www.debian.org/security/2005/dsa-683" source="DEBIAN" adv="1">DSA-683</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10175" source="OVAL">oval:org.mitre.oval:def:10175</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" source="BUGTRAQ" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
      <ref url="http://archives.postgresql.org/pgsql-patches/2005-01/msg00216.php" source="MLIST" adv="1">[pgsql-patches] 20050120 Re: WIP: pl/pgsql cleanup</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php" source="MLIST" adv="1">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00298.php" source="MLIST" adv="1">[pgsql-committers] 20050121 pgsql: Prevent overrunning a heap-allocated buffer is more than 1024</ref>
      <ref url="http://www.securityfocus.com/bid/12417" source="BID">12417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="7.2.6"/>
        <vers num="7.2.7"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.3.3"/>
        <vers num="7.3.4"/>
        <vers num="7.3.5"/>
        <vers num="7.3.6"/>
        <vers num="7.3.7"/>
        <vers num="7.3.8"/>
        <vers num="7.3.9"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.4.6"/>
        <vers num="7.4.7"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0246" published="2005-05-02" name="CVE-2005-0246" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19185" source="XF" patch="1">postgresql-contribintagg-dos(19185)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://secunia.com/advisories/12948" source="SECUNIA" patch="1" adv="1">12948</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00401.php" source="MLIST" patch="1">[pgsql-committers] 20050127 pgsql: Fix security and 64-bit issues in contrib/intagg.</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10148" source="OVAL">oval:org.mitre.oval:def:10148</ref>
      <ref url="http://www.securityfocus.com/bid/12417" source="BID">12417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="7.2.6"/>
        <vers num="7.2.7"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.3.3"/>
        <vers num="7.3.4"/>
        <vers num="7.3.5"/>
        <vers num="7.3.6"/>
        <vers num="7.3.7"/>
        <vers num="7.3.8"/>
        <vers num="7.3.9"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.4.6"/>
        <vers num="7.4.7"/>
        <vers num="8.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0247" published="2005-05-02" name="CVE-2005-0247" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19378" source="XF" patch="1">postgresql-fetch-makefetchstmt-bo(19378)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19377" source="XF" patch="1">postgresql-makeselectstmt-arbitrary-bo(19377)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19376" source="XF" patch="1">postgresql-makeselectstmt-input-bo(19376)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19375" source="XF" patch="1">postgresql-readsqlconstruct-bo(19375)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-150.html" source="REDHAT" patch="1" adv="1">RHSA-2005:150</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-138.html" source="REDHAT" patch="1" adv="1">RHSA-2005:138</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_27_postgresql.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:027</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-19.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-19</ref>
      <ref url="http://www.debian.org/security/2005/dsa-683" source="DEBIAN" patch="1" adv="1">DSA-683</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php" source="MLIST" patch="1">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref>
      <ref url="http://www.securityfocus.com/bid/12417" source="BID">12417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040" source="MANDRAKE">MDKSA-2005:040</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9345" source="OVAL">oval:org.mitre.oval:def:9345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="7.2.6"/>
        <vers num="7.2.7"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.3.3"/>
        <vers num="7.3.4"/>
        <vers num="7.3.5"/>
        <vers num="7.3.6"/>
        <vers num="7.3.7"/>
        <vers num="7.3.8"/>
        <vers num="7.3.9"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.4.6"/>
        <vers num="7.4.7"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0248" published="2005-05-02" name="CVE-2005-0248" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18868" source="XF" patch="1">solaris-smc-blank-password(18868)</ref>
      <ref url="http://www.securityfocus.com/bid/12260" source="BID" patch="1">12260</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57717-1" source="SUNALERT" patch="1">57717</ref>
      <ref url="http://secunia.com/advisories/13803/" source="SECUNIA" patch="1" adv="1">13803</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-096.shtml" source="CIAC" adv="1">P-096</ref>
      <ref url="http://securitytracker.com/id?1012860" source="SECTRACK">1012860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0249" published="2005-02-08" name="CVE-2005-0249" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/107822" source="CERT-VN" patch="1" adv="1">VU#107822</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18869" source="XF" patch="1" adv="1">upx-engine-gain-control(18869)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/187" source="ISS" patch="1" adv="1">20050208 Symantec AntiVirus Library Heap Overflow</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2005.02.08.html" source="CONFIRM" patch="1" adv="1">http://www.symantec.com/avcenter/security/Content/2005.02.08.html</ref>
      <ref url="http://securitytracker.com/id?1013133" source="SECTRACK">1013133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers prev="1" num="4.0" edition=""/>
        <vers prev="1" num="4.0" edition=":netapp_filer"/>
        <vers prev="1" num="4.0" edition=":bluecoat"/>
        <vers prev="1" num="4.0" edition=":netapp_netcache"/>
        <vers prev="1" num="4.3"/>
        <vers prev="1" num="4.3.3" edition=""/>
        <vers prev="1" num="4.3.3" edition=":filers"/>
        <vers prev="1" num="4.3.3" edition=":bluecoat"/>
        <vers prev="1" num="4.3.3" edition=":caching"/>
        <vers prev="1" num="4.3.3" edition=":netapp_filer"/>
        <vers prev="1" num="4.3.3" edition=":netapp_netcache"/>
      </prod>
      <prod vendor="symantec" name="brightmail_antispam">
        <vers prev="1" num="4.0"/>
        <vers prev="1" num="5.5"/>
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="1.0.1_build_8.01.434" edition="mr3"/>
        <vers num="1.0.1_build_8.01.437"/>
        <vers num="1.0.1_build_8.01.446" edition="mr4"/>
        <vers num="1.0.1_build_8.01.457" edition="mr5"/>
        <vers num="1.0.1_build_8.01.460" edition="mr6"/>
        <vers num="1.0.1_build_8.01.464" edition="mr7"/>
        <vers num="1.0.1_build_8.01.471" edition="mr8"/>
        <vers num="1.1.1_mr1_build_8.1.1.314a"/>
        <vers num="1.1.1_mr2_build_8.1.1.319"/>
        <vers num="1.1.1_mr3_build_8.1.1.323"/>
        <vers num="1.1.1_mr4_build_8.1.1.329"/>
        <vers num="1.1.1_mr5_build_8.1.1.336"/>
      </prod>
      <prod vendor="symantec" name="gateway_security">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
      <prod vendor="symantec" name="mail_security">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":domino"/>
        <vers prev="1" num="4.0.2" edition=""/>
        <vers prev="1" num="4.0.2" edition=":smtp"/>
        <vers num="4.1" edition="build_458"/>
        <vers num="4.1" edition="build_458:exchange"/>
        <vers num="4.1" edition="build_459"/>
        <vers num="4.1" edition="build_459:exchange"/>
        <vers num="4.1" edition="build_461"/>
        <vers num="4.1" edition="build_461:exchange"/>
        <vers num="4.5_build_719" edition=""/>
        <vers num="4.5_build_719" edition=":exchange"/>
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2.18_build_83" edition=""/>
        <vers num="2.18_build_83" edition=":exchange"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":windows"/>
        <vers num="8.01.434" edition=""/>
        <vers num="8.01.434" edition=":corporate"/>
        <vers num="8.01.437" edition=""/>
        <vers num="8.01.437" edition=":corporate"/>
        <vers num="8.01.446" edition=""/>
        <vers num="8.01.446" edition=":corporate"/>
        <vers num="8.01.457" edition=""/>
        <vers num="8.01.457" edition=":corporate"/>
        <vers num="8.01.460" edition=""/>
        <vers num="8.01.460" edition=":corporate"/>
        <vers num="8.01.464" edition=""/>
        <vers num="8.01.464" edition=":corporate"/>
        <vers num="8.01.471" edition=""/>
        <vers num="8.01.471" edition=":corporate"/>
        <vers num="8.1.1.319" edition=""/>
        <vers num="8.1.1.319" edition=":corporate"/>
        <vers num="8.1.1.323" edition=""/>
        <vers num="8.1.1.323" edition=":corporate"/>
        <vers num="8.1.1.329" edition=""/>
        <vers num="8.1.1.329" edition=":corporate"/>
        <vers num="8.1.1_build8.1.1.314a" edition=""/>
        <vers num="8.1.1_build8.1.1.314a" edition=":corporate"/>
        <vers prev="1" num="9.0" edition=""/>
        <vers prev="1" num="9.0" edition=":macintosh_corporate"/>
        <vers prev="1" num="9.0" edition=":macintosh_osx"/>
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":professional"/>
        <vers prev="1" num="3.0" edition=""/>
        <vers prev="1" num="3.0" edition=":macintosh"/>
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":windows"/>
        <vers prev="1" num="3.0" edition=""/>
        <vers prev="1" num="3.0" edition=":macintosh"/>
      </prod>
      <prod vendor="symantec" name="sav_filter_domino_nt_ports">
        <vers num="build3.0.5" edition=""/>
        <vers num="build3.0.5" edition=":aix"/>
        <vers num="build3.0.5" edition=":os_400"/>
      </prod>
      <prod vendor="symantec" name="sav_filter_for_domino_nt">
        <vers num="3.1.1"/>
      </prod>
      <prod vendor="symantec" name="web_security">
        <vers num="3.01.59"/>
        <vers num="3.01.60"/>
        <vers num="3.01.61"/>
        <vers num="3.01.62"/>
        <vers num="3.01.63"/>
        <vers num="3.01.67"/>
        <vers num="3.01.68"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0250" published="2005-05-02" name="CVE-2005-0250" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/896729" source="CERT-VN" adv="1">VU#896729</ref>
      <ref url="http://www.securityfocus.com/bid/12496" source="BID" patch="1">12496</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=193&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20050208 IBM AIX auditselect Local Format String Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19255" source="XF">aix-auditselect-format-string(19255)</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67802" source="AIXAPAR" adv="1">IY67802</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67519" source="AIXAPAR" adv="1">IY67519</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67472" source="AIXAPAR" adv="1">IY67472</ref>
      <ref url="http://secunia.com/advisories/14198" source="SECUNIA" adv="1">14198</ref>
      <ref url="http://securitytracker.com/id?1013103" source="SECTRACK">1013103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0251" published="2005-05-02" name="CVE-2005-0251" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12583" source="BID" patch="1" adv="1">12583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2" source="FULLDISC" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2" source="BUGTRAQ" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biborb" name="biborb">
        <vers num="1.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0252" published="2005-05-02" name="CVE-2005-0252" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12583" source="BID" patch="1">12583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2" source="FULLDISC" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2" source="BUGTRAQ" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biborb" name="biborb">
        <vers num="1.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0253" published="2005-05-02" name="CVE-2005-0253" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12583" source="BID" patch="1">12583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2" source="FULLDISC" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2" source="BUGTRAQ" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biborb" name="biborb">
        <vers num="1.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0254" published="2005-05-02" name="CVE-2005-0254" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12583" source="BID" patch="1">12583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2" source="FULLDISC" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2" source="BUGTRAQ" adv="1">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biborb" name="biborb">
        <vers num="1.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0255" published="2005-05-02" name="CVE-2005-0255" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-337.html" source="REDHAT" patch="1" adv="1">RHSA-2005:337</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-277.html" source="REDHAT" patch="1" adv="1">RHSA-2005:277</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:016</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=200&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050228 Mozilla Firefox and Mozilla Browser Out Of Memory Heap Corruption Design Error</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-10</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-18.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-18.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9111" source="OVAL">oval:org.mitre.oval:def:9111</ref>
      <ref url="http://www.securityfocus.com/bid/12659" source="BID">12659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100040" source="OVAL" sig="1">oval:org.mitre.oval:def:100040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7.3"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0256" published="2005-05-02" name="CVE-2005-0256" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-705" source="DEBIAN" patch="1" adv="1">DSA-705</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1271" source="VUPEN" adv="1">ADV-2006-1271</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0588" source="VUPEN" adv="1">ADV-2005-0588</ref>
      <ref url="http://www.osvdb.org/14203" source="OSVDB">14203</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=207&amp;type=vulnerabilities" source="IDEFENSE">20050225 WU-FTPD File Globbing Denial of Service Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57795-1" source="SUNALERT">57795</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101699-1" source="SUNALERT">101699</ref>
      <ref url="http://secunia.com/advisories/19561" source="SECUNIA" adv="1">19561</ref>
      <ref url="http://secunia.com/advisories/18210" source="SECUNIA" adv="1">18210</ref>
      <ref url="http://secunia.com/advisories/14411" source="SECUNIA" adv="1">14411</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00637342" source="HP">HPSBUX02110</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00637342" source="HP">SSRT061110</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.63/SCOSA-2005.63.txt" source="SCO">SCOSA-2005.63</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1762" source="OVAL" sig="1">oval:org.mitre.oval:def:1762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1333" source="OVAL" sig="1">oval:org.mitre.oval:def:1333</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1265" source="OVAL" sig="1">oval:org.mitre.oval:def:1265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0258" published="2005-03-14" name="CVE-2005-0258" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via "/../" sequences in the avatarselect parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=205&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050222 phpBB Group phpBB2 Arbitrary File Unlink Vulnerability</ref>
      <ref url="http://www.phpbb.com/support/documents.php?mode=changelog" source="CONFIRM" adv="1">http://www.phpbb.com/support/documents.php?mode=changelog</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml" source="GENTOO">GLSA-200503-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.6c"/>
        <vers num="2.0.6d"/>
        <vers num="2.0.7"/>
        <vers num="2.0.7a"/>
        <vers num="2.0.8"/>
        <vers num="2.0.8a"/>
        <vers num="2.0.9"/>
        <vers num="2.0_beta1"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
        <vers num="2.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0259" published="2005-03-14" name="CVE-2005-0259" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/774686" source="CERT-VN">VU#774686</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=204&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050222 phpBB Group phpBB Arbitrary File Disclosure Vulnerability</ref>
      <ref url="http://www.phpbb.com/support/documents.php?mode=changelog" source="CONFIRM" adv="1">http://www.phpbb.com/support/documents.php?mode=changelog</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml" source="GENTOO">GLSA-200503-02</ref>
      <ref url="http://secunia.com/advisories/14362/" source="SECUNIA">14362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.6c"/>
        <vers num="2.0.6d"/>
        <vers num="2.0.7"/>
        <vers num="2.0.7a"/>
        <vers num="2.0.8"/>
        <vers num="2.0.8a"/>
        <vers num="2.0.9"/>
        <vers num="2.0_beta1"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
        <vers num="2.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0260" published="2005-05-02" name="CVE-2005-0260" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=194&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050209 Computer Associates BrightStor ARCserve Backup v11 Discovery Service Remote Buffer Overflow Vulnerability</ref>
      <ref url="http://supportconnectw.ca.com/public/enews/BrightStor/brigcurrent.asp#news1" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/enews/BrightStor/brigcurrent.asp#news1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19251" source="XF">brightstor-discovery-bo(19251)</ref>
      <ref url="http://securitytracker.com/id?1013138" source="SECTRACK">1013138</ref>
      <ref url="http://secunia.com/advisories/14183" source="SECUNIA">14183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0261" published="2005-02-10" name="CVE-2005-0261" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67655&amp;apar=only" source="AIXAPAR" patch="1" adv="1">IY67655</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67457&amp;apar=only" source="AIXAPAR" patch="1" adv="1">IY67457</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19281" source="XF">ibm-aix-ispath-information-disclosure(19281)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=195&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050210 IBM AIX lspath Local File Access Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12513" source="BID">12513</ref>
      <ref url="http://secunia.com/advisories/14232" source="SECUNIA">14232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2"/>
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0262" published="2005-05-02" name="CVE-2005-0262" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=196&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050210 IBM AIX ipl_varyon Local Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19282" source="XF">ibm-aix-iplvaryon-bo(19282)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67812&amp;apar=only" source="AIXAPAR">IY67812</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67750&amp;apar=only" source="AIXAPAR">IY67750</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY66933&amp;apar=only" source="AIXAPAR">IY66933</ref>
      <ref url="http://www.securityfocus.com/bid/12516" source="BID">12516</ref>
      <ref url="http://secunia.com/advisories/14231" source="SECUNIA">14231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0263" published="2005-05-02" name="CVE-2005-0263" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=197&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050210 IBM AIX netpmon Local Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19278" source="XF">ibm-aix-netpmon-bo(19278)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67807&amp;apar=only" source="AIXAPAR">IY67807</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67136&amp;apar=only" source="AIXAPAR">IY67136</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67124&amp;apar=only" source="AIXAPAR">IY67124</ref>
      <ref url="http://www.securityfocus.com/bid/12517" source="BID">12517</ref>
      <ref url="http://secunia.com/advisories/14237" source="SECUNIA">14237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0264" published="2005-05-02" name="CVE-2005-0264" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461644407935&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050101 Various Vulnerabilities in OWL Intranet Engine</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18705" source="XF">owl-intranet-engine-xss(18705)</ref>
      <ref url="http://www.securityfocus.com/bid/12114" source="BID">12114</ref>
      <ref url="http://secunia.com/advisories/13695" source="SECUNIA">13695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="owl" name="owl_intranet_engine">
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.71"/>
        <vers num="0.72"/>
        <vers num="0.73"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0265" published="2005-05-02" name="CVE-2005-0265" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12114" source="BID" patch="1">12114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18704" source="XF">owl-intranet-engine-sql-injection(18704)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461644407935&amp;w=2" source="BUGTRAQ" adv="1">20050101 Various Vulnerabilities in OWL Intranet Engine</ref>
      <ref url="http://secunia.com/advisories/13695" source="SECUNIA">13695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="owl" name="owl_intranet_engine">
        <vers num="0.7"/>
        <vers num="0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0266" published="2005-01-01" name="CVE-2005-0266" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461706232174&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050101 Cross Site Scripting Vulnerabilities and Possible Code Execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18719" source="XF">sugar-sales-index-xss(18719)</ref>
      <ref url="http://www.securityfocus.com/bid/12113" source="BID">12113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sugarcrm" name="sugarcrm">
        <vers num="1.0"/>
        <vers num="1.0f"/>
        <vers num="1.0g"/>
        <vers num="1.1"/>
        <vers num="1.1a"/>
        <vers num="1.1b"/>
        <vers num="1.1c"/>
        <vers num="1.1d"/>
        <vers num="1.1e"/>
        <vers num="1.1f"/>
        <vers num="1.5d"/>
        <vers num="2.0.1"/>
        <vers num="2.0.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0267" published="2005-05-02" name="CVE-2005-0267" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12150" source="BID" patch="1">12150</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18741" source="XF">flatnuke-indexphp-gain-access(18741)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2" source="BUGTRAQ" adv="1">20050102 Multiple Vulnerabilities in FlatNuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0268" published="2005-01-03" name="CVE-2005-0268" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18746" source="XF" patch="1" adv="1">flatnuke-indexphp-xss(18746)</ref>
      <ref url="http://www.securityfocus.com/bid/12150" source="BID" patch="1" adv="1">12150</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2" source="BUGTRAQ" adv="1">20050102 Multiple Vulnerabilities in FlatNuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnuke" name="flatnuke">
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0269" published="2005-05-02" name="CVE-2005-0269" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18729" source="XF" patch="1">gnuboard-gbupdate-file-upload(18729)</ref>
      <ref url="http://www.securityfocus.com/bid/12149" source="BID">12149</ref>
      <ref url="http://secunia.com/advisories/13711" source="SECUNIA">13711</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477648219738&amp;w=2" source="BUGTRAQ" adv="1">20050103 STG Security Advisory: [SSA-20041224-21] File extensions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sir" name="gnuboard">
        <vers num="3.30"/>
        <vers num="3.31"/>
        <vers num="3.32"/>
        <vers num="3.33"/>
        <vers num="3.34"/>
        <vers num="3.35"/>
        <vers num="3.36"/>
        <vers num="3.37"/>
        <vers num="3.38"/>
        <vers num="3.39"/>
        <vers num="3.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0270" published="2005-05-02" name="CVE-2005-0270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18731" source="XF">reviewpost-php-xss(18731)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref>
      <ref url="http://secunia.com/advisories/13697/" source="SECUNIA" adv="1">13697</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2" source="BUGTRAQ" adv="1">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="reviewpost_php_pro">
        <vers num="1.0.2"/>
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers prev="1" num="2.84"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0271" published="2005-01-03" name="CVE-2005-0271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18732" source="XF" patch="1" adv="1">reviewpost-php-sql-injection(18732)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref>
      <ref url="http://secunia.com/advisories/13697/" source="SECUNIA" patch="1" adv="1">13697</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="reviewpost_php_pro">
        <vers num="1.0.2"/>
        <vers num="2.5"/>
        <vers prev="1" num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0272" published="2005-05-02" name="CVE-2005-0272" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13697/" source="SECUNIA" patch="1" adv="1">13697</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18735" source="XF">reviewpost-php-file-upload(18735)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="reviewpost_php_pro">
        <vers num="1.0.2"/>
        <vers num="2.5"/>
        <vers prev="1" num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0273" published="2005-05-02" name="CVE-2005-0273" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18744" source="XF" patch="1">photopost-php-showgallery-xss(18744)</ref>
      <ref url="http://www.securityfocus.com/bid/12156" source="BID">12156</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref>
      <ref url="http://secunia.com/advisories/13680/" source="SECUNIA" adv="1">13680</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2" source="BUGTRAQ" adv="1">20050103 Multiple PhotoPost Pro Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers prev="1" num="4.85"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0274" published="2005-01-03" name="CVE-2005-0274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18744" source="XF" patch="1" adv="1">photopost-php-showgallery-xss(18744)</ref>
      <ref url="http://www.securityfocus.com/bid/12156" source="BID" patch="1" adv="1">12156</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050103 Multiple PhotoPost Pro Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/13680/" source="SECUNIA" adv="1">13680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers prev="1" num="4.85"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0275" published="2005-05-02" name="CVE-2005-0275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18750" source="XF">3cdaemon-reserved-name-dos(18750)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2" source="BUGTRAQ" adv="1">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cdaemon">
        <vers num="2.0" edition="revision_10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0276" published="2005-05-02" name="CVE-2005-0276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18751" source="XF">3cdaemon-login-dos(18751)</ref>
      <ref url="http://www.securityfocus.com/bid/12155" source="BID">12155</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2" source="BUGTRAQ" adv="1">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cdaemon">
        <vers num="2.0" edition="revision_10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0277" published="2005-05-02" name="CVE-2005-0277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18754" source="XF">3cdaemon-long-command-dos(18754)</ref>
      <ref url="http://www.securityfocus.com/bid/12155" source="BID">12155</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886719528518&amp;w=2" source="BUGTRAQ">20050218 3com 3CDaemon FTP Unauthorized "USER" Remote BOverflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2" source="BUGTRAQ" adv="1">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cdaemon">
        <vers num="2.0" edition="revision_10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0278" published="2005-05-02" name="CVE-2005-0278" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18756" source="XF">3cdaemon-command-obtain-information(18756)</ref>
      <ref url="http://www.securityfocus.com/bid/12155" source="BID">12155</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2" source="BUGTRAQ" adv="1">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cdaemon">
        <vers num="2.0" edition="revision_10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0279" published="2005-05-02" name="CVE-2005-0279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Soldner Secret Wars 30830 and earlier does not properly handle the "message too long" socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18749" source="XF">soldner-secret-wars-dos(18749)</ref>
      <ref url="http://www.securityfocus.com/bid/12162" source="BID">12162</ref>
      <ref url="http://secunia.com/advisories/13716" source="SECUNIA">13716</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2" source="BUGTRAQ">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jowood_productions" name="soldner_secret_wars">
        <vers prev="1" num="30830"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0280" published="2005-01-04" name="CVE-2005-0280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18752" source="XF" adv="1">soldner-secret-wars-format-string(18752)</ref>
      <ref url="http://www.securityfocus.com/bid/12162" source="BID" adv="1">12162</ref>
      <ref url="http://secunia.com/advisories/13716" source="SECUNIA">13716</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2" source="BUGTRAQ" adv="1">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jowood_productions" name="soldner_secret_wars">
        <vers num="30830"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0281" published="2005-05-02" name="CVE-2005-0281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or quoted when the administrator views the server logs.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18753" source="XF">soldner-secret-wars-xss(18753)</ref>
      <ref url="http://www.securityfocus.com/bid/12162" source="BID">12162</ref>
      <ref url="http://secunia.com/advisories/13716" source="SECUNIA">13716</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2" source="BUGTRAQ" adv="1">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jowood_productions" name="soldner_secret_wars">
        <vers prev="1" num="30830"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0282" published="2005-05-02" name="CVE-2005-0282" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/187" source="XF">mybb-member-sql-injection(18755)</ref>
      <ref url="http://www.securityfocus.com/bid/12161" source="BID">12161</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486566600980&amp;w=2" source="BUGTRAQ" adv="1">20050104 MyBB SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0283" published="2005-01-04" name="CVE-2005-0283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18748" source="XF" adv="1">qwikiwiki-directory-traversal(18748)</ref>
      <ref url="http://www.securityfocus.com/bid/12163" source="BID" adv="1">12163</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486832621053&amp;w=2" source="BUGTRAQ" adv="1">20050104 QWikiwiki directory traversal vulnerability</ref>
      <ref url="http://www.qwikiwiki.com/index.php?page=QwikiVulnerability" source="CONFIRM">http://www.qwikiwiki.com/index.php?page=QwikiVulnerability</ref>
      <ref url="http://secunia.com/advisories/12044" source="SECUNIA">12044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_barrett" name="qwikiwiki">
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0284" published="2005-01-10" name="CVE-2005-0284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18859" source="XF" adv="1">woltlab-book-addentry-sql-injection(18859)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548032401506&amp;w=2" source="BUGTRAQ" adv="1">20050110 Woltlab Burning Book addentry.php SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_book">
        <vers num="1.0_gold"/>
        <vers num="1.1.1e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0285" published="2005-05-02" name="CVE-2005-0285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18848" source="XF">webseries-pa-url-security-bypass(18848)</ref>
      <ref url="http://www.securityfocus.com/bid/12216" source="BID">12216</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547396124885&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-001</ref>
      <ref url="http://securitytracker.com/id?1012854" source="SECTRACK">1012854</ref>
      <ref url="http://secunia.com/advisories/13821" source="SECUNIA">13821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bottomline" name="webseries_payment_application">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0286" published="2005-05-02" name="CVE-2005-0286" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18861" source="XF">mediapartner-bhtml-source-disclosure(18861)</ref>
      <ref url="http://www.securityfocus.com/bid/12236" source="BID">12236</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547824902053&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-004</ref>
      <ref url="http://securitytracker.com/id?1012855" source="SECTRACK">1012855</ref>
      <ref url="http://secunia.com/advisories/13820" source="SECUNIA">13820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emotion" name="mediapartner_web_server">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0287" published="2005-01-10" name="CVE-2005-0287" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18862" source="XF" adv="1">webseries-report-execution(18862)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548383812462&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-009</ref>
      <ref url="http://securitytracker.com/id?1012854" source="SECTRACK">1012854</ref>
      <ref url="http://secunia.com/advisories/13821" source="SECUNIA">13821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bottomline" name="webseries_payment_application">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0288" published="2005-01-11" name="CVE-2005-0288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18860" source="XF" adv="1">webseries-pa-password-gain-access(18860)</ref>
      <ref url="http://www.securityfocus.com/bid/12231" source="BID" adv="1">12231</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549684319400&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-008</ref>
      <ref url="http://securitytracker.com/id?1012854" source="SECTRACK">1012854</ref>
      <ref url="http://secunia.com/advisories/13821" source="SECUNIA">13821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bottomline" name="webseries_payment_application">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0289" published="2005-05-02" name="CVE-2005-0289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110582124528867&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050115 Apple Airport WDS DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18865" source="XF">apple-airport-dos(18865)</ref>
      <ref url="http://www.securityfocus.com/bid/12152" source="BID">12152</ref>
      <ref url="http://secunia.com/advisories/13753" source="SECUNIA">13753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="airport_express">
        <vers prev="1" num="6.1"/>
      </prod>
      <prod vendor="apple" name="airport_extreme">
        <vers prev="1" num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0290" published="2005-01-17" name="CVE-2005-0290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18920" source="XF" adv="1">netgear-fvs318-filter-bypass(18920)</ref>
      <ref url="http://www.securityfocus.com/bid/12278" source="BID" adv="1">12278</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2" source="BUGTRAQ" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html" source="FULLDISC" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
      <ref url="http://securitytracker.com/id?1012913" source="SECTRACK">1012913</ref>
      <ref url="http://secunia.com/advisories/13787" source="SECUNIA">13787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="fvs318">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0291" published="2005-01-17" name="CVE-2005-0291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18921" source="XF" adv="1">netgear-fvs318-log-xss(18921)</ref>
      <ref url="http://www.securityfocus.com/bid/12278" source="BID" adv="1">12278</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2" source="BUGTRAQ" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html" source="FULLDISC" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
      <ref url="http://www.osvdb.org/13012" source="OSVDB">13012</ref>
      <ref url="http://securitytracker.com/id?1012913" source="SECTRACK">1012913</ref>
      <ref url="http://secunia.com/advisories/13787" source="SECUNIA">13787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="fvs318">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0292" published="2005-01-17" name="CVE-2005-0292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12289" source="BID" patch="1" adv="1">12289</ref>
      <ref url="http://www.securityfocus.com/archive/1/392485" source="BUGTRAQ" patch="1" adv="1">20050307 Re: phpGiftReq SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18925" source="XF" adv="1">phpgiftregistry-sql-injection(18925)</ref>
      <ref url="http://secunia.com/advisories/13873" source="SECUNIA" adv="1">13873</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599710017066&amp;w=2" source="BUGTRAQ" adv="1">20050116 phpGiftReq SQL Injection</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html" source="FULLDISC" adv="1">20050116 phpGiftReq SQL Injection</ref>
      <ref url="http://securitytracker.com/id?1012910" source="SECTRACK">1012910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_gift_registry" name="phpgiftreg">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0293" published="2005-05-02" name="CVE-2005-0293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18928" source="XF">minis-month-directory-traversal(18928)</ref>
      <ref url="http://www.securityfocus.com/bid/12279" source="BID">12279</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2" source="BUGTRAQ" adv="1">20050116 Minis directory traversal vulnerability</ref>
      <ref url="http://securitytracker.com/id?1012911" source="SECTRACK">1012911</ref>
      <ref url="http://secunia.com/advisories/13866" source="SECUNIA">13866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minis" name="minis">
        <vers num="0.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0294" published="2005-01-16" name="CVE-2005-0294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18929" source="XF" adv="1">minis-month-dos(18929)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2" source="BUGTRAQ" adv="1">20050116 Minis directory traversal vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030966.html" source="FULLDISC" adv="1">20050116 Minis directory traversal vulnerability</ref>
      <ref url="http://securitytracker.com/id?1012911" source="SECTRACK">1012911</ref>
      <ref url="http://secunia.com/advisories/13866" source="SECUNIA">13866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minis" name="minis">
        <vers num="0.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0295" published="2005-01-17" name="CVE-2005-0295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18952" source="XF" adv="1">nprotect-npptnt2-gain-access(18952)</ref>
      <ref url="http://www.securityfocus.com/bid/12280" source="BID" adv="1">12280</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608422029555&amp;w=2" source="BUGTRAQ" adv="1">20050116 Unrestricted I/O access vulnerability in INCA Gameguard</ref>
      <ref url="http://secunia.com/advisories/13928" source="SECUNIA">13928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inca" name="nprotect_gameguard">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0296" published="2005-01-17" name="CVE-2005-0296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page.  NOTE: the vendor has disputed this issue.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18954" source="XF" adv="1">groupwise-error-auth-bypass(18954)</ref>
      <ref url="http://www.securityfocus.com/bid/12285" source="BID" adv="1">12285</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.html" source="BUGTRAQ" adv="1">20050127 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.html" source="FULLDISC" adv="1">20050121 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref>
      <ref url="http://support.novell.com/servlet/tidfinder/10096251" source="MISC" adv="1">http://support.novell.com/servlet/tidfinder/10096251</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608203729814&amp;w=2" source="BUGTRAQ" adv="1">20050117 Novell GroupWise WebAccess error modules loading</ref>
      <ref url="http://www.osvdb.org/13135" source="OSVDB">13135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp3"/>
        <vers num="6.0" edition="sp4"/>
        <vers num="6.5" edition="sp1"/>
        <vers num="6.5" edition="sp2"/>
      </prod>
      <prod vendor="novell" name="groupwise_webaccess">
        <vers num="6.0" edition="sp4"/>
        <vers num="6.5" edition="sp1"/>
        <vers num="6.5" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0297" published="2005-01-18" name="CVE-2005-0297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110606477308492&amp;w=2" source="BUGTRAQ" adv="1">20050118 Multiple high risk vulnerabilities in Oracle RDBMS 10g/9i</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.1" edition="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0298" published="2005-05-02" name="CVE-2005-0298" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18947" source="XF" patch="1">oracle-directory-lob-obtain-info(18947)</ref>
      <ref url="http://www.petefinnigan.com/directory_traversal.pdf" source="MISC" patch="1" adv="1">http://www.petefinnigan.com/directory_traversal.pdf</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpu-jan-2005_advisory.pdf" source="MISC" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpu-jan-2005_advisory.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608912525883&amp;w=2" source="BUGTRAQ" adv="1">20050118 PeteFinnigan.com - Oracle security advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.2"/>
        <vers num="10.1.0.3"/>
        <vers num="10.1.0.3.1"/>
        <vers num="8.0.6"/>
        <vers num="8.0.6.3"/>
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.4"/>
        <vers num="9.0.1.5"/>
        <vers num="9.0.4"/>
        <vers num="9.2.0.4"/>
        <vers num="9.2.0.5"/>
        <vers num="9.2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0299" published="2005-05-02" name="CVE-2005-0299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12318" source="BID" patch="1">12318</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627132209963&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050120 STG Security Advisory: [SSA-20050120-24] GForge 3.x directory</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18988" source="XF">gforge-dir-dirname-directory-traversal(18988)</ref>
      <ref url="http://securitytracker.com/id?1012950" source="SECTRACK">1012950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.21"/>
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0300" published="2005-01-20" name="CVE-2005-0300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18990" source="XF" patch="1" adv="1">jsboard-session-file-include(18990)</ref>
      <ref url="http://www.securityfocus.com/bid/12319" source="BID" patch="1" adv="1">12319</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627201120011&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050120 STG Security Advisory: [SSA-20050120-22] JSBoard file disclosure</ref>
      <ref url="http://securitytracker.com/id?1012949" source="SECTRACK">1012949</ref>
      <ref url="http://secunia.com/advisories/13920" source="SECUNIA">13920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jsboard" name="jsboard">
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0301" published="2005-05-02" name="CVE-2005-0301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19010" source="XF" patch="1">backoffice-lite-administrative-bypass(19010)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref>
      <ref url="http://www.comersus.org/forum/displayMessage.asp?mid=32753" source="CONFIRM" adv="1">http://www.comersus.org/forum/displayMessage.asp?mid=32753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_backoffice_lite">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0302" published="2005-05-02" name="CVE-2005-0302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19013" source="XF" patch="1">backoffice-lite-sql-injection(19013)</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html" source="MISC" patch="1">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_backoffice_lite">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0303" published="2005-05-02" name="CVE-2005-0303" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19014" source="XF" patch="1">backoffice-lite-xss(19014)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_backoffice_lite">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0304" published="2005-05-02" name="CVE-2005-0304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in DivX Player 2.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename in a ZIP file for a skin.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19030" source="XF">divx-player-directory-traversal(19030)</ref>
      <ref url="http://www.securityfocus.com/bid/12332" source="BID">12332</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642748517854&amp;w=2" source="BUGTRAQ" adv="1">20050121 Arbitrary files overwriting through skins in DivX Player 2.6</ref>
      <ref url="http://secunia.com/advisories/13969" source="SECUNIA">13969</ref>
      <ref url="http://aluigi.altervista.org/adv/divxplayer-adv.txt" source="MISC">http://aluigi.altervista.org/adv/divxplayer-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="divx" name="divx_player">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0305" published="2005-05-02" name="CVE-2005-0305" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18998" source="XF">siteman-gain-access(18998)</ref>
      <ref url="http://www.securityfocus.com/bid/12304" source="BID">12304</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110643320814371&amp;w=2" source="BUGTRAQ">20050122 Siteman User Database Line Insertion Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627350616949&amp;w=2" source="BUGTRAQ" adv="1">20050120 God Admin Injection Vulnerability in Siteman 1.0.x,</ref>
      <ref url="http://www.osvdb.org/13131" source="OSVDB">13131</ref>
      <ref url="http://securitytracker.com/id?1012951" source="SECTRACK">1012951</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siteman" name="siteman">
        <vers num="1.1.10"/>
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0306" published="2005-01-25" name="CVE-2005-0306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19048" source="XF" patch="1" adv="1">mercuryboard-multiple-script-path-disclosure(19048)</ref>
      <ref url="http://www.securityfocus.com/bid/12359" source="BID" patch="1" adv="1">12359</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2" source="BUGTRAQ" adv="1">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0307" published="2005-01-25" name="CVE-2005-0307" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19050" source="XF" patch="1" adv="1">mercuryboard-multiple-scripts-xss(19050)</ref>
      <ref url="http://www.securityfocus.com/bid/12359" source="BID" patch="1" adv="1">12359</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2" source="BUGTRAQ" adv="1">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0308" published="2005-01-24" name="CVE-2005-0308" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19044" source="XF" adv="1">w32dasm-wsprintf-bo(19044)</ref>
      <ref url="http://www.securityfocus.com/bid/12352" source="BID" adv="1">12352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661194108205&amp;w=2" source="BUGTRAQ" adv="1">20050124 Local buffer-overflow in W32Dasm 8.93</ref>
      <ref url="http://securitytracker.com/id?1012997" source="SECTRACK">1012997</ref>
      <ref url="http://secunia.com/advisories/13986" source="SECUNIA">13986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ursoftware" name="w32dasm">
        <vers num="8.94"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0309" published="2005-01-25" name="CVE-2005-0309" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19061" source="XF" adv="1">exponent-module-xss(19061)</ref>
      <ref url="http://www.securityfocus.com/bid/12358" source="BID" adv="1">12358</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110666998407073&amp;w=2" source="BUGTRAQ" adv="1">20050125 Vulnerabilities in eXponent 0.95</ref>
      <ref url="http://www.osvdb.org/13190" source="OSVDB">13190</ref>
      <ref url="http://www.osvdb.org/13188" source="OSVDB">13188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exponent" name="exponent">
        <vers num="0.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0310" published="2005-05-02" name="CVE-2005-0310" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19064" source="XF">exponent-pathoscoreversion-path-disclosure(19064)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110666998407073&amp;w=2" source="BUGTRAQ" adv="1">20050125 Vulnerabilities in eXponent 0.95</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exponent" name="exponent">
        <vers num="0.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0311" published="2005-05-02" name="CVE-2005-0311" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19123" source="XF">ingate-firewall-unath-access(19123)</ref>
      <ref url="http://www.securityfocus.com/bid/12383" source="BID">12383</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110684375429946&amp;w=2" source="BUGTRAQ" adv="1">20050127 Ingate Firewall: Removed PPTP tunnels not deactivated</ref>
      <ref url="http://www.ingate.com/relnote-422.php" source="CONFIRM">http://www.ingate.com/relnote-422.php</ref>
      <ref url="http://securitytracker.com/id?1013022" source="SECTRACK">1013022</ref>
      <ref url="http://secunia.com/advisories/14060" source="SECUNIA">14060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ingate" name="ingate_firewall">
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.3.1"/>
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0312" published="2005-01-27" name="CVE-2005-0312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12384" source="BID" patch="1" adv="1">12384</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110687202332039&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050127 WarFTPD 1.82 RC9 DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19129" source="XF">warftpd-cwd-dos(19129)</ref>
      <ref url="http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643" source="CONFIRM" adv="1">http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="war_ftp_daemon" name="war_ftp_daemon">
        <vers num="1.8"/>
        <vers num="1.82_rc9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0313" published="2005-01-27" name="CVE-2005-0313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19114" source="XF" patch="1" adv="1">magic-winmail-command-directory-traversal(19114)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19108" source="XF" patch="1" adv="1">magicwinmail-uploadphp-file-upload(19108)</ref>
      <ref url="http://www.securityfocus.com/bid/12388" source="BID" patch="1" adv="1">12388</ref>
      <ref url="http://securitytracker.com/id?1013017" source="SECTRACK">1013017</ref>
      <ref url="http://secunia.com/advisories/14053" source="SECUNIA">14053</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" source="BUGTRAQ" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amax_information_technologies" name="magic_winmail_server">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0314" published="2005-01-27" name="CVE-2005-0314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19113" source="XF" patch="1" adv="1">magic-winmail-userphp-xss(19113)</ref>
      <ref url="http://www.securityfocus.com/bid/12388" source="BID" patch="1" adv="1">12388</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1013017" source="SECTRACK">1013017</ref>
      <ref url="http://secunia.com/advisories/14053" source="SECUNIA">14053</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0315" published="2005-01-27" name="CVE-2005-0315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19115" source="XF" patch="1" adv="1">magicwinmail-ftp-obtain-information(19115)</ref>
      <ref url="http://www.securityfocus.com/bid/12388" source="BID" patch="1" adv="1">12388</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1013017" source="SECTRACK">1013017</ref>
      <ref url="http://secunia.com/advisories/14053" source="SECUNIA">14053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amax_information_technologies" name="magic_winmail_server">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0316" published="2005-01-28" name="CVE-2005-0316" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12394" source="BID" patch="1" adv="1">12394</ref>
      <ref url="http://secunia.com/advisories/14058" source="SECUNIA" patch="1" adv="1">14058</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19144" source="XF" adv="1">webwasher-classic-connect-gain-access(19144)</ref>
      <ref url="http://www.oliverkarow.de/research/WebWasherCONNECT.txt" source="MISC" adv="1">http://www.oliverkarow.de/research/WebWasherCONNECT.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693045507245&amp;w=2" source="BUGTRAQ" adv="1">20050128 WebWasher Classic - HTTP CONNECT weakness</ref>
      <ref url="http://securitytracker.com/id?1013036" source="SECTRACK">1013036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webwasher" name="webwasher_classic">
        <vers num="2.2.1"/>
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0317" published="2005-01-28" name="CVE-2005-0317" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19161" source="XF" patch="1" adv="1">webadmin-usereditaccountwdm-xss(19161)</ref>
      <ref url="http://www.securityfocus.com/bid/12395" source="BID" patch="1" adv="1">12395</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
      <ref url="http://securitytracker.com/id?1013038" source="SECTRACK">1013038</ref>
      <ref url="http://secunia.com/advisories/14079" source="SECUNIA">14079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num="3.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0318" published="2005-01-28" name="CVE-2005-0318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12395" source="BID" patch="1">12395</ref>
      <ref url="http://securitytracker.com/id?1013038" source="SECTRACK">1013038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num="3.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0319" published="2005-01-28" name="CVE-2005-0319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12395" source="BID" patch="1" adv="1">12395</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19162" source="XF" adv="1">webadmin-html-injection(19162)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num="3.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0320" published="2005-01-28" name="CVE-2005-0320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12396" source="BID" patch="1" adv="1">12396</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19147" source="XF" adv="1">merak-icewarp-multiple-xss(19147)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0321" published="2005-05-02" name="CVE-2005-0321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allows remote authenticated users to gain sensitive information via an HTTP request to (1) calendar_d.html, (2) calendar_m.html, (3) calendar_w.html, or (4) calendar_y.html, which reveal the installation path.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19152" source="XF">merak-icewarp-user-path-disclosure(19152)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.3.0"/>
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="7.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0322" published="2005-05-02" name="CVE-2005-0322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19153" source="XF">merak-icewarp-weak-password-encryption(19153)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2" source="BUGTRAQ" adv="1">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.3.0"/>
        <vers num="5.3.2"/>
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="7.6.0"/>
        <vers num="7.6.4r"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0323" published="2005-05-02" name="CVE-2005-0323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19151" source="XF">infinite-mobile-delivery-xss(19151)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110703630922262&amp;w=2" source="BUGTRAQ" adv="1">20050129 XSS in Infinite Mobile Delivery v2.6 Webmail</ref>
      <ref url="http://www.securityfocus.com/bid/12399" source="BID">12399</ref>
      <ref url="http://www.lovebug.org/imd_advisory.txt" source="MISC">http://www.lovebug.org/imd_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1013044" source="SECTRACK">1013044</ref>
      <ref url="http://secunia.com/advisories/14075" source="SECUNIA">14075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="captaris" name="infinite_mobile_delivery_webmail">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0324" published="2005-05-02" name="CVE-2005-0324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19154" source="XF">infinite-mobile-delivery-path-disclosure(19154)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110703630922262&amp;w=2" source="BUGTRAQ">20050129 XSS in Infinite Mobile Delivery v2.6 Webmail</ref>
      <ref url="http://www.securityfocus.com/bid/12399" source="BID">12399</ref>
      <ref url="http://www.lovebug.org/imd_advisory.txt" source="MISC">http://www.lovebug.org/imd_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1013044" source="SECTRACK">1013044</ref>
      <ref url="http://secunia.com/advisories/14075" source="SECUNIA">14075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="captaris" name="infinite_mobile_delivery_webmail">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0325" published="2005-05-02" name="CVE-2005-0325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large values that are not properly handled in certain malloc or memcpy operations.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19150" source="XF" patch="1">xpand-rally-memory-dos(19150)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031336.html" source="FULLDISC" patch="1">20050130 Broadcast crash in Xpand Rally 1.0.0.0</ref>
      <ref url="http://aluigi.altervista.org/adv/xprallyboom-adv.txt" source="MISC" patch="1">http://aluigi.altervista.org/adv/xprallyboom-adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12409" source="BID">12409</ref>
      <ref url="http://securitytracker.com/id?1013043" source="SECTRACK">1013043</ref>
      <ref url="http://secunia.com/advisories/14073" source="SECUNIA">14073</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720064811485&amp;w=2" source="BUGTRAQ">20050130 Broadcast crash in Xpand Rally 1.0.0.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="techland" name="xpand_rally">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0326" published="2005-05-02" name="CVE-2005-0326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720365923818&amp;w=2" source="BUGTRAQ" patch="1">20050131 [PersianHacker.net] Full Path Disclosure and PHP Injection In Pafiledb 3.1 Final</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19175" source="XF">pafiledb-login-path-disclosure(19175)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0327" published="2005-05-02" name="CVE-2005-0327" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19176" source="XF">pafiledb-login-file-include(19176)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720365923818&amp;w=2" source="BUGTRAQ">20050131 [PersianHacker.net] Full Path Disclosure and PHP Injection In Pafiledb 3.1 Final</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0328" published="2005-05-02" name="CVE-2005-0328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN's MAC address.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20609" source="XF">zyxel-netgear-ping-information-disclosure(20609)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720465527599&amp;w=2" source="BUGTRAQ" adv="1">20050131 Zyxel / Netgear and probably other routers leaking information.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="rt311">
        <vers num=""/>
      </prod>
      <prod vendor="netgear" name="rt314">
        <vers num=""/>
      </prod>
      <prod vendor="zyxel" name="prestige">
        <vers num="310"/>
        <vers num="314"/>
        <vers num="324"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0329" published="2005-05-02" name="CVE-2005-0329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ZipGenius 5.5 and earlier allows remote attackers to create and possibly modify arbitrary files via a ZIP file with a file whose name includes .. (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12419" source="BID" patch="1">12419</ref>
      <ref url="http://securitytracker.com/id?1013542" source="SECTRACK" patch="1">1013542</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110736990230696&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050202 7a69Adv#19 - ZipGenius unpack path disclosure</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19203" source="XF">zipgenius-path-disclosure(19203)</ref>
      <ref url="http://secunia.com/advisories/14123" source="SECUNIA">14123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zipgenius" name="zipgenius">
        <vers num="standard_5.5"/>
        <vers num="suite_5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0330" published="2005-05-02" name="CVE-2005-0330" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in Painkiller 1.35 and earlier, and possibly other versions before 1.61, allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a long cd-key hash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19205" source="XF" patch="1">painkiller-long-cdkey-bo(19205)</ref>
      <ref url="http://www.securityfocus.com/bid/12423" source="BID" patch="1">12423</ref>
      <ref url="http://secunia.com/advisories/14113/" source="SECUNIA" patch="1">14113</ref>
      <ref url="http://securitytracker.com/id?1013066" source="SECTRACK">1013066</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110736915015707&amp;w=2" source="BUGTRAQ">20050202 Limited buffer-overflow in Painkiller 1.35</ref>
    </refs>
    <vuln_soft>
      <prod vendor="people_can_fly" name="painkiller">
        <vers num="1.3.1"/>
        <vers num="1.3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0331" published="2005-05-02" name="CVE-2005-0331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20585" source="XF">winrar-dotdotdotdirectory-traversal(20585)</ref>
      <ref url="http://www.securityfocus.com/bid/12422" source="BID">12422</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737609604210&amp;w=2" source="BUGTRAQ" adv="1">20050202 7a69Adv#21 - WinRAR unpack one-folder path disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rarlab" name="winrar">
        <vers num="3.0.0"/>
        <vers num="3.10"/>
        <vers num="3.10_beta3"/>
        <vers num="3.10_beta5"/>
        <vers num="3.11"/>
        <vers num="3.20"/>
        <vers num="3.40"/>
        <vers num="3.41"/>
        <vers num="3.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0332" published="2005-05-02" name="CVE-2005-0332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19211" source="XF" patch="1">desknow-jsp-gain-access(19211)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19206" source="XF" patch="1">desknow-attachmentkey-file-upload(19206)</ref>
      <ref url="http://www.securityfocus.com/bid/12421" source="BID" patch="1">12421</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19212" source="XF">desknow-filedo-file-deletion(19212)</ref>
      <ref url="http://www.security.org.sg/vuln/desknow2512.html" source="MISC" adv="1">http://www.security.org.sg/vuln/desknow2512.html</ref>
      <ref url="http://securitytracker.com/id?1013060" source="SECTRACK">1013060</ref>
      <ref url="http://secunia.com/advisories/14116" source="SECUNIA">14116</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737616324614&amp;w=2" source="BUGTRAQ" adv="1">20050202 [SIG^2 G-TEC] DeskNow Mail and Collaboration Server Directory Traversal Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ventia" name="desknow_mail_and_collaboration_server">
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0333" published="2005-05-02" name="CVE-2005-0333" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LANChat Pro Revival 1.666c allows remote attackers to cause a denial of service (application crash) via a malformed UDP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19213" source="XF">lanchatpro-udp-packet-dos(19213)</ref>
      <ref url="http://www.securityfocus.com/bid/12439" source="BID">12439</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/LANChatRevival1.666c-adv.txt" source="MISC" adv="1">http://www.autistici.org/fdonato/advisory/LANChatRevival1.666c-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746524021133&amp;w=2" source="BUGTRAQ" adv="1">20050203 DoS in LANChat Pro Revival 1.666c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lanchat_pro_revival" name="lanchat_pro_revival">
        <vers num="1.666c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0334" published="2005-05-02" name="CVE-2005-0334" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linksys PSUS4 running firmware 6032 allows remote attackers to cause a denial of service (device crash) via an HTTP POST request containing an unknown parameter without a value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19222" source="XF">linksys-psus4-dos(19222)</ref>
      <ref url="http://www.securityfocus.com/bid/12443" source="BID">12443</ref>
      <ref url="http://secunia.com/advisories/14136" source="SECUNIA" adv="1">14136</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110747234701646&amp;w=2" source="BUGTRAQ" adv="1">20050203 [ RSTACK Public Security Advisory ] Remote DOS against Linksys PSUS4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="psus4_printserver">
        <vers num="6032"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0335" published="2005-05-02" name="CVE-2005-0335" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18842" source="XF">mediapartner-dotdot-directory-traversal(18842)</ref>
      <ref url="http://www.securityfocus.com/bid/12236" source="BID">12236</ref>
      <ref url="http://securitytracker.com/id?1012838" source="SECTRACK">1012838</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547214224714&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-010</ref>
      <ref url="http://secunia.com/advisories/13820" source="SECUNIA">13820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emotion" name="mediapartner_web_server">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0336" published="2005-05-02" name="CVE-2005-0336" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to inject arbitrary HTML or web script, as demonstrated using a URL containing .. sequences and HTML, which results in a directory browsing page that does not properly filter the HTML.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18845" source="XF">mediapartner-url-xss(18845)</ref>
      <ref url="http://www.securityfocus.com/bid/12236" source="BID">12236</ref>
      <ref url="http://securitytracker.com/id?1012838" source="SECTRACK">1012838</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547214224714&amp;w=2" source="BUGTRAQ" adv="1">20050110 Portcullis Security Advisory 05-010</ref>
      <ref url="http://secunia.com/advisories/13820" source="SECUNIA">13820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emotion" name="mediapartner_web_server">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0337" published="2005-05-02" name="CVE-2005-0337" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19218" source="XF" patch="1">postfix-ipv6-security-bypass(19218)</ref>
      <ref url="http://www.securityfocus.com/bid/12445" source="BID" patch="1">12445</ref>
      <ref url="http://secunia.com/advisories/14137/" source="SECUNIA" patch="1">14137</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763358832637&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050204 [USN-74-1] Postfix vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11339" source="OVAL">oval:org.mitre.oval:def:11339</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=267837" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=267837</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-152.html" source="REDHAT">RHSA-2005:152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wietse_venema" name="postfix">
        <vers num="2.1.3"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0338" published="2005-05-02" name="CVE-2005-0338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19177" source="XF">savant-bo(19177)</ref>
      <ref url="http://www.securityfocus.com/bid/12429" source="BID">12429</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110728448025559&amp;w=2" source="FULLDISC">20050201 Remotely exploitable buffer overflow vulnerability in Savant Web Server 3.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110725682327452&amp;w=2" source="FULLDISC" adv="1">20050201 Remotely exploitable buffer overflow vulnerability in Savant Web Server 3.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110756234611259&amp;w=2" source="BUGTRAQ">20050204 Exploit For Savant Web Server 3.1 (tested on win2003)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="savant" name="savant_webserver">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0339" published="2005-05-02" name="CVE-2005-0339" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19229" source="XF">foxmail-mailfrom-bo(19229)</ref>
      <ref url="http://www.securityfocus.com/bid/12454" source="BID">12454</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763204301080&amp;w=2" source="BUGTRAQ" adv="1">20050205 Foxmail Server Remote Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxmail" name="foxmail_email_server">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0340" published="2005-05-02" name="CVE-2005-0340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" patch="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19263" source="XF">Applefileserver-fploginext-dos(19263)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110791369419784&amp;w=2" source="BUGTRAQ" adv="1">20050208 AppleFileServer Denial of Service.</ref>
      <ref url="http://www.securityfocus.com/bid/12478" source="BID">12478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="afp_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0341" published="2005-05-02" name="CVE-2005-0341" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19227" source="XF">safari-contenttype-xss(19227)</ref>
      <ref url="http://tigger.uic.edu/~jrockw2/safari_20050204.txt" source="MISC" adv="1">http://tigger.uic.edu/~jrockw2/safari_20050204.txt</ref>
      <ref url="http://securitytracker.com/id?1013087" source="SECTRACK">1013087</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110756965213819&amp;w=2" source="BUGTRAQ" adv="1">20050204 Input Validation Vulnerability in Apple Safari version 1.2.4 v125.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0342" published="2005-05-02" name="CVE-2005-0342" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14188" source="SECUNIA" patch="1" adv="1">14188</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19253" source="XF">finder-dsstore-file-overwrite(19253)</ref>
      <ref url="http://www.securityfocus.com/bid/12458" source="BID">12458</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780124707975&amp;w=2" source="BUGTRAQ" adv="1">20050207 [OSX Finder] DS_Store arbitrary file overwrite vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0343" published="2005-05-02" name="CVE-2005-0343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12471" source="BID" patch="1">12471</ref>
      <ref url="http://secunia.com/advisories/12512" source="SECUNIA" patch="1">12512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19245" source="XF">perldesk-view-sql-injection(19245)</ref>
      <ref url="http://www.security-project.org/projects/board/showthread.php?p=5172#post5172" source="MISC" adv="1">http://www.security-project.org/projects/board/showthread.php?p=5172#post5172</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782042532295&amp;w=2" source="BUGTRAQ" adv="1">20050207 [SePro Bugtraq] SQL-Injection in PerlDesk 1.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logicnow" name="perldesk">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0344" published="2005-05-02" name="CVE-2005-0344" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.security.org.sg/vuln/602lansuite1221.html" source="MISC" patch="1" adv="1">http://www.security.org.sg/vuln/602lansuite1221.html</ref>
      <ref url="http://secunia.com/advisories/14169/" source="SECUNIA" patch="1" adv="1">14169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110793103506620&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050208 [SIG^2 G-TEC] 602LAN SUITE Web Mail Vulnerability Allows File Upload to Arbitrary Directories</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19258" source="XF">602lansuite-webmail-directory-traversal(19258)</ref>
      <ref url="http://securitytracker.com/id?1013106" source="SECTRACK">1013106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602lan_suite">
        <vers num="2004.0.04.1221"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0345" published="2005-05-02" name="CVE-2005-0345" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19257" source="XF">phpfusion-viewthread-obtain-information(19257)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110788267311132&amp;w=2" source="BUGTRAQ" adv="1">20050208 php-fusion 4.x vuln</ref>
      <ref url="http://www.securityfocus.com/bid/12482" source="BID">12482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0346" published="2005-05-02" name="CVE-2005-0346" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19256" source="XF">softremote-vpn-password-disclosure(19256)</ref>
      <ref url="http://www.nta-monitor.com/news/vpn-flaws/safenet/index.htm" source="MISC" adv="1">http://www.nta-monitor.com/news/vpn-flaws/safenet/index.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110791865522076&amp;w=2" source="BUGTRAQ" adv="1">20050208 SafeNet SoftRemote VPN Client Issue: Clear-text password</ref>
      <ref url="http://securitytracker.com/id?1013134" source="SECTRACK">1013134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="safenet" name="softremote_vpn_client">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0347" published="2005-05-02" name="CVE-2005-0347" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in RealArcade 1.2.0.994 and earlier allows remote attackers to execute arbitrary code via an RGS file with an invalid size string for the GUID and game name, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19259" source="XF">realarcade-rgs-bo(19259)</ref>
      <ref url="http://secunia.com/advisories/14187/" source="SECUNIA" adv="1">14187</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792779115794&amp;w=2" source="BUGTRAQ">20050208 Integer overflow and arbitrary files deletion in RealArcade</ref>
      <ref url="http://securitytracker.com/id?1013128" source="SECTRACK">1013128</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0348" published="2005-05-02" name="CVE-2005-0348" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RealArcade 1.2.0.994 allows remote attackers to delete arbitrary files via an RGP file with a .. (dot dot) in the FILENAME tag.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19260" source="XF">realarcade-rgp-file-deletion(19260)</ref>
      <ref url="http://www.securityfocus.com/bid/12494" source="BID">12494</ref>
      <ref url="http://secunia.com/advisories/14187/" source="SECUNIA" adv="1">14187</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792779115794&amp;w=2" source="BUGTRAQ">20050208 Integer overflow and arbitrary files deletion in RealArcade</ref>
      <ref url="http://securitytracker.com/id?1013128" source="SECTRACK">1013128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realarcade">
        <vers prev="1" num="1.2.0.994"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0349" published="2005-05-02" name="CVE-2005-0349" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The production release of the UniversalAgent for UNIX in BrightStor ARCserve Backup 11.1 contains hard-coded credentials, which allows remote attackers to access the file system and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=198&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050210 Computer Associates BrightStor ARCserve Backup UniversalAgent Backdoor Vulnerability</ref>
      <ref url="http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO63672&amp;os=UNIX&amp;returninput=0" source="CONFIRM" patch="1" adv="1">http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO63672&amp;os=UNIX&amp;returninput=0</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0145" source="VUPEN">ADV-2005-0145</ref>
      <ref url="http://www.securityfocus.com/bid/12522" source="BID">12522</ref>
      <ref url="http://www.osvdb.org/13706" source="OSVDB">13706</ref>
      <ref url="http://securitytracker.com/id?1013144" source="SECTRACK">1013144</ref>
      <ref url="http://secunia.com/advisories/14233" source="SECUNIA">14233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0350" published="2005-05-02" name="CVE-2005-0350" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/alerts/id/188" source="ISS" patch="1" adv="1">20050210 F-Secure AntiVirus Library Heap Overflow</ref>
      <ref url="http://www.f-secure.com/security/fsc-2005-1.shtml" source="CONFIRM" patch="1">http://www.f-secure.com/security/fsc-2005-1.shtml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2004"/>
        <vers num="2005"/>
        <vers prev="1" num="4.52" edition=""/>
        <vers prev="1" num="4.52" edition=":linux_workstations"/>
        <vers num="4.60" edition=""/>
        <vers num="4.60" edition=":samba_servers"/>
        <vers prev="1" num="4.61" edition=""/>
        <vers prev="1" num="4.61" edition=":linux_servers"/>
        <vers prev="1" num="4.61" edition=":linux_gateways"/>
        <vers prev="1" num="5.01" edition=""/>
        <vers prev="1" num="5.01" edition=":linux_server_security"/>
        <vers prev="1" num="5.01" edition=":linux_client_security"/>
        <vers prev="1" num="5.43" edition=""/>
        <vers prev="1" num="5.43" edition=":workstations"/>
        <vers prev="1" num="5.5" edition=""/>
        <vers prev="1" num="5.5" edition=":windows_servers"/>
        <vers prev="1" num="5.5" edition=":citrix_servers"/>
        <vers prev="1" num="5.51" edition=""/>
        <vers prev="1" num="5.51" edition=":mimesweeper"/>
        <vers prev="1" num="5.55" edition=""/>
        <vers prev="1" num="5.55" edition=":client_security"/>
        <vers prev="1" num="6.2" edition=""/>
        <vers prev="1" num="6.2" edition=":firewalls"/>
        <vers prev="1" num="6.31" edition=""/>
        <vers prev="1" num="6.31" edition=":ms_exchange"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2004"/>
        <vers num="2005"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_personal_express">
        <vers prev="1" num="5.10"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="2.06" edition=""/>
        <vers num="2.06" edition=":linux"/>
        <vers prev="1" num="6.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0351" published="2005-04-07" name="CVE-2005-0351" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.15/SCOSA-2005.15.txt" source="SCO" patch="1" adv="1">SCOSA-2005.15</ref>
      <ref url="http://www.securityfocus.com/bid/13062" source="BID">13062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0352" published="2005-03-16" name="CVE-2005-0352" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19715" source="XF" adv="1">serversalive-gain-privileges(19715)</ref>
      <ref url="http://www.securityfocus.com/bid/12822" source="BID" adv="1">12822</ref>
      <ref url="http://secunia.com/advisories/14616/" source="SECUNIA" adv="1">14616</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100364513513&amp;w=2" source="BUGTRAQ" adv="1">20050316 Servers Alive: Local Privilege Escalation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woodstone" name="servers_alive">
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0353" published="2005-05-02" name="CVE-2005-0353" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/108790" source="CERT-VN" patch="1" adv="1">VU#108790</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-30-advisory.pdf" source="MISC" patch="1" adv="1">http://www.cirt.dk/advisories/cirt-30-advisory.pdf</ref>
      <ref url="http://secunia.com/advisories/14511" source="SECUNIA" patch="1" adv="1">14511</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19621" source="XF">sentinel-license-manager-bo(19621)</ref>
      <ref url="http://www.securityfocus.com/bid/12742" source="BID">12742</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111072872816405&amp;w=2" source="FULLDISC" adv="1">20050313 [HAT-SQUAD]  SafeNet Sentinel LM, UDP License Manager Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022094326772&amp;w=2" source="BUGTRAQ" adv="1">20050307 CIRT.DK Advisory - SafeNet Inc Sentinel License Manager 7.2.0.2 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="safenet" name="sentinel_license_manager">
        <vers num="7.2_.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0356" published="2005-05-31" name="CVE-2005-0356" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/637934" source="CERT-VN" adv="1">VU#637934</ref>
      <ref url="http://secunia.com/advisories/15417/" source="SECUNIA" patch="1">15417</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20635" source="XF">tcp-ip-timestamp-dos(20635)</ref>
      <ref url="http://www.securityfocus.com/bid/13676" source="BID">13676</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtml" source="CISCO" adv="1">20050518 Vulnerability in a Variant of the TCP Timestamps Option</ref>
      <ref url="http://secunia.com/advisories/15393" source="SECUNIA">15393</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-032.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-032.htm</ref>
      <ref url="http://secunia.com/advisories/18662" source="SECUNIA">18662</ref>
      <ref url="http://secunia.com/advisories/18222" source="SECUNIA">18222</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txt" source="SCO">SCOSA-2005.64</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc" source="FREEBSD">FreeBSD-SA-05:15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="agent_desktop">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_access_control_list_manager">
        <vers num="1.5"/>
        <vers num="1.6"/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="2.2"/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_lms">
        <vers num="1.3"/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_vpn_security_management_solution">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_windows">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="e-mail_manager">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="emergency_responder">
        <vers num="1.1"/>
      </prod>
      <prod vendor="cisco" name="intelligent_contact_manager">
        <vers num="5.0"/>
      </prod>
      <prod vendor="cisco" name="interactive_voice_response">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ip_contact_center_enterprise">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ip_contact_center_express">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="meetingplace">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="personal_assistant">
        <vers num="1.3(1)"/>
        <vers num="1.3(2)"/>
        <vers num="1.3(3)"/>
        <vers num="1.3(4)"/>
        <vers num="1.4(1)"/>
        <vers num="1.4(2)"/>
      </prod>
      <prod vendor="cisco" name="remote_monitoring_suite_option">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":unix"/>
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":windows_nt"/>
        <vers num="2.3" edition=""/>
        <vers num="2.3" edition=":unix"/>
        <vers num="2.3" edition=":windows_nt"/>
        <vers num="2.3.5.1" edition=""/>
        <vers num="2.3.5.1" edition=":unix"/>
        <vers num="2.3.6.1" edition=""/>
        <vers num="2.3.6.1" edition=":unix"/>
        <vers num="2.4" edition=""/>
        <vers num="2.4" edition=":windows_nt"/>
        <vers num="2.42" edition=""/>
        <vers num="2.42" edition=":windows_nt"/>
        <vers num="2.5" edition=""/>
        <vers num="2.5" edition=":windows_nt"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":windows_nt"/>
        <vers num="2.6.2" edition=""/>
        <vers num="2.6.2" edition=":windows_nt"/>
        <vers num="2.6.3" edition=""/>
        <vers num="2.6.3" edition=":windows_nt"/>
        <vers num="2.6.4" edition=""/>
        <vers num="2.6.4" edition=":windows_nt"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":windows_nt"/>
        <vers num="3.0.1" edition=""/>
        <vers num="3.0.1" edition=":windows_nt"/>
        <vers num="3.0.3" edition=""/>
        <vers num="3.0.3" edition=":windows_nt"/>
        <vers num="3.1"/>
        <vers num="3.1.1" edition=""/>
        <vers num="3.1.1" edition=":windows_nt"/>
        <vers num="3.2" edition=""/>
        <vers num="3.2" edition=":windows_server"/>
        <vers num="3.2(1)"/>
        <vers num="3.2(1.20)"/>
        <vers num="3.2(2)"/>
        <vers num="3.2(3)"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.3"/>
        <vers num="3.3(1)"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
      </prod>
      <prod vendor="cisco" name="secure_access_control_server_solution_engine">
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
      </prod>
      <prod vendor="cisco" name="support_tools">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="web_collaboration_option">
        <vers num=""/>
      </prod>
      <prod vendor="f5" name="big-ip">
        <vers num="4.0"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.5.10"/>
        <vers num="4.5.11"/>
        <vers num="4.5.12"/>
        <vers num="4.5.6"/>
        <vers num="4.5.9"/>
        <vers num="4.6"/>
        <vers num="4.6.2"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.0.4"/>
        <vers num="9.0.5"/>
      </prod>
      <prod vendor="hitachi" name="alaxala">
        <vers num="ax"/>
      </prod>
      <prod vendor="nortel" name="business_communications_manager">
        <vers num="1000"/>
        <vers num="200"/>
        <vers num="400"/>
      </prod>
      <prod vendor="nortel" name="callpilot">
        <vers num="200i"/>
        <vers num="201i"/>
        <vers num="702t"/>
        <vers num="703t"/>
      </prod>
      <prod vendor="nortel" name="contact_center">
        <vers num=""/>
      </prod>
      <prod vendor="alaxala" name="alaxala_networks">
        <vers num="ax5400s"/>
        <vers num="ax7800r"/>
        <vers num="ax7800s"/>
      </prod>
      <prod vendor="cisco" name="aironet_ap1200">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="aironet_ap350">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1(2)"/>
        <vers num="3.1(3a)"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3(3)"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11050">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11150">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11501">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11503">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11506">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11800">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="sn_5420_storage_router">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="unity_server">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.46"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="hitachi" name="gr3000">
        <vers num=""/>
      </prod>
      <prod vendor="hitachi" name="gr4000">
        <vers num=""/>
      </prod>
      <prod vendor="hitachi" name="gs4000">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="7220_wlan_access_point">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="7250_wlan_access_point">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="ethernet_routing_switch_1612">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="ethernet_routing_switch_1624">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="ethernet_routing_switch_1648">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="optical_metro_5000">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="optical_metro_5100">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="optical_metro_5200">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="succession_communication_server_1000">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="survivable_remote_gateway">
        <vers num="1.0"/>
      </prod>
      <prod vendor="nortel" name="universal_signaling_point">
        <vers num="5200"/>
        <vers num="compact_lite"/>
      </prod>
      <prod vendor="yamaha" name="rt105">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt250i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt300i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt57i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtv700">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtx1000">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtx1100">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtx1500">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtx2000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_1105_hosting_solution_engine">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_1105_wireless_lan_solution_engine">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_cd1">
        <vers num="1st"/>
        <vers num="2nd"/>
        <vers num="3rd"/>
        <vers num="4th"/>
        <vers num="5th"/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_windows_wug">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="conference_connection">
        <vers num="1.1(1)"/>
        <vers num="1.2"/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="7.10_(05.07)s"/>
        <vers num="7.20_(03.09)s"/>
        <vers num="7.20_(03.10)s"/>
        <vers num="7.30_(00.08)s"/>
        <vers num="7.30_(00.09)s"/>
      </prod>
      <prod vendor="cisco" name="mgx_8230">
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
      </prod>
      <prod vendor="cisco" name="mgx_8250">
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
      </prod>
      <prod vendor="cisco" name="sn_5420_storage_router">
        <vers num="1.1(2)"/>
        <vers num="1.1(3)"/>
        <vers num="1.1(4)"/>
        <vers num="1.1(5)"/>
        <vers num="1.1(7)"/>
        <vers num="1.1.3"/>
      </prod>
      <prod vendor="cisco" name="sn_5428_storage_router">
        <vers num="2-3.3.1-k9"/>
        <vers num="2-3.3.2-k9"/>
        <vers num="2.5.1-k9"/>
        <vers num="3.2.1-k9"/>
        <vers num="3.2.2-k9"/>
        <vers num="3.3.1-k9"/>
        <vers num="3.3.2-k9"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0" edition="releng"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5" edition="stable"/>
        <vers num="3.5.1" edition="release"/>
        <vers num="3.5.1" edition="stable"/>
        <vers num="4.0" edition="alpha"/>
        <vers num="4.0" edition="releng"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
        <vers num="4.1.1" edition="stable"/>
        <vers num="4.10" edition="release"/>
        <vers num="4.10" edition="release_p8"/>
        <vers num="4.10" edition="releng"/>
        <vers num="4.11" edition="release_p3"/>
        <vers num="4.11" edition="releng"/>
        <vers num="4.11" edition="stable"/>
        <vers num="4.2" edition="stable"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.3" edition="release_p38"/>
        <vers num="4.3" edition="releng"/>
        <vers num="4.3" edition="stable"/>
        <vers num="4.4" edition="release_p42"/>
        <vers num="4.4" edition="releng"/>
        <vers num="4.4" edition="stable"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.5" edition="release_p32"/>
        <vers num="4.5" edition="releng"/>
        <vers num="4.5" edition="stable"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.6" edition="release_p20"/>
        <vers num="4.6" edition="releng"/>
        <vers num="4.6" edition="stable"/>
        <vers num="4.6.2"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.7" edition="release_p17"/>
        <vers num="4.7" edition="releng"/>
        <vers num="4.7" edition="stable"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="4.8" edition="release_p6"/>
        <vers num="4.8" edition="releng"/>
        <vers num="4.9" edition="pre-release"/>
        <vers num="4.9" edition="releng"/>
        <vers num="5.0" edition="alpha"/>
        <vers num="5.0" edition="release_p14"/>
        <vers num="5.0" edition="releng"/>
        <vers num="5.1" edition="alpha"/>
        <vers num="5.1" edition="release"/>
        <vers num="5.1" edition="release_p5"/>
        <vers num="5.1" edition="releng"/>
        <vers num="5.2"/>
        <vers num="5.2.1" edition="release"/>
        <vers num="5.2.1" edition="releng"/>
        <vers num="5.3" edition="release"/>
        <vers num="5.3" edition="releng"/>
        <vers num="5.3" edition="stable"/>
        <vers num="5.4" edition="pre-release"/>
        <vers num="5.4" edition="release"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:advanced_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="standard_64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0357" published="2005-08-23" name="CVE-2005-0357" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/606857" source="CERT-VN" patch="1" adv="1">VU#606857</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21887" source="XF" patch="1">legato-authunix-bypass-authentication(21887)</ref>
      <ref url="http://www.securityfocus.com/bid/14582" source="BID" patch="1">14582</ref>
      <ref url="http://www.legato.com/support/websupport/product_alerts/081605_NW_authentication.htm" source="CONFIRM" patch="1">http://www.legato.com/support/websupport/product_alerts/081605_NW_authentication.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1" source="SUNALERT" patch="1" adv="1">101886</ref>
      <ref url="http://securitytracker.com/id?1014713" source="SECTRACK" patch="1">1014713</ref>
      <ref url="http://secunia.com/advisories/16464" source="SECUNIA" patch="1" adv="1">16464</ref>
      <ref url="http://www.osvdb.org/18800" source="OSVDB">18800</ref>
      <ref url="http://secunia.com/advisories/16470" source="SECUNIA" adv="1">16470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="legato_networker">
        <vers num="4.2.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.13"/>
        <vers num="7.2"/>
      </prod>
      <prod vendor="sun" name="solstice_backup">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
      <prod vendor="sun" name="storedge_enterprise_backup_software">
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0358" published="2005-08-23" name="CVE-2005-0358" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/407641" source="CERT-VN" patch="1" adv="1">VU#407641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21892" source="XF" patch="1">legato-token-gain-privileges(21892)</ref>
      <ref url="http://www.securityfocus.com/bid/14582" source="BID" patch="1" adv="1">14582</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1" source="SUNALERT" patch="1" adv="1">101886</ref>
      <ref url="http://securitytracker.com/id?1014713" source="SECTRACK" patch="1">1014713</ref>
      <ref url="http://secunia.com/advisories/16464" source="SECUNIA" patch="1" adv="1">16464</ref>
      <ref url="http://www.osvdb.org/18801" source="OSVDB">18801</ref>
      <ref url="http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm" source="CONFIRM">http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm</ref>
      <ref url="http://secunia.com/advisories/16470" source="SECUNIA" adv="1">16470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="legato_networker">
        <vers num="4.2.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.13"/>
        <vers num="7.2"/>
      </prod>
      <prod vendor="sun" name="solstice_backup">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
      <prod vendor="sun" name="storedge_enterprise_backup_software">
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0359" published="2005-08-23" name="CVE-2005-0359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/801089" source="CERT-VN" patch="1" adv="1">VU#801089</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21893" source="XF" patch="1">legato-portmapper-obtain-information(21893)</ref>
      <ref url="http://www.securityfocus.com/bid/14582" source="BID" patch="1">14582</ref>
      <ref url="http://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htm" source="CONFIRM" patch="1">http://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1" source="SUNALERT" patch="1" adv="1">101886</ref>
      <ref url="http://securitytracker.com/id?1014713" source="SECTRACK" patch="1">1014713</ref>
      <ref url="http://secunia.com/advisories/16464" source="SECUNIA" patch="1" adv="1">16464</ref>
      <ref url="http://www.osvdb.org/18802" source="OSVDB">18802</ref>
      <ref url="http://secunia.com/advisories/16470" source="SECUNIA" adv="1">16470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="legato_networker">
        <vers num="4.2.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.13"/>
        <vers num="7.2"/>
      </prod>
      <prod vendor="sun" name="solstice_backup">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
      <prod vendor="sun" name="storedge_enterprise_backup_software">
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0360" published="2005-07-05" name="CVE-2005-0360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/165022" source="CERT-VN" patch="1" adv="1">VU#165022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="log_sink_class_activex_control">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0362" published="2005-02-09" name="CVE-2005-0362" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488</ref>
      <ref url="http://www.osvdb.org/16089" source="OSVDB">16089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0363" published="2005-05-02" name="CVE-2005-0363" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-682" source="DEBIAN" patch="1" adv="1">DSA-682</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="4.0"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0364" published="2005-02-10" name="CVE-2005-0364" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19276" source="XF" patch="1" adv="1">hpux-bind-dos(19276)</ref>
      <ref url="http://secunia.com/advisories/14220/" source="SECUNIA" patch="1" adv="1">14220</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805105200470&amp;w=2" source="HP" patch="1" adv="1">HPSBUX01117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5690" source="OVAL">oval:org.mitre.oval:def:5690</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00"/>
        <vers num="11.11"/>
        <vers num="11.23" edition=""/>
        <vers num="11.23" edition=":ia64_64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0365" published="2005-05-02" name="CVE-2005-0365" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050316-2.txt" source="CONFIRM" patch="1">http://www.kde.org/info/security/advisory-20050316-2.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-14.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-14</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110814653804757&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050211 insecure temporary file creation in kdelibs 3.3.2</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=97608" source="CONFIRM" patch="1" adv="1">http://bugs.kde.org/show_bug.cgi?id=97608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10676" source="OVAL">oval:org.mitre.oval:def:10676</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-325.html" source="REDHAT">RHSA-2005:325</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058" source="MANDRAKE">MDKSA-2005:058</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:045" source="MANDRAKE">MDKSA-2005:045</ref>
      <ref url="http://securitytracker.com/id?1013525" source="SECTRACK">1013525</ref>
      <ref url="http://secunia.com/advisories/14254" source="SECUNIA">14254</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2005-245.shtml" source="FEDORA">FEDORA-2005-245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.2.x"/>
        <vers num="3.3.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0366" published="2005-05-02" name="CVE-2005-0366" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/303094" source="CERT-VN" adv="1">VU#303094</ref>
      <ref url="http://www.pgp.com/library/ctocorner/openpgp.html" source="CONFIRM" patch="1" adv="1">http://www.pgp.com/library/ctocorner/openpgp.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-29.xml" source="GENTOO" adv="1">GLSA-200503-29</ref>
      <ref url="http://eprint.iacr.org/2005/033.pdf" source="MISC">http://eprint.iacr.org/2005/033.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/12529" source="BID">12529</ref>
      <ref url="http://www.osvdb.org/13775" source="OSVDB">13775</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_07_sr.html" source="SUSE">SUSE-SR:2005:007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:057" source="MANDRAKE">MDKSA-2005:057</ref>
      <ref url="http://securitytracker.com/id?1013166" source="SECTRACK">1013166</ref>
      <ref url="http://eprint.iacr.org/2005/033" source="MISC">http://eprint.iacr.org/2005/033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpgp" name="openpgp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0367" published="2005-02-09" name="CVE-2005-0367" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796956011699&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050209 [SIG^2 G-TEC] ArGoSoft Mail Server Webmail Multiple Directory Traversal Vulnerabilities</ref>
      <ref url="http://www.security.org.sg/vuln/argosoftmail1873.html" source="MISC" adv="1">http://www.security.org.sg/vuln/argosoftmail1873.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0368" published="2005-05-02" name="CVE-2005-0368" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19235" source="XF">cmscore-multiple-sql-injection(19235)</ref>
      <ref url="http://www.securityfocus.com/bid/12457" source="BID">12457</ref>
      <ref url="http://secunia.com/advisories/14142/" source="SECUNIA" adv="1">14142</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110803385223054&amp;w=2" source="BUGTRAQ" adv="1">20050209 CMS Core SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chipmunk_scripts" name="cmscore">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0369" published="2005-05-02" name="CVE-2005-0369" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2" source="BUGTRAQ" adv="1">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armagetron" name="armagetron">
        <vers prev="1" num="0.2.6.0"/>
      </prod>
      <prod vendor="armagetron" name="armagetron_advanced">
        <vers prev="1" num="0.2.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0370" published="2005-05-02" name="CVE-2005-0370" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2" source="BUGTRAQ" adv="1">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armagetron" name="armagetron">
        <vers prev="1" num="0.2.6.0"/>
      </prod>
      <prod vendor="armagetron" name="armagetron_advanced">
        <vers prev="1" num="0.2.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0371" published="2005-05-02" name="CVE-2005-0371" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2" source="BUGTRAQ" adv="1">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armagetron" name="armagetron">
        <vers num="0.2.5.2"/>
        <vers num="0.2.6.0"/>
      </prod>
      <prod vendor="armagetron" name="armagetron_advanced">
        <vers num="0.2.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0372" published="2005-05-02" name="CVE-2005-0372" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12539" source="BID" patch="1">12539</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-27.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-27</ref>
      <ref url="http://www.debian.org/security/2005/dsa-686" source="DEBIAN" patch="1" adv="1">DSA-686</ref>
      <ref url="http://www.securityfocus.com/advisories/8380" source="FEDORA">FEDORA-2005-310</ref>
      <ref url="http://www.securityfocus.com/advisories/8379" source="FEDORA">FEDORA-2005-309</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9923" source="OVAL">oval:org.mitre.oval:def:9923</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000957" source="CONECTIVA">CLSA-2005:957</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-410.html" source="REDHAT">RHSA-2005:410</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:050" source="MANDRAKE">MDKSA-2005:050</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:717" source="OVAL" sig="1">oval:org.mitre.oval:def:717</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtk" name="gtk+">
        <vers prev="1" num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.18"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0373" published="2004-10-07" name="CVE-2005-0373" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17642" source="XF" patch="1" adv="1">cyrus-sasl-digestmda5-bo(17642)</ref>
      <ref url="http://www.securityfocus.com/bid/11347" source="BID" patch="1" adv="1">11347</ref>
      <ref url="http://www.monkey.org/openbsd/archive/ports/0407/msg00265.html" source="MLIST" patch="1" adv="1">[openbsd-ports] 20040717 UPDATE: cyrus-sasl-2.1.19</ref>
      <ref url="http://www.linuxcompatible.org/print42495.html" source="SUSE" patch="1" adv="1">SUSE-SR:2005:006</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-05</ref>
      <ref url="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup" source="CONFIRM" adv="1">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup</ref>
      <ref url="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171" source="CONFIRM" adv="1">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:054" source="MANDRAKE">MDKSA-2005:054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyrus" name="sasl">
        <vers num="1.5.24"/>
        <vers num="1.5.27"/>
        <vers num="1.5.28"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.1.13"/>
        <vers num="2.1.14"/>
        <vers num="2.1.15"/>
        <vers num="2.1.16"/>
        <vers num="2.1.17"/>
        <vers num="2.1.18"/>
        <vers num="2.1.18_r1"/>
        <vers num="2.1.9"/>
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod vendor="suse" name="suse_cvsup">
        <vers num="16.1h_36.i586"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0"/>
        <vers num="9.0"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":desktop"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":enterprise_server"/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":x86_64"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":x86_64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0374" published="2005-05-02" name="CVE-2005-0374" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Bitboard 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via an [img] bbcode image tag with an event such as mouseover.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18871" source="XF">bitshifters-bitboard-xss(18871)</ref>
      <ref url="http://www.securityfocus.com/bid/12248" source="BID">12248</ref>
      <ref url="http://securitytracker.com/id?1012864" source="SECTRACK">1012864</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110555988111899&amp;w=2" source="BUGTRAQ" adv="1">20050112 Security Advisory: BiTBOARD xss</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitshifters" name="bitboard">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0375" published="2005-05-02" name="CVE-2005-0375" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18877" source="XF">sgallery-path-disclosure(18877)</ref>
      <ref url="http://www.waraxe.us/advisory-39.html" source="MISC" adv="1">http://www.waraxe.us/advisory-39.html</ref>
      <ref url="http://securitytracker.com/id?1012868" source="SECTRACK">1012868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_kiselev" name="sgallery">
        <vers num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0376" published="2005-01-12" name="CVE-2005-0376" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18878" source="XF" adv="1">sgallery-file-include(18878)</ref>
      <ref url="http://www.waraxe.us/advisory-39.html" source="MISC" adv="1">http://www.waraxe.us/advisory-39.html</ref>
      <ref url="http://securitytracker.com/id?1012868" source="SECTRACK">1012868</ref>
      <ref url="http://secunia.com/advisories/13824" source="SECUNIA" adv="1">13824</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2" source="BUGTRAQ" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html" source="FULLDISC" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_kiselev" name="sgallery">
        <vers num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0377" published="2005-05-02" name="CVE-2005-0377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18876" source="XF">sgallery-imageview-sql-injection(18876)</ref>
      <ref url="http://www.waraxe.us/advisory-39.html" source="MISC">http://www.waraxe.us/advisory-39.html</ref>
      <ref url="http://www.securityfocus.com/bid/12249" source="BID" adv="1">12249</ref>
      <ref url="http://securitytracker.com/id?1012868" source="SECTRACK">1012868</ref>
      <ref url="http://secunia.com/advisories/13824" source="SECUNIA" adv="1">13824</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2" source="BUGTRAQ" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_kiselev" name="sgallery">
        <vers num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0378" published="2005-05-02" name="CVE-2005-0378" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12255" source="BID" patch="1">12255</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110564059322774&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050113 Cross Site Scripting holes found in Horde 3.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18881" source="XF">horde-prefs-index-xss(18881)</ref>
      <ref url="http://www.hyperdose.com/advisories/H2005-01.txt" source="MISC">http://www.hyperdose.com/advisories/H2005-01.txt</ref>
      <ref url="http://securitytracker.com/id?1012892" source="SECTRACK">1012892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="horde">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0379" published="2005-05-02" name="CVE-2005-0379" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlogin.php, or the dir parameter to (3) write.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18891" source="XF">zeroboard-file-disclosure(18891)</ref>
      <ref url="http://www.securityfocus.com/bid/12257" source="BID">12257</ref>
      <ref url="http://securitytracker.com/id?1012884" source="SECTRACK">1012884</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565373407474&amp;w=2" source="BUGTRAQ" adv="1">20050113 STG Security Advisory: [SSA-20050113-25] ZeroBoard multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2"/>
        <vers num="4.1_pl3"/>
        <vers num="4.1_pl4"/>
        <vers num="4.1_pl5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0380" published="2005-05-02" name="CVE-2005-0380" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the dir parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13769" source="SECUNIA" patch="1" adv="1">13769</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18893" source="XF">zeroboard-zero-vote-file-include(18893)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18892" source="XF">zeroboard-printcategory-file-include(18892)</ref>
      <ref url="http://www.securityfocus.com/bid/12258" source="BID">12258</ref>
      <ref url="http://www.securityfocus.com/bid/12206" source="BID">12206</ref>
      <ref url="http://www.osvdb.org/12932" source="OSVDB">12932</ref>
      <ref url="http://www.osvdb.org/12931" source="OSVDB">12931</ref>
      <ref url="http://www.osvdb.org/12930" source="OSVDB">12930</ref>
      <ref url="http://www.osvdb.org/12929" source="OSVDB">12929</ref>
      <ref url="http://www.osvdb.org/12928" source="OSVDB">12928</ref>
      <ref url="http://securitytracker.com/id?1012884" source="SECTRACK">1012884</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565373407474&amp;w=2" source="BUGTRAQ" adv="1">20050113 STG Security Advisory: [SSA-20050113-25] ZeroBoard multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2"/>
        <vers num="4.1_pl3"/>
        <vers num="4.1_pl4"/>
        <vers num="4.1_pl5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0381" published="2005-01-13" name="CVE-2005-0381" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18880" source="XF" adv="1">forumkit-members-xss(18880)</ref>
      <ref url="http://www.securityfocus.com/bid/12256" source="BID" adv="1">12256</ref>
      <ref url="http://securitytracker.com/id?1012895" source="SECTRACK">1012895</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110563769413994&amp;w=2" source="BUGTRAQ" adv="1">20050113 XSS Vulnerability in ForumKIT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="forumkit" name="forumkit">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0382" published="2005-05-02" name="CVE-2005-0382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18890" source="XF">breed-udp-datagram-dos(18890)</ref>
      <ref url="http://www.securityfocus.com/bid/12262" source="BID">12262</ref>
      <ref url="http://secunia.com/advisories/13211" source="SECUNIA" adv="1">13211</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565587010998&amp;w=2" source="BUGTRAQ" adv="1">20050113 Server crash in Breed patch #1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="breed" name="breed">
        <vers num="patch_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0383" published="2005-05-02" name="CVE-2005-0383" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Trend Micro Control Manager 3.0 Enterprise Edition allows remote attackers to gain privileges via a replay attack of the encrypted username and password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cirt.dk/advisories/cirt-28-advisory.pdf" source="MISC" patch="1" adv="1">http://www.cirt.dk/advisories/cirt-28-advisory.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565281205427&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050113 Trend Micro Control Manager - Enterprise Edition 3.0 Web application Replay attack</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18887" source="XF">control-manager-replay-attack(18887)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110564369316593&amp;w=2" source="BUGTRAQ" adv="1">20050113 Trend Micro Control Manager - Enterprise Edition 3.0 Web application Replay attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="control_manager">
        <vers num="3.0_enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0384" published="2005-03-15" name="CVE-2005-0384" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1" source="UBUNTU">USN-95-1</ref>
      <ref url="http://www.trustix.org/errata/2005/0009/" source="TRUSTIX" adv="1">2005-0009</ref>
      <ref url="http://www.securityfocus.com/bid/12810" source="BID">12810</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" adv="1">RHSA-2005:284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-283.html" source="REDHAT" adv="1">RHSA-2005:283</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9562" source="OVAL">oval:org.mitre.oval:def:9562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.2"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0385" published="2005-05-02" name="CVE-2005-0385" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <env/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12797" source="BID" patch="1">12797</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19680" source="XF">luxman-bo-execute-commands(19680)</ref>
      <ref url="http://www.securityfocus.com/archive/1/393195/2005-03-13/2005-03-19/0" source="BUGTRAQ">20050314 DMA[2005-0310a] - 'Frank McIngvale LuxMan buffer overflow'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0310a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2005-0310a].txt </ref>
      <ref url="http://www.debian.org/security/2005/dsa-693" source="DEBIAN" adv="1">DSA-693</ref>
      <ref url="http://secunia.com/advisories/14582" source="SECUNIA" adv="1">14582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frank_mcingvale" name="luxman">
        <vers num="0.41"/>
        <vers num="0.41_17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0386" published="2005-05-02" name="CVE-2005-0386" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in network.cgi in mailreader before 2.3.29 earlier allows remote attackers to inject arbitrary web script or HTML via MIME text/enriched or text/richtext messages.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-700" source="DEBIAN" patch="1" adv="1">DSA-700</ref>
      <ref url="http://secunia.com/advisories/14777" source="SECUNIA" adv="1">14777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailreader.com" name="mailreader.com">
        <vers num="2.3.20"/>
        <vers num="2.3.21"/>
        <vers num="2.3.22"/>
        <vers num="2.3.23"/>
        <vers num="2.3.24"/>
        <vers num="2.3.25"/>
        <vers num="2.3.26"/>
        <vers num="2.3.27"/>
        <vers num="2.3.28"/>
        <vers num="2.3.29"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0387" published="2005-05-02" name="CVE-2005-0387" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-704" source="DEBIAN" patch="1" adv="1">DSA-704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="remstats" name="remstats">
        <vers num="1.0.13"/>
        <vers num="1.0.8a"/>
        <vers num="1.0.9b"/>
        <vers num="1.00a4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0388" published="2005-05-02" name="CVE-2005-0388" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-704" source="DEBIAN" patch="1" adv="1">DSA-704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="remstats" name="remstats">
        <vers num="1.0.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0389" reject="1" published="2005-05-02" name="CVE-2005-0389" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0814.  Reason: This candidate is a duplicate of CVE-2005-0814.  Notes: All CVE users should reference CVE-2005-0814 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0390" published="2005-05-02" name="CVE-2005-0390" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP redirection capability in conn.c for Axel before 1.0b may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13059" source="BID" patch="1">13059</ref>
      <ref url="http://www.debian.org/security/2005/dsa-706" source="DEBIAN" patch="1" adv="1">DSA-706</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200504-09.xml" source="GENTOO" patch="1" adv="1">GLSA-200504-09</ref>
      <ref url="http://secunia.com/advisories/14831" source="SECUNIA" patch="1">14831</ref>
      <ref url="http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg118978.html" source="CONFIRM">http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg118978.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axel" name="axel">
        <vers num="1.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0391" published="2005-05-02" name="CVE-2005-0391" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">geneweb 4.10 and earlier does not properly check file permissions and content during conversion, which allows attackers to modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-712" source="DEBIAN" patch="1" adv="1">DSA-712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20176" source="XF">geneweb-insecure-file-permission(20176)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_de_rauglaudre" name="geneweb">
        <vers prev="1" num="4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0392" published="2005-05-19" name="CVE-2005-0392" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ppxp does not drop root privileges before opening log files, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13681" source="BID">13681</ref>
      <ref url="http://www.debian.org/security/2005/dsa-725" source="DEBIAN">DSA-725</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="ppxp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0393" published="2005-07-05" name="CVE-2005-0393" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-733" source="DEBIAN" patch="1" adv="1">DSA-733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crip" name="crip">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0395" reject="1" published="2005-06-09" name="CVE-2005-0395" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0396" published="2005-05-02" name="CVE-2005-0396" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Desktop Communication Protocol (DCOP) daemon, aka dcopserver, in KDE before 3.4 allows local users to cause a denial of service (dcopserver consumption) by "stalling the DCOP authentication process."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20050316-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20050316-1.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-22</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111099766716483&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050316 Multiple KDE Security Advisories (2005-03-16)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10432" source="OVAL">oval:org.mitre.oval:def:10432</ref>
      <ref url="http://www.securityfocus.com/bid/12820" source="BID">12820</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" source="FEDORA">FLSA:178606</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-325.html" source="REDHAT">RHSA-2005:325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-307.html" source="REDHAT">RHSA-2005:307</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058" source="MANDRAKE">MDKSA-2005:058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="dcopserver">
        <vers prev="1" num="3.3"/>
      </prod>
      <prod vendor="kde" name="desktop_communication_protocol_daemon">
        <vers prev="1" num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0397" published="2005-05-02" name="CVE-2005-0397" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19586" source="XF" patch="1">imagemagick-filename-format-string(19586)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-320.html" source="REDHAT" patch="1" adv="1">RHSA-2005:320</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:017</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-11.xml" source="GENTOO" patch="1">GLSA-200503-11</ref>
      <ref url="http://www.debian.org/security/2005/dsa-702" source="DEBIAN" patch="1" adv="1">DSA-702</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110987256010857&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050303 [USN-90-1] Imagemagick vulnerability</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=83542" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=83542</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10302" source="OVAL">oval:org.mitre.oval:def:10302</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-070.html" source="REDHAT">RHSA-2005:070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0398" published="2005-03-14" name="CVE-2005-0398" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=109966&amp;action=view" source="MISC" patch="1" adv="1">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=109966&amp;action=view</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19707" source="XF" patch="1" adv="1">racoon-isakmp-header-dos(19707)</ref>
      <ref url="http://www.securityfocus.com/bid/12804" source="BID" patch="1" adv="1">12804</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-232.html" source="REDHAT" patch="1" adv="1">RHSA-2005:232</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=6787713&amp;forum_id=32000" source="MLIST" patch="1" adv="1">[ipsec-tools-devel] 20050312 potential remote crash in racoon</ref>
      <ref url="http://securitytracker.com/id?1013433" source="SECTRACK" patch="1" adv="1">1013433</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200503-33.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-33</ref>
      <ref url="http://secunia.com/advisories/14584" source="SECUNIA" patch="1" adv="1">14584</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0264" source="VUPEN">ADV-2005-0264</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10028" source="OVAL">oval:org.mitre.oval:def:10028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:062" source="MANDRAKE">MDKSA-2005:062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipsec-tools" name="ipsec-tools">
        <vers num="0.3.3"/>
        <vers num="0.5"/>
      </prod>
      <prod vendor="kame" name="racoon">
        <vers num="2003-07-11"/>
        <vers num="2004-04-05"/>
        <vers num="2004-04-07b"/>
        <vers num="2004-05-03"/>
        <vers num="2005-01-03"/>
        <vers num="2005-01-10"/>
        <vers num="2005-01-17"/>
        <vers num="2005-01-24"/>
        <vers num="2005-01-31"/>
        <vers num="2005-02-07"/>
        <vers num="2005-02-14"/>
        <vers num="2005-02-21"/>
        <vers num="2005-02-28"/>
        <vers num="2005-03-07"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0"/>
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition=""/>
        <vers num="2.3" edition=":compact"/>
        <vers num="2.3" edition=":junior"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":advanced_servers"/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":workstation"/>
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="" edition=":desktop"/>
        <vers num="" edition=":enterprise_server"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":x86_64"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":x86_64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0399" published="2005-05-02" name="CVE-2005-0399" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/557948" source="CERT-VN" adv="1">VU#557948</ref>
      <ref url="http://secunia.com/advisories/14654" source="SECUNIA" patch="1" adv="1">14654</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=150877" source="MISC" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=150877</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19269" source="XF">gif-extension-overflow(19269)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/191" source="ISS" adv="1">20050323 Mozilla Foundation GIF Overflow</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0296" source="VUPEN">ADV-2005-0296</ref>
      <ref url="http://www.securityfocus.com/bid/12881" source="BID">12881</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-337.html" source="REDHAT" adv="1">RHSA-2005:337</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-336.html" source="REDHAT" adv="1">RHSA-2005:336</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" adv="1">RHSA-2005:323</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-30.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-30.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" adv="1">GLSA-200503-30</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-160.shtml" source="CIAC">P-160</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11377" source="OVAL">oval:org.mitre.oval:def:11377</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100028" source="OVAL" sig="1">oval:org.mitre.oval:def:100028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="alpha"/>
        <vers num="1.5" edition="rc1"/>
        <vers num="1.5" edition="rc2"/>
        <vers num="1.5.1"/>
        <vers num="1.6" edition="alpha"/>
        <vers num="1.6" edition="beta"/>
        <vers num="1.7" edition="alpha"/>
        <vers num="1.7" edition="beta"/>
        <vers num="1.7" edition="rc1"/>
        <vers num="1.7" edition="rc2"/>
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0400" published="2005-05-02" name="CVE-2005-0400" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ext2_make_empty function call in the Linux kernel before 2.6.11.6 does not properly initialize memory when creating a block for a new directory entry, which allows local users to obtain potentially sensitive information by reading the block.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19866" source="XF" patch="1">kernel-ext2-information-disclosure(19866)</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-103-1" source="UBUNTU">USN-103-1</ref>
      <ref url="http://secunia.com/advisories/14713/" source="SECUNIA">14713</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10336" source="OVAL">oval:org.mitre.oval:def:10336</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6</ref>
      <ref url="http://arkoon.net/advisories/ext2-make-empty-leak.txt" source="MISC" adv="1">http://arkoon.net/advisories/ext2-make-empty-leak.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12932" source="BID">12932</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0191.html" source="REDHAT">RHSA-2006:0191</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0190.html" source="REDHAT">RHSA-2006:0190</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://secunia.com/advisories/18684" source="SECUNIA">18684</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238764720696&amp;w=2" source="BUGTRAQ">20050401 Information leak in the Linux kernel ext2 implementation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.11.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0401" published="2005-05-02" name="CVE-2005-0401" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12885" source="BID" patch="1">12885</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0296" source="VUPEN">ADV-2005-0296</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-336.html" source="REDHAT" adv="1">RHSA-2005:336</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-32.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-32.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" adv="1">GLSA-200503-30</ref>
      <ref url="http://secunia.com/advisories/14654" source="SECUNIA" adv="1">14654</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9650" source="OVAL">oval:org.mitre.oval:def:9650</ref>
      <ref url="http://mikx.de/firescrolling2/" source="MISC">http://mikx.de/firescrolling2/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168413007891&amp;w=2" source="BUGTRAQ" adv="1">20050324 Firescrolling 2 [Firefox 1.0.1]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100026" source="OVAL" sig="1">oval:org.mitre.oval:def:100026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="alpha"/>
        <vers num="1.5" edition="rc1"/>
        <vers num="1.5" edition="rc2"/>
        <vers num="1.5.1"/>
        <vers num="1.6" edition="alpha"/>
        <vers num="1.6" edition="beta"/>
        <vers num="1.7" edition="alpha"/>
        <vers num="1.7" edition="beta"/>
        <vers num="1.7" edition="rc1"/>
        <vers num="1.7" edition="rc2"/>
        <vers num="1.7" edition="rc3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0402" published="2005-05-02" name="CVE-2005-0402" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=284627" source="MISC" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=284627</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-336.html" source="REDHAT" patch="1" adv="1">RHSA-2005:336</ref>
      <ref url="http://secunia.com/advisories/14654" source="SECUNIA" patch="1" adv="1">14654</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0296" source="VUPEN">ADV-2005-0296</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-31.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/mfsa2005-31.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11868" source="OVAL">oval:org.mitre.oval:def:11868</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100027" source="OVAL" sig="1">oval:org.mitre.oval:def:100027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0403" published="2005-09-01" name="CVE-2005-0403" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT" patch="1" adv="1">RHSA-2005:293</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=144059" source="MISC">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=144059</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9435" source="OVAL">oval:org.mitre.oval:def:9435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation"/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":advanced_servers"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0404" published="2005-05-02" name="CVE-2005-0404" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/5GP0B0AFFE.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/unixfocus/5GP0B0AFFE.html</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=96020" source="MISC" patch="1" adv="1">http://bugs.kde.org/show_bug.cgi?id=96020</ref>
      <ref url="http://secunia.com/advisories/14925" source="SECUNIA" adv="1">14925</ref>
      <ref url="http://mail.kde.org/pipermail/kmail-devel/2005-February/015490.html" source="MLIST" adv="1">[kmail-devel] 20050215 [Bug 96020] HTML Allows Spoofing of Emails Content</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kmail" name="kmail">
        <vers num="1.7.1"/>
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0406" published="2005-02-14" name="CVE-2005-0406" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html" source="FULLDISC">20050214 Advisory: JPEG EXIF information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="image_processing_software" name="image_processing_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0407" published="2005-05-02" name="CVE-2005-0407" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Openconf 1.04, and possibly other versions before 1.10, allows remote attackers to inject arbitrary HTML and web script via the paper title.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12554" source="BID">12554</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-007.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-007.txt</ref>
      <ref url="http://secunia.com/advisories/14294" source="SECUNIA" adv="1">14294</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Feb/0347.html" source="FULLDISC">20050214 Advisory: Cross Site Scripting Vulnerability in Openconf Conference Management Software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zakon_group" name="openconf">
        <vers num="1.0"/>
        <vers num="1.01"/>
        <vers num="1.02"/>
        <vers num="1.03"/>
        <vers num="1.04"/>
        <vers num="1.0_beta1"/>
        <vers num="1.0_beta2"/>
        <vers num="1.0_rc1"/>
        <vers num="1.0_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0408" published="2005-02-14" name="CVE-2005-0408" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the "boogaadeeboo" string, which is hard-coded in the $hidden_hash variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html" source="FULLDISC">20050214 Advisory: Authentication bypass in CitrusDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb">
        <vers prev="1" num="0.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0409" published="2005-02-14" name="CVE-2005-0409" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html" source="FULLDISC">20050214 Advisory: Upload Authorization bypass in CitrusDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb">
        <vers prev="1" num="0.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0410" published="2005-02-14" name="CVE-2005-0410" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031709.html" source="FULLDISC">20050214 Advisory: SQL-Injection in CitrusDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb">
        <vers prev="1" num="0.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0411" published="2005-02-14" name="CVE-2005-0411" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031710.html" source="FULLDISC">20050214 Advisory: Directory traversal in CitrusDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrusdb" name="citrusdb">
        <vers prev="1" num="0.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0412" published="2005-04-27" name="CVE-2005-0412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19261" source="XF" adv="1">postwrap-xss(19261)</ref>
      <ref url="http://securitytracker.com/id?1013130" source="SECTRACK" adv="1">1013130</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0065.html" source="FULLDISC">20050208 XSS VULNERABILITY AT MODULE PostWrap</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidean" name="postwrap">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0413" published="2005-04-27" name="CVE-2005-0413" modified="2010-12-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php.  NOTE: it was later reported that vector 2 exists in 3.0 and earlier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39348" source="XF">myphpforum-member-sql-injection(39348)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19272" source="XF">myphpforum-multiple-sql-injection(19272)</ref>
      <ref url="http://www.securityfocus.com/bid/27083" source="BID">27083</ref>
      <ref url="http://www.securityfocus.com/bid/12501" source="BID">12501</ref>
      <ref url="http://www.milw0rm.com/exploits/4822" source="MILW0RM">4822</ref>
      <ref url="http://securitytracker.com/id?1013136" source="SECTRACK" adv="1">1013136</ref>
      <ref url="http://secunia.com/advisories/14205" source="SECUNIA" adv="1">14205</ref>
      <ref url="http://seclists.org/lists/bugtraq/2005/Feb/0125.html" source="BUGTRAQ">20050209 Several SQL injection bugs in myPHP Forum v.1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphp_forum" name="myphp_forum">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0414" published="2005-04-27" name="CVE-2005-0414" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013137" source="SECTRACK" patch="1" adv="1">1013137</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19051" source="XF">mercuryboard-index-sql-injection(19051)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110797495532358&amp;w=2" source="BUGTRAQ">20050209 Mercuryboard =?iso-8859-1?Q?&lt;=3D?= 1.1.1 Working Sql Injection</ref>
      <ref url="http://cvs.sunsite.dk/viewcvs.cgi/mercury/func/post.php.diff?r1=1.68&amp;r2=1.70" source="CONFIRM">http://cvs.sunsite.dk/viewcvs.cgi/mercury/func/post.php.diff?r1=1.68&amp;r2=1.70</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0415" published="2005-04-27" name="CVE-2005-0415" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19273" source="XF">emdros-mql-dos(19273)</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1116935&amp;group_id=37219&amp;atid=419458" source="CONFIRM" adv="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1116935&amp;group_id=37219&amp;atid=419458</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=303465" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=303465</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ulrik_petersen" name="emdros_database_engine">
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.20"/>
        <vers num="1.1.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0416" published="2005-04-27" name="CVE-2005-0416" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18879" source="XF" patch="1" adv="1">win-user32-aniheader-overflow(18879)</ref>
      <ref url="http://www.securityfocus.com/bid/12233" source="BID" patch="1" adv="1">12233</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-002.mspx" source="MS" patch="1" adv="1">MS05-002</ref>
      <ref url="http://eeye.com/html/research/advisories/AD20050111.html" source="MISC">http://eeye.com/html/research/advisories/AD20050111.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110556975827760&amp;w=2" source="BUGTRAQ">20050112 Windows ANI File Parsing Proof Of Concept (MS05-002)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547079218397&amp;w=2" source="BUGTRAQ">20050111 EEYE: Windows ANI File Parsing Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0417" published="2005-04-27" name="CVE-2005-0417" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors.  NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future.  In addition, this may be a duplicate of other issues as reported by the vendor.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12508" source="BID" patch="1" adv="1">12508</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110801212422825&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050209 Patch available for high risk IBM DB2 Universal Database flaw</ref>
      <ref url="http://www.ngssoftware.com/advisories/db2-09-05-05.htm" source="MISC">http://www.ngssoftware.com/advisories/db2-09-05-05.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="6.0"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":linux"/>
        <vers num="7.1" edition=""/>
        <vers num="7.1" edition=":linux"/>
        <vers num="7.2" edition=""/>
        <vers num="7.2" edition=":linux"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":linux"/>
        <vers num="8.1" edition=""/>
        <vers num="8.1" edition=":aix"/>
        <vers num="8.2" edition=""/>
        <vers num="8.2" edition=":windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0418" published="2005-05-02" name="CVE-2005-0418" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-03-24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="j2se">
        <vers num="1.4.2" edition=""/>
        <vers num="1.4.2" edition=":sdk"/>
        <vers num="1.4.2_01" edition=""/>
        <vers num="1.4.2_01" edition=":sdk"/>
        <vers num="1.4.2_02" edition=""/>
        <vers num="1.4.2_02" edition=":sdk"/>
        <vers num="1.4.2_03" edition=""/>
        <vers num="1.4.2_03" edition=":sdk"/>
        <vers num="1.4.2_04" edition=""/>
        <vers num="1.4.2_04" edition=":sdk"/>
        <vers num="1.4.2_05" edition=""/>
        <vers num="1.4.2_05" edition=":sdk"/>
        <vers num="1.4.2_06" edition=""/>
        <vers num="1.4.2_06" edition=":sdk"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0419" published="2005-04-27" name="CVE-2005-0419" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19250" source="XF">3cserver-multiple-command-bo(19250)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780306326130&amp;w=2" source="BUGTRAQ" adv="1">20050207 Vulnerability in 3Com 3CServer v1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cserver">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0420" published="2005-04-27" name="CVE-2005-0420" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19225" source="XF" adv="1">owa-owalogonasp-url-redirect(19225)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0105" source="VUPEN">ADV-2005-0105</ref>
      <ref url="http://www.securityfocus.com/bid/12459" source="BID" adv="1">12459</ref>
      <ref url="http://secunia.com/advisories/14144" source="SECUNIA" adv="1">14144</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2005/Feb/0106.html" source="FULLDISC">20050206 Microsoft Outlook Web Access URL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2003" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0421" published="2005-04-27" name="CVE-2005-0421" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19248" source="XF">delphiturkcodebank-obtain-information(19248)</ref>
      <ref url="http://securitytracker.com/id?1013139" source="SECTRACK" adv="1">1013139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delphiturk" name="delphiturk_ftp">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0422" published="2005-04-27" name="CVE-2005-0422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19248" source="XF" adv="1">delphiturkcodebank-obtain-information(19248)</ref>
      <ref url="http://securitytracker.com/id?1013139" source="SECTRACK" adv="1">1013139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delphiturk" name="codebank">
        <vers prev="1" num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0423" published="2005-04-27" name="CVE-2005-0423" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12521" source="BID" patch="1" adv="1">12521</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19299" source="XF" adv="1">aspjar-guest-login-sql-injection(19299)</ref>
      <ref url="http://secunia.com/advisories/14225/" source="SECUNIA" adv="1">14225</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110809687921701&amp;w=2" source="BUGTRAQ">20050210 ASPjar guestbook (Injection in login page)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspjar" name="aspjar_guestbook">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0424" published="2005-04-27" name="CVE-2005-0424" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages.  NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12521" source="BID" patch="1" adv="1">12521</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19301" source="XF" adv="1">aspjar-delete-message-deletion(19301)</ref>
      <ref url="http://secunia.com/advisories/14225/" source="SECUNIA" adv="1">14225</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110809687921701&amp;w=2" source="BUGTRAQ">20050210 ASPjar guestbook (Injection in login page)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspjar" name="aspjar_guestbook">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0425" published="2005-05-02" name="CVE-2005-0425" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24008815" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg24008815</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24008814" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg24008814</ref>
      <ref url="http://secunia.com/advisories/14274" source="SECUNIA" patch="1" adv="1">14274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.0"/>
        <vers num="5.1.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0426" published="2005-05-02" name="CVE-2005-0426" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19119" source="XF">solaris-udp-end-point-dos(19119)</ref>
      <ref url="http://www.securityfocus.com/bid/12385" source="BID">12385</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57728-1" source="SUNALERT" adv="1">57728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0427" published="2005-05-02" name="CVE-2005-0427" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19315" source="XF">webmin-encrypted-password(19315)</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=77731" source="MISC" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=77731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="webmin">
        <vers num="1.140"/>
        <vers num="1.150"/>
        <vers num="1.160"/>
        <vers num="1.170" edition="r1"/>
        <vers num="1.170" edition="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0428" published="2005-05-02" name="CVE-2005-0428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19221" source="XF" patch="1" adv="1">powerdns-random-bytes-dos(19221)</ref>
      <ref url="http://www.securityfocus.com/bid/12446" source="BID" patch="1" adv="1">12446</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-15</ref>
      <ref url="http://ds9a.nl/cgi-bin/cvstrac/pdns/tktview?tn=21" source="MISC">http://ds9a.nl/cgi-bin/cvstrac/pdns/tktview?tn=21</ref>
      <ref url="http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-17" source="CONFIRM">http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerdns" name="powerdns">
        <vers num="2.0_rc1"/>
        <vers num="2.8"/>
        <vers num="2.9.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0429" published="2005-05-02" name="CVE-2005-0429" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110840807415315&amp;w=2" source="BUGTRAQ" adv="1">20050213 vbulletin 3.0.x PHP code execution</ref>
      <ref url="http://www.securityfocus.com/bid/12542" source="BID">12542</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0430" published="2005-02-12" name="CVE-2005-0430" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/q3infoboom-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/q3infoboom-adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12534" source="BID">12534</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824822224025&amp;w=2" source="BUGTRAQ">20050212 Infostring crash and shutdown in the Quake 3 engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quake_3_engine">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0431" published="2005-05-02" name="CVE-2005-0431" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19283" source="XF">barracuda-open-relay(19283)</ref>
      <ref url="http://secunia.com/advisories/14243" source="SECUNIA" adv="1">14243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805534732492&amp;w=2" source="BUGTRAQ" adv="1">20050210 Barracuda Spam Firewall &lt;= 3.1.10 acts as open relay for whitelisted senders.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barracuda_networks" name="barracuda_spam_firewall">
        <vers num="3.1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0432" published="2005-05-02" name="CVE-2005-0432" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14298" source="SECUNIA" patch="1" adv="1">14298</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA05-74.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA05-74.00.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp5"/>
        <vers num="8.1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0433" published="2005-02-15" name="CVE-2005-0433" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19344" source="XF">phpnuke-multiple-scripts-path-disclosure(19344)</ref>
      <ref url="http://www.waraxe.us/advisory-40.html" source="MISC" adv="1">http://www.waraxe.us/advisory-40.html</ref>
      <ref url="http://www.securityfocus.com/bid/12561" source="BID" adv="1">12561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0"/>
        <vers num="6.5"/>
        <vers num="6.5_beta1"/>
        <vers num="6.5_final"/>
        <vers num="6.5_rc1"/>
        <vers num="6.5_rc2"/>
        <vers num="6.5_rc3"/>
        <vers num="6.6"/>
        <vers num="6.7"/>
        <vers num="6.9"/>
        <vers num="7.0"/>
        <vers num="7.0_final"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0434" published="2005-02-15" name="CVE-2005-0434" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19346" source="XF">phpnuke-downloads-weblinks-xss(19346)</ref>
      <ref url="http://www.waraxe.us/advisory-40.html" source="MISC" adv="1">http://www.waraxe.us/advisory-40.html</ref>
      <ref url="http://www.securityfocus.com/bid/12561" source="BID" adv="1">12561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0"/>
        <vers num="6.5"/>
        <vers num="6.5_beta1"/>
        <vers num="6.5_final"/>
        <vers num="6.5_rc1"/>
        <vers num="6.5_rc2"/>
        <vers num="6.5_rc3"/>
        <vers num="6.6"/>
        <vers num="6.7"/>
        <vers num="6.9"/>
        <vers num="7.0"/>
        <vers num="7.0_final"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0435" published="2005-05-02" name="CVE-2005-0435" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14299" source="SECUNIA" patch="1" adv="1">14299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19333" source="XF">awstats-awstatpl-obtain-information(19333)</ref>
      <ref url="http://www.securityfocus.com/archive/1/390368" source="BUGTRAQ" adv="1">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0436" published="2005-05-02" name="CVE-2005-0436" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14299" source="SECUNIA" patch="1" adv="1">14299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19336" source="XF">awstats-function-code-execution(19336)</ref>
      <ref url="http://www.securityfocus.com/archive/1/390368" source="BUGTRAQ" adv="1">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/13832" source="OSVDB">13832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0437" published="2005-05-02" name="CVE-2005-0437" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14299" source="SECUNIA" patch="1" adv="1">14299</ref>
      <ref url="http://www.securityfocus.com/archive/1/390368" source="BUGTRAQ" adv="1">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0438" published="2005-05-02" name="CVE-2005-0438" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14299" source="SECUNIA" patch="1" adv="1">14299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19477" source="XF">awstats-information-disclosure(19477)</ref>
      <ref url="http://www.securityfocus.com/archive/1/390368" source="BUGTRAQ" adv="1">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0439" published="2005-05-02" name="CVE-2005-0439" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12556" source="BID" patch="1">12556</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880</ref>
      <ref url="http://midas.psi.ch/elogs/Forum/941" source="CONFIRM" patch="1" adv="1">http://midas.psi.ch/elogs/Forum/941</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19313" source="XF">elog-weblog-bo(19313)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0440" published="2005-05-02" name="CVE-2005-0440" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12556" source="BID" patch="1">12556</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880</ref>
      <ref url="http://midas.psi.ch/elogs/Forum/941" source="CONFIRM" adv="1">http://midas.psi.ch/elogs/Forum/941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0441" published="2004-12-22" name="CVE-2005-0441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19980" source="XF" patch="1" adv="1">sybase-ase-install-java-bo(19980)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19979" source="XF" patch="1" adv="1">sybase-ase-abstract-bo(19979)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19978" source="XF" patch="1" adv="1">sybase-ase-declare-bo(19978)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19976" source="XF" patch="1" adv="1">sybase-ase-convert-bo(19976)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19974" source="XF" patch="1" adv="1">sybase-ase-attribvalid-bo(19974)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19354" source="XF" patch="1" adv="1">sybase-adaptive-server(19354)</ref>
      <ref url="http://www.sybase.com/detail?id=1034752" source="CONFIRM" patch="1" adv="1">http://www.sybase.com/detail?id=1034752</ref>
      <ref url="http://www.sybase.com/detail?id=1034520" source="CONFIRM" patch="1" adv="1">http://www.sybase.com/detail?id=1034520</ref>
      <ref url="http://www.securityfocus.com/bid/12080" source="BID" patch="1" adv="1">12080</ref>
      <ref url="http://www.securityfocus.com/archive/1/393851" source="BUGTRAQ" patch="1" adv="1">20050321 Details of Sybase ASE bugs withheld</ref>
      <ref url="http://secunia.com/advisories/13632" source="SECUNIA" patch="1" adv="1">13632</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272918117194&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050405 Sybase ASE Multiple Security Issues (#NISR05042005)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0315.html" source="BUGTRAQ" patch="1" adv="1">20041222 Sybase ASE 12.5.2 vulnerabilities</ref>
      <ref url="http://www.ngssoftware.com/advisories/sybase-ase.txt" source="MISC" adv="1">http://www.ngssoftware.com/advisories/sybase-ase.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="adaptive_server_enterprise">
        <vers num="11.03.3" edition=""/>
        <vers num="11.03.3" edition=":linux"/>
        <vers num="11.5" edition=""/>
        <vers num="11.5" edition=":hp"/>
        <vers num="11.5" edition=":win"/>
        <vers num="11.5" edition=":sun"/>
        <vers num="11.5" edition=":digital_unix"/>
        <vers num="11.5.1" edition=""/>
        <vers num="11.5.1" edition=":sun"/>
        <vers num="11.5.1" edition=":win"/>
        <vers num="11.5.1" edition=":digital_unix"/>
        <vers num="11.5.1" edition=":hp"/>
        <vers num="11.9.2" edition=""/>
        <vers num="11.9.2" edition=":sun"/>
        <vers num="11.9.2" edition=":win"/>
        <vers num="11.9.2" edition=":digital_unix"/>
        <vers num="11.9.2" edition=":hp"/>
        <vers num="12.0" edition=""/>
        <vers num="12.0" edition=":hp"/>
        <vers num="12.0" edition=":win"/>
        <vers num="12.0" edition=":sun"/>
        <vers num="12.0" edition=":digital_unix"/>
        <vers num="12.0.1" edition=""/>
        <vers num="12.0.1" edition=":hp"/>
        <vers num="12.0.1" edition=":sun"/>
        <vers num="12.0.1" edition=":win"/>
        <vers num="12.0.1" edition=":digital_unix"/>
        <vers num="12.5" edition=""/>
        <vers num="12.5" edition=":hp"/>
        <vers num="12.5" edition=":sgi"/>
        <vers num="12.5" edition=":sun"/>
        <vers num="12.5" edition=":linux"/>
        <vers num="12.5" edition=":digital_unix"/>
        <vers num="12.5" edition=":win"/>
        <vers num="12.5.2"/>
        <vers num="12.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0442" published="2005-05-02" name="CVE-2005-0442" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12549" source="BID" patch="1">12549</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=5741" source="CONFIRM" patch="1" adv="1">http://www.cubecart.com/site/forums/index.php?showtopic=5741</ref>
      <ref url="http://secunia.com/advisories/14272" source="SECUNIA" patch="1" adv="1">14272</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19322" source="XF">cubecart-dotdot-directory-traversal(19322)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111281888605580&amp;w=2" source="BUGTRAQ" adv="1">20050406 RE: [NOBYTES.COM: #6] CubeCart 2.0.6 - Information Disclosure</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110842125901191&amp;w=2" source="BUGTRAQ" adv="1">20050214 [NOBYTES.COM: #2] CubeCart 2.0.4 - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.1"/>
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0443" published="2005-05-02" name="CVE-2005-0443" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12549" source="BID" patch="1">12549</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=5741" source="CONFIRM" patch="1" adv="1">http://www.cubecart.com/site/forums/index.php?showtopic=5741</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19328" source="XF">cubecart-index-xss(19328)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110842125901191&amp;w=2" source="BUGTRAQ" adv="1">20050214 [NOBYTES.COM: #2] CubeCart 2.0.4 - Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/14064" source="OSVDB">14064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.1"/>
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0444" published="2005-02-14" name="CVE-2005-0444" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-18.xml" source="GENTOO" adv="1">GLSA-200502-18</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="4.5.2_build_8848" edition="r4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0445" published="2005-05-02" name="CVE-2005-0445" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14253" source="SECUNIA" patch="1" adv="1">14253</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19335" source="XF">open-webmail-logindomain-xss(19335)</ref>
      <ref url="http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:01/2.5x.patch" source="CONFIRM">http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:01/2.5x.patch</ref>
      <ref url="http://turtle.ee.ncku.edu.tw/openwebmail/doc/changes.txt" source="CONFIRM">http://turtle.ee.ncku.edu.tw/openwebmail/doc/changes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12547" source="BID">12547</ref>
      <ref url="http://securitytracker.com/id?1013172" source="SECTRACK">1013172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_webmail" name="open_webmail">
        <vers num="2.00"/>
        <vers num="2.01"/>
        <vers num="2.10"/>
        <vers num="2.20"/>
        <vers num="2.21"/>
        <vers num="2.30"/>
        <vers num="2.32"/>
        <vers num="2.40"/>
        <vers num="2.41"/>
        <vers num="2.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0446" published="2005-05-02" name="CVE-2005-0446" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE8-dns_assert.patch" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE8-dns_assert.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE8-dns_assert" source="CONFIRM" patch="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE8-dns_assert</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-173.html" source="REDHAT" patch="1" adv="1">RHSA-2005:173</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-25</ref>
      <ref url="http://www.debian.org/security/2005/dsa-688" source="DEBIAN" patch="1" adv="1">DSA-688</ref>
      <ref url="http://secunia.com/advisories/14271" source="SECUNIA" patch="1" adv="1">14271</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" source="CONECTIVA" patch="1" adv="1">CLA-2005:931</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19332" source="XF">squid-xstrndup-dos(19332)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11264" source="OVAL">oval:org.mitre.oval:def:11264</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901183320453&amp;w=2" source="BUGTRAQ" adv="1">20050221 [USN-84-1] Squid vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/12551" source="BID">12551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-201.html" source="REDHAT">RHSA-2005:201</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:047" source="MANDRAKE">MDKSA-2005:047</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0.patch1"/>
        <vers num="2.0.patch2"/>
        <vers num="2.0.pre1"/>
        <vers num="2.0.release"/>
        <vers num="2.0_patch2"/>
        <vers num="2.1.patch1"/>
        <vers num="2.1.patch2"/>
        <vers num="2.1.pre1"/>
        <vers num="2.1.pre3"/>
        <vers num="2.1.pre4"/>
        <vers num="2.1.release"/>
        <vers num="2.1_patch2"/>
        <vers num="2.2.devel3"/>
        <vers num="2.2.devel4"/>
        <vers num="2.2.pre1"/>
        <vers num="2.2.pre2"/>
        <vers num="2.2.stable1"/>
        <vers num="2.2.stable2"/>
        <vers num="2.2.stable3"/>
        <vers num="2.2.stable4"/>
        <vers num="2.2.stable5"/>
        <vers num="2.3.devel2"/>
        <vers num="2.3.devel3"/>
        <vers num="2.3.stable1"/>
        <vers num="2.3.stable2"/>
        <vers num="2.3.stable3"/>
        <vers num="2.3.stable4"/>
        <vers num="2.3.stable5"/>
        <vers num="2.3_.stable4"/>
        <vers num="2.3_.stable5"/>
        <vers num="2.3_stable5"/>
        <vers num="2.4"/>
        <vers num="2.4.stable1"/>
        <vers num="2.4.stable2"/>
        <vers num="2.4.stable3"/>
        <vers num="2.4.stable4"/>
        <vers num="2.4.stable6"/>
        <vers num="2.4.stable7"/>
        <vers num="2.4_.stable2"/>
        <vers num="2.4_.stable6"/>
        <vers num="2.4_.stable7"/>
        <vers num="2.4_stable7"/>
        <vers num="2.5.6"/>
        <vers num="2.5.stable1"/>
        <vers num="2.5.stable2"/>
        <vers num="2.5.stable3"/>
        <vers num="2.5.stable4"/>
        <vers num="2.5.stable5"/>
        <vers num="2.5.stable6"/>
        <vers num="2.5.stable7"/>
        <vers num="2.5.stable8"/>
        <vers num="2.5_.stable1"/>
        <vers num="2.5_.stable3"/>
        <vers num="2.5_.stable4"/>
        <vers num="2.5_.stable5"/>
        <vers num="2.5_.stable6"/>
        <vers num="2.5_stable3"/>
        <vers num="2.5_stable4"/>
        <vers num="2.5_stable9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0447" published="2005-02-15" name="CVE-2005-0447" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14286" source="SECUNIA" patch="1" adv="1">14286</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19331" source="XF">solaris-arp-dos(19331)</ref>
      <ref url="http://www.securityfocus.com/bid/12553" source="BID">12553</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57673-1" source="SUNALERT">57673</ref>
      <ref url="http://securitytracker.com/id?1013179" source="SECTRACK">1013179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0448" published="2005-05-02" name="CVE-2005-0448" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-38</ref>
      <ref url="http://www.debian.org/security/2005/dsa-696" source="DEBIAN" patch="1" adv="1">DSA-696</ref>
      <ref url="http://www.securityfocus.com/advisories/8704" source="HP">HPSBUX01208</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10475" source="OVAL">oval:org.mitre.oval:def:10475</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-94-1" source="UBUNTU">USN-94-1</ref>
      <ref url="http://www.securityfocus.com/bid/12767" source="BID">12767</ref>
      <ref url="http://www.securityfocus.com/advisories/8704" source="HP">HPSBUX01208</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-881.html" source="REDHAT">RHSA-2005:881</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-674.html" source="REDHAT">RHSA-2005:674</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:079" source="MANDRIVA">MDKSA-2005:079</ref>
      <ref url="http://secunia.com/advisories/18517" source="SECUNIA">18517</ref>
      <ref url="http://secunia.com/advisories/18075" source="SECUNIA">18075</ref>
      <ref url="http://secunia.com/advisories/17079" source="SECUNIA">17079</ref>
      <ref url="http://secunia.com/advisories/14531" source="SECUNIA">14531</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056" source="CONECTIVA">CLSA-2006:1056</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U" source="SGI">20060101-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:728" source="OVAL" sig="1">oval:org.mitre.oval:def:728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.8.0"/>
        <vers num="5.8.1"/>
        <vers num="5.8.3"/>
        <vers num="5.8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0449" published="2005-05-02" name="CVE-2005-0449" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-284.html" source="REDHAT" patch="1" adv="1">RHSA-2005:284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-283.html" source="REDHAT" patch="1" adv="1">RHSA-2005:283</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945" source="CONECTIVA" patch="1">CLA-2005:945</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-82-1" source="UBUNTU">USN-82-1</ref>
      <ref url="http://www.securityfocus.com/bid/12598" source="BID">12598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" source="MANDRAKE">MDKSA-2005:218</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1018" source="DEBIAN">DSA-1018</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA" adv="1">19607</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA" adv="1">19374</ref>
      <ref url="http://secunia.com/advisories/19369" source="SECUNIA" adv="1">19369</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10753" source="OVAL">oval:org.mitre.oval:def:10753</ref>
      <ref url="http://oss.sgi.com/archives/netdev/2005-01/msg01036.html" source="MLIST" adv="1">[netdev] 20050124 Re: skb_checksum_help</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0450" published="2005-05-02" name="CVE-2005-0450" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013191" source="SECTRACK" adv="1">1013191</ref>
      <ref url="http://secunia.com/advisories/14283" source="SECUNIA" adv="1">14283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sami" name="sami_http_server">
        <vers num="1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0451" published="2005-05-02" name="CVE-2005-0451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013191" source="SECTRACK" adv="1">1013191</ref>
      <ref url="http://secunia.com/advisories/14283" source="SECUNIA" adv="1">14283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sami" name="sami_http_server">
        <vers num="1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0452" published="2005-02-16" name="CVE-2005-0452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "&lt;".</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12574" source="BID" adv="1">12574</ref>
      <ref url="http://secunia.com/advisories/14214" source="SECUNIA" adv="1">14214</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2" source="BUGTRAQ" adv="1">20050217 XSS vulnerabilty in ASP.Net [with details]</ref>
      <ref url="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml" source="MISC" adv="1">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="1.0" edition="sp1"/>
        <vers num="1.0" edition="sp2"/>
        <vers num="1.1" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0453" published="2005-02-16" name="CVE-2005-0453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-21.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-21</ref>
      <ref url="http://secunia.com/advisories/14297" source="SECUNIA" patch="1" adv="1">14297</ref>
      <ref url="http://article.gmane.org/gmane.comp.web.lighttpd/1171" source="CONFIRM" patch="1" adv="1">http://article.gmane.org/gmane.comp.web.lighttpd/1171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lighttpd" name="lighttpd">
        <vers num="1.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0454" published="2005-05-02" name="CVE-2005-0454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.php, or (2) the mid or bid parameters to forums.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackgen.org/advisories/hackgen-2005-003.txt" source="MISC" adv="1">http://www.hackgen.org/advisories/hackgen-2005-003.txt</ref>
      <ref url="http://securitytracker.com/id?1013216" source="SECTRACK" adv="1">1013216</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110858497207809&amp;w=2" source="BUGTRAQ" adv="1">20050216 [hackgen-2005-#003] - SQL injection bugs in DCP-Portal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19361" source="XF">dcpportal-multiple-sql-injection(19361)</ref>
      <ref url="http://www.securityfocus.com/bid/12573" source="BID">12573</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419280/100/0/threaded" source="BUGTRAQ">20051211 [PHP-CHECKER] 99 potential SQL injection vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/108" source="SREASON">108</ref>
      <ref url="http://glide.stanford.edu/yichen/research/sec.pdf" source="MISC">http://glide.stanford.edu/yichen/research/sec.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codeworx_technologies" name="dcp-portal">
        <vers prev="1" num="6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0455" published="2005-05-02" name="CVE-2005-0455" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-265.html" source="REDHAT" patch="1" adv="1">RHSA-2005:265</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=209&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050301 RealNetworks RealPlayer .smil Buffer Overflow Vulnerability</ref>
      <ref url="http://service.real.com/help/faq/security/050224_player" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/050224_player</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10926" source="OVAL">oval:org.mitre.oval:def:10926</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-271.html" source="REDHAT">RHSA-2005:271</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0456" published="2005-01-12" name="CVE-2005-0456" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/882926" source="CERT-VN" adv="1">VU#882926</ref>
      <ref url="http://www.opera.com/linux/changelogs/754u2/" source="CONFIRM" patch="1" adv="1">http://www.opera.com/linux/changelogs/754u2/</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-17</ref>
      <ref url="http://secunia.com/advisories/13818/" source="SECUNIA" patch="1" adv="1">13818</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18867" source="XF" adv="1">opera-data-dialog-spoofing(18867)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_31_opera.html" source="SUSE">SUSE-SA:2005:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":linux"/>
        <vers num="5.0" edition=":mac"/>
        <vers num="5.0.2" edition=""/>
        <vers num="5.0.2" edition=":win32"/>
        <vers num="5.1.0" edition=""/>
        <vers num="5.1.0" edition=":win32"/>
        <vers num="5.1.1" edition=""/>
        <vers num="5.1.1" edition=":win32"/>
        <vers num="5.12" edition=""/>
        <vers num="5.12" edition=":win32"/>
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":win32"/>
        <vers num="6.0.1" edition=""/>
        <vers num="6.0.1" edition=":win32"/>
        <vers num="6.0.1" edition=":linux"/>
        <vers num="6.0.2" edition=""/>
        <vers num="6.0.2" edition=":linux"/>
        <vers num="6.0.2" edition=":win32"/>
        <vers num="6.0.3" edition=""/>
        <vers num="6.0.3" edition=":linux"/>
        <vers num="6.0.3" edition=":win32"/>
        <vers num="6.0.4" edition=""/>
        <vers num="6.0.4" edition=":win32"/>
        <vers num="6.0.5" edition=""/>
        <vers num="6.0.5" edition=":win32"/>
        <vers num="6.0.6" edition=""/>
        <vers num="6.0.6" edition=":win32"/>
        <vers num="6.10" edition=""/>
        <vers num="6.10" edition=":linux"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":win32"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":win32"/>
        <vers num="7.0.3" edition=""/>
        <vers num="7.0.3" edition=":win32"/>
        <vers num="7.0_beta1" edition=""/>
        <vers num="7.0_beta1" edition=":win32"/>
        <vers num="7.0_beta2" edition=""/>
        <vers num="7.0_beta2" edition=":win32"/>
        <vers num="7.10"/>
        <vers num="7.11"/>
        <vers num="7.11b"/>
        <vers num="7.11j"/>
        <vers num="7.20"/>
        <vers num="7.20_beta1_build2981"/>
        <vers num="7.21"/>
        <vers num="7.22"/>
        <vers num="7.23"/>
        <vers num="7.50"/>
        <vers num="7.51"/>
        <vers num="7.52"/>
        <vers num="7.53"/>
        <vers num="7.54"/>
        <vers num="9.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0457" published="2005-05-02" name="CVE-2005-0457" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-17</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=81747" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=81747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.50"/>
        <vers num="7.50b1"/>
        <vers num="7.52"/>
        <vers num="7.53"/>
        <vers num="7.54"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0458" published="2005-05-02" name="CVE-2005-0458" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110851122614995&amp;w=2" source="BUGTRAQ" adv="1">20050215 [NOBYTES.COM: #3] osCommerce 2.2-MS2 - XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="oscommerce">
        <vers num="2.2_ms2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0459" published="2005-05-02" name="CVE-2005-0459" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013210" source="SECTRACK" adv="1">1013210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2_pre1"/>
        <vers num="2.2_rc1"/>
        <vers num="2.2_rc2"/>
        <vers num="2.2_rc3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.5_pl1"/>
        <vers num="2.5.5_rc1"/>
        <vers num="2.5.5_rc2"/>
        <vers num="2.5.6_rc1"/>
        <vers num="2.5.7"/>
        <vers num="2.5.7_pl1"/>
        <vers num="2.6.0_pl1"/>
        <vers num="2.6.0_pl2"/>
        <vers num="2.6.0_pl3"/>
        <vers num="2.6.2_dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0460" published="2005-05-02" name="CVE-2005-0460" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/13787" source="OSVDB" patch="1" adv="1">13787</ref>
      <ref url="http://secunia.com/advisories/14284" source="SECUNIA" patch="1" adv="1">14284</ref>
      <ref url="http://lostmon.blogspot.com/2005/02/mercuryboard-debug-information.html" source="MISC" patch="1" adv="1">http://lostmon.blogspot.com/2005/02/mercuryboard-debug-information.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0461" published="2005-05-02" name="CVE-2005-0461" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14262" source="SECUNIA" patch="1" adv="1">14262</ref>
      <ref url="http://newsbruiser.tigris.org/servlets/NewsItemView?newsItemID=1016" source="CONFIRM" patch="1">http://newsbruiser.tigris.org/servlets/NewsItemView?newsItemID=1016</ref>
      <ref url="http://newsbruiser.tigris.org/source/browse/newsbruiser/CHANGELOG?rev=1.283&amp;content-type=text/x-cvsweb-markup" source="CONFIRM">http://newsbruiser.tigris.org/source/browse/newsbruiser/CHANGELOG?rev=1.283&amp;content-type=text/x-cvsweb-markup</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0462" published="2005-02-17" name="CVE-2005-0462" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13937" source="SECUNIA" patch="1" adv="1">13937</ref>
      <ref url="http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html" source="MISC">http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercuryboard" name="mercuryboard">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0463" published="2005-05-02" name="CVE-2005-0463" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12610" source="BID" patch="1">12610</ref>
      <ref url="http://www.inl.fr/article.php3?id_article=7" source="CONFIRM" patch="1" adv="1">http://www.inl.fr/article.php3?id_article=7</ref>
      <ref url="http://securitytracker.com/id?1013220" source="SECTRACK" patch="1" adv="1">1013220</ref>
      <ref url="http://secunia.com/advisories/14321" source="SECUNIA" patch="1" adv="1">14321</ref>
      <ref url="http://www.osvdb.org/13853" source="OSVDB" adv="1">13853</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inl" name="ulog-php">
        <vers num="0.8"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0464" published="2005-05-02" name="CVE-2005-0464" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=226&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050407 SGI IRIX gr_osview Information Disclosure Vulnerability</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050402-01-P" source="SGI" patch="1">20050402-01-P</ref>
      <ref url="http://www.osvdb.org/15351" source="OSVDB">15351</ref>
      <ref url="http://securitytracker.com/id?1013662" source="SECTRACK">1013662</ref>
      <ref url="http://secunia.com/advisories/14875" source="SECUNIA">14875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0465" published="2005-05-02" name="CVE-2005-0465" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=225&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050407 SGI IRIX gr_osview File Overwrite Vulnerability</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050402-01-P" source="SGI" patch="1">20050402-01-P</ref>
      <ref url="http://securitytracker.com/id?1013662" source="SECTRACK">1013662</ref>
      <ref url="http://secunia.com/advisories/14875" source="SECUNIA">14875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.1t"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4b"/>
        <vers num="4.0.4t"/>
        <vers num="4.0.5"/>
        <vers num="4.0.5_iop"/>
        <vers num="4.0.5_ipr"/>
        <vers num="4.0.5a"/>
        <vers num="4.0.5b"/>
        <vers num="4.0.5e"/>
        <vers num="4.0.5f"/>
        <vers num="4.0.5g"/>
        <vers num="4.0.5h"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=""/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=""/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
        <vers num="6.5.22"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
        <vers num="6.5_20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0467" published="2005-02-21" name="CVE-2005-0467" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=201&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050221 Multiple PuTTY SFTP Client Packet Parsing Integer Overflow Vulnerabilities</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-28</ref>
      <ref url="http://secunia.com/advisories/14333" source="SECUNIA" patch="1" adv="1">14333</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19403" source="XF">putty-sftppktgetstring-bo(19403)</ref>
      <ref url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html" source="CONFIRM" adv="1">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html</ref>
      <ref url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html" source="CONFIRM" adv="1">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414</ref>
      <ref url="http://secunia.com/advisories/17214" source="SECUNIA">17214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="putty" name="putty">
        <vers prev="1" num="0.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0468" published="2005-05-02" name="CVE-2005-0468" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/341908" source="CERT-VN">VU#341908</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-330.html" source="REDHAT" patch="1" adv="1">RHSA-2005:330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-327.html" source="REDHAT" patch="1" adv="1">RHSA-2005:327</ref>
      <ref url="http://www.debian.org/security/2005/dsa-703" source="DEBIAN" patch="1" adv="1">DSA-703</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050405-01-P" source="SGI" patch="1">20050405-01-P</ref>
      <ref url="http://www.ubuntulinux.org/usn/usn-224-1" source="UBUNTU">USN-224-1</ref>
      <ref url="http://www.securityfocus.com/bid/12919" source="BID">12919</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=221&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050328 Multiple Telnet Client env_opt_add() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.debian.de/security/2005/dsa-731" source="DEBIAN">DSA-731</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1" source="SUNALERT">57761</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1" source="SUNALERT">57755</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1" source="SUNALERT">101671</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1" source="SUNALERT">101665</ref>
      <ref url="http://secunia.com/advisories/17899" source="SECUNIA">17899</ref>
      <ref url="http://secunia.com/advisories/14745" source="SECUNIA">14745</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9640" source="OVAL">oval:org.mitre.oval:def:9640</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000962" source="CONECTIVA">CLA-2005:962</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc" source="FREEBSD" adv="1">FreeBSD-SA-05:01.telnet</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:061" source="MANDRAKE">MDKSA-2005:061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncsa" name="telnet">
        <vers num="c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0469" published="2005-05-02" name="CVE-2005-0469" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/291924" source="CERT-VN" adv="1">VU#291924</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-330.html" source="REDHAT" patch="1" adv="1">RHSA-2005:330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-327.html" source="REDHAT" patch="1" adv="1">RHSA-2005:327</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=220&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050328 Multiple Telnet Client slc_add_reply() Buffer Overflow Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-36.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-36</ref>
      <ref url="http://www.debian.org/security/2005/dsa-703" source="DEBIAN" patch="1" adv="1">DSA-703</ref>
      <ref url="http://www.debian.org/security/2005/dsa-699" source="DEBIAN" patch="1" adv="1">DSA-699</ref>
      <ref url="http://www.debian.org/security/2005/dsa-697" source="DEBIAN" patch="1" adv="1">DSA-697</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1" source="SUNALERT" patch="1" adv="1">57755</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20050405-01-P" source="SGI" patch="1">20050405-01-P</ref>
      <ref url="http://www.ubuntulinux.org/usn/usn-224-1" source="UBUNTU">USN-224-1</ref>
      <ref url="http://www.securityfocus.com/bid/12918" source="BID">12918</ref>
      <ref url="http://www.debian.de/security/2005/dsa-731" source="DEBIAN">DSA-731</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1" source="SUNALERT">57761</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1" source="SUNALERT">101671</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1" source="SUNALERT">101665</ref>
      <ref url="http://secunia.com/advisories/17899" source="SECUNIA">17899</ref>
      <ref url="http://secunia.com/advisories/14745" source="SECUNIA">14745</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9708" source="OVAL">oval:org.mitre.oval:def:9708</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc" source="FREEBSD" adv="1">FreeBSD-SA-05:01.telnet</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:061" source="MANDRAKE">MDKSA-2005:061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncsa" name="telnet">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0470" published="2005-03-14" name="CVE-2005-0470" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19357" source="XF" patch="1" adv="1">wpasupplicant-bo(19357)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-22</ref>
      <ref url="http://secunia.com/advisories/14313" source="SECUNIA" patch="1" adv="1">14313</ref>
      <ref url="http://securitytracker.com/id?1013226" source="SECTRACK">1013226</ref>
      <ref url="http://lists.shmoo.com/pipermail/hostap/2005-February/009465.html" source="MLIST">[HostAP] 20050213 wpa_supplicant - new stable releases v0.3.8 and v0.2.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wpa_supplicant" name="wpa_supplicant">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.2.2"/>
        <vers num="0.2.3"/>
        <vers num="0.2.4"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":x86_64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0471" published="2005-03-14" name="CVE-2005-0471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/544392" source="CERT-VN" adv="1">VU#544392</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19285" source="XF">sun-java-create-files(19285)</ref>
      <ref url="http://secunia.com/secunia_research/2004-7/advisory/" source="MISC">http://secunia.com/secunia_research/2004-7/advisory/</ref>
      <ref url="http://secunia.com/advisories/11070/" source="SECUNIA" adv="1">11070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.1.0"/>
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers num="1.4.0"/>
        <vers num="1.5.0"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3.0"/>
        <vers num="1.4"/>
        <vers num="1.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0472" published="2005-03-14" name="CVE-2005-0472" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/839280" source="CERT-VN" patch="1" adv="1">VU#839280</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19380" source="XF" patch="1" adv="1">gaim-snac-dos(19380)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-432.html" source="REDHAT">RHSA-2005:432</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-215.html" source="REDHAT">RHSA-2005:215</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml" source="GENTOO">GLSA-200503-03</ref>
      <ref url="http://www.debian.org/security/2005/dsa-716" source="DEBIAN">DSA-716</ref>
      <ref url="http://secunia.com/advisories/14322" source="SECUNIA">14322</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10433" source="OVAL">oval:org.mitre.oval:def:10433</ref>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=10" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/index.php?id=10</ref>
      <ref url="http://www.securityfocus.com/bid/12589" source="BID">12589</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049" source="MANDRAKE">MDKSA-2005:049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2" source="BUGTRAQ">20050225 [USN-85-1] Gaim vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933" source="CONECTIVA">CLA-2005:933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="10.1" edition=""/>
        <vers num="10.1" edition=":x86_64"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":x86_64"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0473" published="2005-03-14" name="CVE-2005-0473" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/523888" source="CERT-VN" patch="1" adv="1">VU#523888</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19381" source="XF" patch="1" adv="1">gaim-html-dos(19381)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-215.html" source="REDHAT" patch="1" adv="1">RHSA-2005:215</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml" source="GENTOO">GLSA-200503-03</ref>
      <ref url="http://secunia.com/advisories/14322" source="SECUNIA">14322</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10212" source="OVAL">oval:org.mitre.oval:def:10212</ref>
      <ref url="http://gaim.sourceforge.net/security/index.php?id=11" source="CONFIRM">http://gaim.sourceforge.net/security/index.php?id=11</ref>
      <ref url="http://www.securityfocus.com/bid/12589" source="BID">12589</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded" source="FEDORA">FLSA:158543</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html" source="SUSE">SUSE-SA:2005:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049" source="MANDRAKE">MDKSA-2005:049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2" source="BUGTRAQ">20050225 [USN-85-1] Gaim vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933" source="CONECTIVA">CLA-2005:933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="10.1" edition=""/>
        <vers num="10.1" edition=":x86_64"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":x86_64"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0474" published="2005-03-30" name="CVE-2005-0474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19369" source="XF" patch="1" adv="1">webcalendar-sql-injection(19369)</ref>
      <ref url="http://www.scovettalabs.com/advisory/SCL-2005.001.txt" source="MISC" patch="1" adv="1">http://www.scovettalabs.com/advisory/SCL-2005.001.txt</ref>
      <ref url="http://secunia.com/advisories/14319" source="SECUNIA" patch="1" adv="1">14319</ref>
      <ref url="http://www.osvdb.org/13918" source="OSVDB">13918</ref>
      <ref url="http://securitytracker.com/id?1013231" source="SECTRACK">1013231</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868446431706&amp;w=2" source="BUGTRAQ">20050217 [ SCL-2005.001 ] - WebCalendar: SQL Injection from encoded cookie</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="0.9.45"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0475" published="2005-03-30" name="CVE-2005-0475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868808723487&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050217 [PersianHacker.NET 200505-07] paFAQ Beta4 Sql Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19371" source="XF" adv="1">pafaq-sql-injection(19371)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafaq">
        <vers num="beta4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0476" published="2005-03-30" name="CVE-2005-0476" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19372" source="XF">hpm-guestbook-xss(19372)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110869187805397&amp;w=2" source="BUGTRAQ">20050217 hpm_guestbook.cgi JavaScript-Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hpm_guestbook.cgi" name="hpm_guestbook.cgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0477" published="2005-03-30" name="CVE-2005-0477" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19399" source="XF">invision-power-board-sml-xss(19399)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868196922995&amp;w=2" source="BUGTRAQ" adv="1">20050217 Invision Power Boards 1.3.1 FINAL XSS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3.1_final"/>
        <vers num="1.3_final"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0478" published="2005-03-30" name="CVE-2005-0478" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19411" source="XF">trackercam-php-bo(19411)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19409" source="XF">trackercam-useragent-bo(19409)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0479" published="2005-03-30" name="CVE-2005-0479" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." sequences and (1) "/" slash), (2) "\" (backslash), or (3) hex-encoded characters in the fn parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19414" source="XF">trackercam-fn-directory-traversal(19414)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0480" published="2005-03-30" name="CVE-2005-0480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and earlier allows remote attackers to inject arbitrary HTML or web script via the login request, which is recorded in a log file but not properly handled when the administrator views the log file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19416" source="XF">trackercam-xss(19416)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0481" published="2005-03-30" name="CVE-2005-0481" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19415" source="XF">trackercam-fn-path-disclosure(19415)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0482" published="2005-03-30" name="CVE-2005-0482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TrackerCam 5.12 and earlier allows remote attackers to cause a denial of service (crash) via (1) a large number of connections with a negative Content-Length header, possibly triggering an integer signedness error, or (2) a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19417" source="XF">trackercam-contentlength-dos(19417)</ref>
      <ref url="http://www.securityfocus.com/bid/12592" source="BID" adv="1">12592</ref>
      <ref url="http://www.securityfocus.com/archive/1/390918" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in TrackerCam 5.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trackercam" name="trackercam">
        <vers prev="1" num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0483" published="2005-03-30" name="CVE-2005-0483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19401" source="XF">glftpd-sitenfosh-directory-traversal(19401)</ref>
      <ref url="http://www.securityfocus.com/bid/12586" source="BID" adv="1">12586</ref>
      <ref url="http://www.securityfocus.com/archive/1/390924" source="BUGTRAQ" adv="1">20050218 Multiple vulnerabilities in Glftpd v1.26 - v2.00 default zip based plug-ins</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glftpd" name="glftpd">
        <vers num="1.26"/>
        <vers num="1.27"/>
        <vers num="1.28"/>
        <vers num="1.29.1"/>
        <vers num="1.31"/>
        <vers num="1.32"/>
        <vers num="2.0"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
        <vers num="2.0_rc4"/>
        <vers num="2.0_rc5"/>
        <vers num="2.0_rc6"/>
        <vers num="2.0_rc7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0484" published="2005-03-30" name="CVE-2005-0484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200502-26.xml" source="GENTOO" adv="1">GLSA-200502-26</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=81894" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=81894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gproftpd" name="gproftpd">
        <vers prev="1" num="8.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0485" published="2005-03-30" name="CVE-2005-0485" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110863062605906&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050216 [PersianHacker.NET 200505-06] paNews v2.0b4 XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19359" source="XF" adv="1">panews-commentphp-xss(19359)</ref>
      <ref url="http://www.securityfocus.com/bid/12576" source="BID" adv="1">12576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="panews">
        <vers num="2.0_b4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0486" published="2005-03-30" name="CVE-2005-0486" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.tarantella.com/security/bulletin-11.html" source="CONFIRM" patch="1" adv="1">http://www.tarantella.com/security/bulletin-11.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19407" source="XF">tarantella-enterprise-obtain-information(19407)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tarantella" name="secure_global_desktop">
        <vers num="enterprise_3.42"/>
        <vers num="enterprise_4.0"/>
      </prod>
      <prod vendor="tarantella" name="tarantella_enterprise">
        <vers num="3.30"/>
        <vers num="3.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0487" published="2005-03-30" name="CVE-2005-0487" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18571" source="XF">kayako-index-xss(18571)</ref>
      <ref url="http://www.securityfocus.com/bid/12563" source="BID" adv="1">12563</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110845724029888&amp;w=2" source="FULLDISC" adv="1">20050215 Kayako eSupport v2.3.1 Support Tracker XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="esupport">
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0488" published="2005-06-14" name="CVE-2005-0488" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/800829" source="CERT-VN" patch="1" adv="1">VU#800829</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1" source="SUNALERT" patch="1" adv="1">57761</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1" source="SUNALERT" patch="1" adv="1">57755</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-504.html" source="REDHAT">RHSA-2005:504</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_16_sr.html" source="SUSE">SUSE-SR:2005:016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11373" source="OVAL">oval:org.mitre.oval:def:11373</ref>
      <ref url="http://idefense.com/application/poi/display?id=260&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050614 Multiple Vendor Telnet Client Information Disclosure Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.securityfocus.com/bid/13940" source="BID">13940</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-562.html" source="REDHAT">RHSA-2005:562</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1" source="SUNALERT">101671</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1" source="SUNALERT">101665</ref>
      <ref url="http://securitytracker.com/id?1014203" source="SECTRACK">1014203</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA">17135</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1139" source="OVAL" sig="1">oval:org.mitre.oval:def:1139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="telnet_client">
        <vers num="5.1.2600.2180"/>
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.3.4"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0489" published="2005-12-31" name="CVE-2005-0489" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.27</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18173" source="BID" patch="1">18173</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN" patch="1" adv="1">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN" patch="1" adv="1">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN" patch="1" adv="1">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN" patch="1" adv="1">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA" patch="1" adv="1">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA" patch="1" adv="1">20163</ref>
      <ref url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes" source="CONFIRM" patch="1">http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0490" published="2005-05-02" name="CVE-2005-0490" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-20</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110959085507755&amp;w=2" source="FULLDISC" patch="1" adv="1">20050228 [USN-86-1] cURL vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000940" source="CONECTIVA" patch="1" adv="1">CLA-2005:940</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19423" source="XF">curl-kerberos-bo(19423)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=203&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050221 Multiple Unix/Linux Vendor cURL/libcURL Kerberos Authentication Buffer Overflow Vulnerability</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=202&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20050221 Multiple Unix/Linux Vendor cURL/libcURL NTLM Authentication Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10273" source="OVAL">oval:org.mitre.oval:def:10273</ref>
      <ref url="http://www.securityfocus.com/bid/12616" source="BID">12616</ref>
      <ref url="http://www.securityfocus.com/bid/12615" source="BID">12615</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-340.html" source="REDHAT">RHSA-2005:340</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_11_curl.html" source="SUSE">SUSE-SA:2005:011</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:048" source="MANDRAKE">MDKSA-2005:048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="curl" name="curl">
        <vers num="7.12.1"/>
      </prod>
      <prod vendor="libcurl" name="libcurl">
        <vers num="7.12.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0491" published="2005-05-02" name="CVE-2005-0491" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12594" source="BID" patch="1">12594</ref>
      <ref url="http://secunia.com/advisories/14327" source="SECUNIA" patch="1" adv="1">14327</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19398" source="XF">arkeia-backup-client-bo(19398)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110887325425794&amp;w=2" source="BUGTRAQ" adv="1">20050218 Knox Arkeia remote root/system exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knox_software" name="arkeia_server_backup">
        <vers num="5.3.0"/>
        <vers num="5.3.0_rc1"/>
        <vers num="5.3.0_rc2"/>
        <vers num="5.3.0_rc3"/>
        <vers num="5.3.0_rc4"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0492" published="2005-05-02" name="CVE-2005-0492" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/331468.html" source="CONFIRM" patch="1">http://www.adobe.com/support/techdocs/331468.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19946" source="XF">adobe-root-page-node-dos(19946)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0310" source="VUPEN">ADV-2005-0310</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110879063511486&amp;w=2" source="BUGTRAQ" adv="1">20050218 Adobe Reader invalid root page node Count value DOS</ref>
      <ref url="http://secunia.com/advisories/14813" source="SECUNIA">14813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0.3"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0493" published="2005-05-02" name="CVE-2005-0493" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam e-mail via CRLF sequences and forged mail headers in the email parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to newest version.</sol>
    </sols>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110876655521321&amp;w=2" source="BUGTRAQ" adv="1">20050218 BizMail 2.1 Spam Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seth_m._knorr" name="biz_mail_form">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0494" published="2005-02-21" name="CVE-2005-0494" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19387" source="XF">thomson-tcw690-gain-access(19387)</ref>
      <ref url="http://secunia.com/advisories/14353" source="SECUNIA" adv="1">14353</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886937131507&amp;w=2" source="BUGTRAQ" adv="1">20050219 Thomson TCW690 POST Password Validation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomson" name="thomson_cable_modem">
        <vers num="tcw690"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0495" published="2005-02-19" name="CVE-2005-0495" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19420" source="XF">zeroboard-xss(19420)</ref>
      <ref url="http://securitytracker.com/id?1013243" source="SECTRACK" adv="1">1013243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110884332105513&amp;w=2" source="BUGTRAQ" adv="1">20050219 Multiples vulnerability in ZeroBoard,</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2"/>
        <vers num="4.1_pl3"/>
        <vers num="4.1_pl4"/>
        <vers num="4.1_pl5"/>
        <vers num="4.1_pl6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0496" published="2005-02-21" name="CVE-2005-0496" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20667" source="XF">arkeia-backup-client-gain-access(20667)</ref>
      <ref url="http://securitytracker.com/id?1013256" source="SECTRACK" adv="1">1013256</ref>
      <ref url="http://metasploit.com/research/arkeia_agent/" source="MISC" adv="1">http://metasploit.com/research/arkeia_agent/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900879826004&amp;w=2" source="BUGTRAQ" adv="1">20050220 Arkeia Network Backup Client Remote Access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knox_software" name="arkeia">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0497" published="2005-05-02" name="CVE-2005-0497" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901051420503&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050219 ADP Elite System Max 9000 Series Login Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20622" source="XF">adp-elite-gain-privileges(20622)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adp" name="elite_system_max_9000">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0498" published="2005-05-02" name="CVE-2005-0498" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19422" source="XF">gigafast-backupcfg-plaintext-password(19422)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900986022760&amp;w=2" source="BUGTRAQ" adv="1">20050220 Gigafast/CompUSA router (model EE400-R) vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigafast_ethernet" name="gigafast_router">
        <vers num="ee400-r"/>
        <vers num="ee410-r"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0499" published="2005-02-20" name="CVE-2005-0499" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19426" source="XF">gigafast-dns-queries-dos(19426)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900986022760&amp;w=2" source="BUGTRAQ" adv="1">20050220 Gigafast/CompUSA router (model EE400-R) vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigafast_ethernet" name="gigafast_router">
        <vers num="ee400-r"/>
        <vers num="ee410-r"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0500" published="2005-05-02" name="CVE-2005-0500" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19452" source="XF">ie-title-bar-spoofing(19452)</ref>
      <ref url="http://www.securityfocus.com/bid/12602" source="BID">12602</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110895997201027&amp;w=2" source="FULLDISC" adv="1">20050221 WindowsXPSP2 script-initiated popup window</ref>
      <ref url="http://secunia.com/advisories/14335" source="SECUNIA">14335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0501" published="2005-05-02" name="CVE-2005-0501" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Bontago 1.1 and earlier allows remote attackers exeucte arbitrary code via a long nickname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19406" source="XF">bontago-nickname-bo(19406)</ref>
      <ref url="http://www.securityfocus.com/bid/12603" source="BID">12603</ref>
      <ref url="http://secunia.com/advisories/14350" source="SECUNIA" adv="1">14350</ref>
      <ref url="http://aluigi.altervista.org/adv/bontagobof-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/bontagobof-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digipen_institute_of_technology" name="bontago">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0502" published="2005-02-18" name="CVE-2005-0502" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19404" source="XF">xinkaa-web-directory-traversal(19404)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0189" source="VUPEN">ADV-2005-0189</ref>
      <ref url="http://www.securityfocus.com/bid/12606" source="BID">12606</ref>
      <ref url="http://secunia.com/advisories/14349" source="SECUNIA" adv="1">14349</ref>
      <ref url="http://aluigi.altervista.org/adv/xinkaa-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/xinkaa-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xinkaa_web_station" name="xinkaa_web_station">
        <vers num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0503" published="2005-02-21" name="CVE-2005-0503" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12604" source="BID" patch="1" adv="1">12604</ref>
      <ref url="http://secunia.com/advisories/13981" source="SECUNIA" patch="1" adv="1">13981</ref>
      <ref url="http://lists.freedesktop.org/archives/uim/2005-February/000996.html" source="MLIST" adv="1">[uim] 20050220 uim 0.4.5.1 released</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:046" source="MANDRAKE">MDKSA-2005:046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uim" name="uim">
        <vers num="0.4.5"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition=""/>
        <vers num="10.1" edition=":x86_64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0504" published="2005-03-14" name="CVE-2005-0504" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12195" source="BID" patch="1" adv="1">12195</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.ubuntu.com/usn/usn-508-1" source="UBUNTU">USN-508-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-551.html" source="REDHAT">RHSA-2005:551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-529.html" source="REDHAT">RHSA-2005:529</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://securitytracker.com/id?1013273" source="SECTRACK">1013273</ref>
      <ref url="http://secunia.com/advisories/30112" source="SECUNIA">30112</ref>
      <ref url="http://secunia.com/advisories/26651" source="SECUNIA" adv="1">26651</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA" adv="1">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA" adv="1">20163</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA" adv="1">17002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9770" source="OVAL">oval:org.mitre.oval:def:9770</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" source="FULLDISC">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0237.html" source="REDHAT">RHSA-2008:0237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.15_pre20"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21"/>
        <vers num="2.2.22"/>
        <vers num="2.2.23"/>
        <vers num="2.2.24"/>
        <vers num="2.2.25"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.99" edition="pre1"/>
        <vers num="2.3.99" edition="pre2"/>
        <vers num="2.3.99" edition="pre3"/>
        <vers num="2.3.99" edition="pre4"/>
        <vers num="2.3.99" edition="pre5"/>
        <vers num="2.3.99" edition="pre6"/>
        <vers num="2.3.99" edition="pre7"/>
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.2"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.3"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.4"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.5"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.6"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.2"/>
        <vers prev="1" num="2.6.21" edition="rc7"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.9" edition="2.6.20"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0505" published="2005-03-14" name="CVE-2005-0505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers has "potentially serious" impact, related to LDAP logins.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19419" source="XF" patch="1" adv="1">irm-ldap-security-bypass(19419)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=306629" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=306629</ref>
      <ref url="http://secunia.com/advisories/14342" source="SECUNIA" patch="1" adv="1">14342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stackworks_enterprises" name="information_resource_manager">
        <vers num="1.4.3"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0506" published="2005-03-14" name="CVE-2005-0506" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-041_Sensitive_Info_Leak.pdf" source="CONFIRM" adv="1">http://support.avaya.com/elmodocs2/security/ASA-2005-041_Sensitive_Info_Leak.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910486128709&amp;w=2" source="BUGTRAQ" adv="1">20050222 Re: Avaya IP Office Phone Manager - Sensitive Information Cleartext Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110909733831694&amp;w=2" source="BUGTRAQ" adv="1">20050222 Avaya IP Office Phone Manager - Sensitive Information Cleartext</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip_office_phone_manager">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="ip_soft_phone">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0507" published="2005-03-14" name="CVE-2005-0507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SD Server 4.0.70 and earlier allows remote attackers to read arbitrary files via .. sequences in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14365" source="SECUNIA" patch="1" adv="1">14365</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110901639709476&amp;w=2" source="FULLDISC" patch="1" adv="1">20050221 SD Server 4.0.70 Directory Traversal Bug</ref>
      <ref url="http://www.gdsoftware.dk/" source="CONFIRM">http://www.gdsoftware.dk/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910535122762&amp;w=2" source="BUGTRAQ">20050222 SD Server 4.0.70 Directory Traversal Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gd_software" name="sd_server">
        <vers num="4.0.70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0508" published="2005-03-14" name="CVE-2005-0508" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12619" source="BID" patch="1" adv="1">12619</ref>
      <ref url="http://secunia.com/advisories/14336" source="SECUNIA" patch="1" adv="1">14336</ref>
      <ref url="http://xml.apache.org/batik/#SecurityWarning" source="CONFIRM">http://xml.apache.org/batik/#SecurityWarning</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0509" published="2005-03-14" name="CVE-2005-0509" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "&lt;".</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14325" source="SECUNIA" patch="1" adv="1">14325</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2" source="BUGTRAQ">20050217 XSS vulnerabilty in ASP.Net [with details]</ref>
      <ref url="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml" source="MISC">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp1"/>
        <vers num="1.0" edition="sp2"/>
        <vers num="1.1" edition="sp1"/>
      </prod>
      <prod vendor="mono" name="mono">
        <vers num="1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0510" published="2005-03-14" name="CVE-2005-0510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14328" source="SECUNIA" patch="1" adv="1">14328</ref>
      <ref url="http://dcs.nac.uci.edu/~strombrg/fallback-reboot/" source="CONFIRM" adv="1">http://dcs.nac.uci.edu/~strombrg/fallback-reboot/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fallback-reboot" name="fallback-reboot">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0511" published="2005-02-21" name="CVE-2005-0511" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14326" source="SECUNIA" patch="1" adv="1">14326</ref>
      <ref url="http://www.vbulletin.com/forum/showthread.php?postid=819562" source="CONFIRM">http://www.vbulletin.com/forum/showthread.php?postid=819562</ref>
      <ref url="http://www.securityfocus.com/bid/12622" source="BID">12622</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910899415763&amp;w=2" source="BUGTRAQ" adv="1">20050222 [SCAN Associates Security Advisory] vbulletin 3.0.6 and below php code injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0_beta_2"/>
        <vers num="2.0_beta_3"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9_can"/>
        <vers num="2.3.0"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0_beta_2"/>
        <vers num="3.0.0_can4"/>
        <vers num="3.0.0_rc4"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0_beta_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0512" published="2005-02-21" name="CVE-2005-0512" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14337" source="SECUNIA" patch="1" adv="1">14337</ref>
      <ref url="http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip" source="CONFIRM" patch="1">http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo">
        <vers prev="1" num="4.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0513" published="2005-02-19" name="CVE-2005-0513" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying the pm_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2003-1086.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12597" source="BID" patch="1" adv="1">12597</ref>
      <ref url="http://www.securityfocus.com/bid/15473" source="BID">15473</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110883604531802&amp;w=2" source="FULLDISC" adv="1">20050219 pMachine Pro / pMachine Free Remote Code Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmachine" name="pmachine_pro">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0514" published="2005-02-22" name="CVE-2005-0514" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/716144" source="CERT-VN" patch="1" adv="1">VU#716144</ref>
      <ref url="http://www.mikx.de/index.php?p=6" source="MISC" patch="1" adv="1">http://www.mikx.de/index.php?p=6</ref>
      <ref url="http://secunia.com/advisories/14367" source="SECUNIA" patch="1" adv="1">14367</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html" source="FULLDISC" adv="1">20041223 Cross-Site Scripting - an industry-wide problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verity" name="verity_ultraseek">
        <vers num="5.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0515" published="2005-05-18" name="CVE-2005-0515" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary files by saving log files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.webroot.com/services/mfp_advisory.php" source="CONFIRM" patch="1" adv="1">http://www.webroot.com/services/mfp_advisory.php</ref>
      <ref url="http://www.securityfocus.com/bid/12842" source="BID" patch="1" adv="1">12842</ref>
      <ref url="http://secunia.com/secunia_research/2004-20/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2004-20/advisory/</ref>
      <ref url="http://secunia.com/advisories/13577" source="SECUNIA" patch="1" adv="1">13577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webroot_software" name="my_firewall_plus">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0516" published="2005-02-23" name="CVE-2005-0516" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/14384" source="SECUNIA" patch="1" adv="1">14384</ref>
      <ref url="http://www.enyo.de/fw/security/notes/twiki-robustness.html" source="MISC" adv="1">http://www.enyo.de/fw/security/notes/twiki-robustness.html</ref>
      <ref url="http://static.enyo.de/fw/patches/twiki/imagegallery-robustness-20041128.diff" source="MISC" adv="1">http://static.enyo.de/fw/patches/twiki/imagegallery-robustness-20041128.diff</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110918725225288&amp;w=2" source="BUGTRAQ" adv="1">20050223 Robustness patch for TWiki, vulnerability in ImageGalleryPlugin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="twiki" name="imagegalleryplugin">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0517" published="2005-02-23" name="CVE-2005-0517" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013263" source="SECTRACK" adv="1">1013263</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peerftp_5" name="peerftp_5">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0518" published="2005-02-23" name="CVE-2005-0518" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013266" source="SECTRACK" adv="1">1013266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exeem" name="exeem">
        <vers num="0.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0519" published="2005-02-18" name="CVE-2005-0519" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.argosoft.com/ftpserver/changelist.aspx" source="CONFIRM" patch="1" adv="1">http://www.argosoft.com/ftpserver/changelist.aspx</ref>
      <ref url="http://secunia.com/advisories/14172" source="SECUNIA" patch="1">14172</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17939" source="XF">argosoft-ink-file-upload(17939)</ref>
      <ref url="http://www.securityfocus.com/bid/12487" source="BID">12487</ref>
      <ref url="http://www.osvdb.org/13614" source="OSVDB">13614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="ftp_server">
        <vers num="1.4.1.1"/>
        <vers num="1.4.1.2"/>
        <vers num="1.4.1.3"/>
        <vers num="1.4.1.4"/>
        <vers num="1.4.1.5"/>
        <vers num="1.4.1.6"/>
        <vers num="1.4.1.7"/>
        <vers num="1.4.1.8"/>
        <vers num="1.4.1.9"/>
        <vers num="1.4.2"/>
        <vers num="1.4.2.1"/>
        <vers num="1.4.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0520" published="2005-02-23" name="CVE-2005-0520" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.argosoft.com/ftpserver/changelist.aspx" source="CONFIRM" patch="1" adv="1">http://www.argosoft.com/ftpserver/changelist.aspx</ref>
      <ref url="http://secunia.com/advisories/14372" source="SECUNIA" patch="1" adv="1">14372</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19442" source="XF">argosoft-site-copy-files(19442)</ref>
      <ref url="http://www.securityfocus.com/bid/12632" source="BID">12632</ref>
      <ref url="http://www.osvdb.org/14061" source="OSVDB">14061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="ftp_server">
        <vers num="1.4.1.1"/>
        <vers num="1.4.1.2"/>
        <vers num="1.4.1.3"/>
        <vers num="1.4.1.4"/>
        <vers num="1.4.1.5"/>
        <vers num="1.4.1.6"/>
        <vers num="1.4.1.7"/>
        <vers num="1.4.1.8"/>
        <vers num="1.4.1.9"/>
        <vers num="1.4.2"/>
        <vers num="1.4.2.1"/>
        <vers num="1.4.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0521" published="2005-02-23" name="CVE-2005-0521" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013269" source="SECTRACK" adv="1">1013269</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0522" published="2005-05-02" name="CVE-2005-0522" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013270" source="SECTRACK">1013270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="chat_anywhere">
        <vers num="2.72a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0523" published="2005-05-02" name="CVE-2005-0523" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-719" source="DEBIAN" patch="1">DSA-719</ref>
      <ref url="http://www.securityfocus.com/bid/12635" source="BID">12635</ref>
      <ref url="http://www.securiteam.com/exploits/5WP082KEUW.html" source="MISC">http://www.securiteam.com/exploits/5WP082KEUW.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prozilla" name="prozilla_download_accelerator">
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.5.1"/>
        <vers num="1.3.5.2"/>
        <vers num="1.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0524" published="2005-05-02" name="CVE-2005-0524" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/394797" source="IDEFENSE" patch="1" adv="1">20050331 PHP getimagesize() Multiple Denial of Service Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1013619" source="SECTRACK" patch="1">1013619</ref>
      <ref url="http://secunia.com/advisories/14792" source="SECUNIA" patch="1">14792</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19920" source="XF">php-phphandleiff-dos(19920)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0305" source="VUPEN">ADV-2005-0305</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-406.html" source="REDHAT">RHSA-2005:406</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-405.html" source="REDHAT">RHSA-2005:405</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml" source="GENTOO">GLSA-200504-15</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9310" source="OVAL">oval:org.mitre.oval:def:9310</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
      <ref url="http://www.osvdb.org/15183" source="OSVDB">15183</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.2.2"/>
        <vers num="4.3.10"/>
        <vers num="4.3.9"/>
        <vers num="5.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0525" published="2005-05-02" name="CVE-2005-0525" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-708" source="DEBIAN" patch="1">DSA-708</ref>
      <ref url="http://secunia.com/advisories/14792" source="SECUNIA" patch="1">14792</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/0305" source="VUPEN">ADV-2005-0305</ref>
      <ref url="http://www.securityfocus.com/archive/1/394797" source="IDEFENSE" adv="1">20050331 PHP getimagesize() Multiple Denial of Service Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-406.html" source="REDHAT">RHSA-2005:406</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-405.html" source="REDHAT">RHSA-2005:405</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml" source="GENTOO">GLSA-200504-15</ref>
      <ref url="http://www.debian.org/security/2005/dsa-729" source="DEBIAN">DSA-729</ref>
      <ref url="http://securitytracker.com/id?1013619" source="SECTRACK">1013619</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11703" source="OVAL">oval:org.mitre.oval:def:11703</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html" source="APPLE">APPLE-SA-2005-06-08</ref>
      <ref url="http://www.osvdb.org/15184" source="OSVDB">15184</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.2.2"/>
        <vers num="4.3.10"/>
        <vers num="4.3.9"/>
        <vers num="5.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0526" published="2005-05-02" name="CVE-2005-0526" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PBLang 4.65 allow remote attackers to inject arbitrary web script or HTML via (1) the search string to search.php, (2) the subject of a PM, which is processed by pm.php, or (3) the body of a PM, which is processed by pmpshow.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013277" source="SECTRACK">1013277</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917768511595&amp;w=2" source="BUGTRAQ">20050222 Software PBLang 4.65 pm.php XSS vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917702708589&amp;w=2" source="BUGTRAQ">20050222 Software PBLang 4.65 pmpshow.php XSS vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917641105486&amp;w=2" source="BUGTRAQ">20050222 Software PBLang 4.65 search.php XSS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pblang" name="pblang">
        <vers num="4.65"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0527" published="2005-05-02" name="CVE-2005-0527" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO" patch="1">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO" patch="1">GLSA-200503-10</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-27.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-27.html</ref>
      <ref url="http://www.mikx.de/?p=11" source="MISC">http://www.mikx.de/?p=11</ref>
      <ref url="http://securitytracker.com/id?1013301" source="SECTRACK">1013301</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11772" source="OVAL">oval:org.mitre.oval:def:11772</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935267500395&amp;w=2" source="BUGTRAQ">20050225 Firescrolling [Firefox 1.0]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100031" source="OVAL" sig="1">oval:org.mitre.oval:def:100031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2005-0528" reject="1" published="2005-12-31" name="CVE-2005-0528" modified="2008-09-10" discovered="2004-01-05">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0985.  Reason: This candidate is a duplicate of CVE-2003-0985.  Notes: All CVE users should reference CVE-2003-0985 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0529" published="2005-05-02" name="CVE-2005-0529" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html" source="MISC" patch="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2" source="FULLDISC" patch="1">20050215 linux kernel 2.6 fun. windoze is a joke</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE">SUSE-SA:2005:018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8994" source="OVAL">oval:org.mitre.oval:def:8994</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@4201818eC6aMn0x3GY_9rw3ueb2ZWQ" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@4201818eC6aMn0x3GY_9rw3ueb2ZWQ</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10"/>
        <vers num="2.6.11_rc1_bk6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0530" published="2005-05-02" name="CVE-2005-0530" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Signedness error in the copy_from_read_buf function in n_tty.c for Linux kernel 2.6.10 and 2.6.11rc1 allows local users to read kernel memory via a negative argument.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html" source="MISC" patch="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2" source="FULLDISC" patch="1">20050215 linux kernel 2.6 fun. windoze is a joke</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE">SUSE-SA:2005:018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10960" source="OVAL">oval:org.mitre.oval:def:10960</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@420181322LZmhPTewcCOLkubGwOL3w" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@420181322LZmhPTewcCOLkubGwOL3w</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10"/>
        <vers num="2.6.11_rc1_bk6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0531" published="2005-05-02" name="CVE-2005-0531" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The atm_get_addr function in addr.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4 may allow local users to trigger a buffer overflow via negative arguments.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html" source="MISC" patch="1" adv="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2" source="FULLDISC" patch="1" adv="1">20050215 linux kernel 2.6 fun. windoze is a joke</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/gnupatch@4208e1fcfccuD-eH2OGM5mBhihmQ3A" source="CONFIRM" patch="1">http://linux.bkbits.net:8080/linux-2.6/gnupatch@4208e1fcfccuD-eH2OGM5mBhihmQ3A</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" patch="1">CLA-2005:930</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10095" source="OVAL">oval:org.mitre.oval:def:10095</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-366.html" source="REDHAT">RHSA-2005:366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2005-0532" published="2005-05-02" name="CVE-2005-0532" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The reiserfs_copy_from_user_to_file_region function in reiserfs/file.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4, when running on 64-bit architectures, may allow local users to trigger a buffer overflow as a result of casting discrepancies between size_t and int data types.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html" source="MISC" patch="1" adv="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2" source="FULLDISC" patch="1" adv="1">20050215 linux kernel 2.6 fun. windoze is a joke</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050315 [USN-95-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@42018227TkNpHlX6BefnItV_GqMmzQ" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@42018227TkNpHlX6BefnItV_GqMmzQ</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0533" published="2005-05-02" name="CVE-2005-0533" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+VSAPI+ARJ+parsing+could+allow+Remote+Code+execution" source="CONFIRM" patch="1">http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+VSAPI+ARJ+parsing+could+allow+Remote+Code+execution</ref>
      <ref url="http://www.securityfocus.com/bid/12643" source="BID" patch="1">12643</ref>
      <ref url="http://securitytracker.com/id?1013290" source="SECTRACK" patch="1" adv="1">1013290</ref>
      <ref url="http://securitytracker.com/id?1013289" source="SECTRACK" patch="1" adv="1">1013289</ref>
      <ref url="http://secunia.com/advisories/14396" source="SECUNIA" patch="1" adv="1">14396</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/189" source="ISS" adv="1">20050224 Trend Micro AntiVirus Library Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="client-server-messaging_suite_smb">
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":windows"/>
      </prod>
      <prod vendor="trend_micro" name="client-server_suite_smb">
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":windows"/>
      </prod>
      <prod vendor="trend_micro" name="control_manager">
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":windows"/>
        <vers num="gold" edition=":solaris"/>
        <vers num="gold" edition=":as_400"/>
        <vers num="gold" edition=":windows_nt"/>
        <vers num="gold" edition=":s_390"/>
        <vers num="netware"/>
      </prod>
      <prod vendor="trend_micro" name="interscan_emanager">
        <vers num="3.5" edition=""/>
        <vers num="3.5" edition=":hp"/>
        <vers num="3.5.2" edition=""/>
        <vers num="3.5.2" edition=":windows"/>
        <vers num="3.51"/>
        <vers num="3.51_j"/>
        <vers num="3.6" edition=""/>
        <vers num="3.6" edition=":linux"/>
        <vers num="3.6" edition=":sun"/>
      </prod>
      <prod vendor="trend_micro" name="interscan_messaging_security_suite">
        <vers num="3.81"/>
        <vers num="5.5"/>
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":windows"/>
        <vers num="gold" edition=":solaris"/>
        <vers num="gold" edition=":linux"/>
      </prod>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.0.1" edition=""/>
        <vers num="3.0.1" edition=":unix"/>
        <vers num="3.0.1" edition=":linux"/>
        <vers num="3.4" edition=""/>
        <vers num="3.4" edition=":windows_nt"/>
        <vers num="3.5" edition=""/>
        <vers num="3.5" edition=":windows_nt"/>
        <vers num="3.51" edition=""/>
        <vers num="3.51" edition=":windows_nt"/>
        <vers num="3.52" edition=""/>
        <vers num="3.52" edition=":windows_nt"/>
        <vers num="3.52_build1466" edition=""/>
        <vers num="3.52_build1466" edition=":windows_nt"/>
        <vers num="3.6" edition=""/>
        <vers num="3.6" edition=":windows_nt"/>
        <vers num="3.6" edition=":solaris"/>
        <vers num="3.6" edition=":unix"/>
        <vers num="3.6" edition=":hp_ux"/>
        <vers num="3.6.5" edition=""/>
        <vers num="3.6.5" edition=":linux"/>
        <vers num="5.1" edition=""/>
        <vers num="5.1" edition=":windows_nt"/>
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":windows"/>
        <vers num="gold" edition=":aix"/>
        <vers num="gold" edition=":smb"/>
        <vers num="gold" edition=":linux_for_smb"/>
        <vers num="gold" edition=":windows_nt_for_smb"/>
      </prod>
      <prod vendor="trend_micro" name="interscan_web_security_suite">
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":solaris"/>
        <vers num="gold" edition=":linux"/>
        <vers num="gold" edition=":windows"/>
      </prod>
      <prod vendor="trend_micro" name="interscan_webmanager">
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod vendor="trend_micro" name="interscan_webprotect">
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":isa"/>
      </prod>
      <prod vendor="trend_micro" name="officescan">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":corporate"/>
        <vers num="corporate_3.0" edition=""/>
        <vers num="corporate_3.0" edition=":windows_nt_server"/>
        <vers num="corporate_3.1.1" edition=""/>
        <vers num="corporate_3.1.1" edition=":windows_nt_server"/>
        <vers num="corporate_3.11" edition=""/>
        <vers num="corporate_3.11" edition=":windows_nt_server"/>
        <vers num="corporate_3.13" edition=""/>
        <vers num="corporate_3.13" edition=":windows_nt_server"/>
        <vers num="corporate_3.5" edition=""/>
        <vers num="corporate_3.5" edition=":windows_nt_server"/>
        <vers num="corporate_3.54"/>
        <vers num="corporate_5.02"/>
        <vers num="corporate_5.5"/>
        <vers num="corporate_5.58"/>
        <vers num="corporate_6.5"/>
      </prod>
      <prod vendor="trend_micro" name="pc-cillin">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="6.0"/>
      </prod>
      <prod vendor="trend_micro" name="portalprotect">
        <vers num="1.0"/>
      </prod>
      <prod vendor="trend_micro" name="scanmail">
        <vers num="2.51" edition=""/>
        <vers num="2.51" edition=":domino"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":domino"/>
        <vers num="3.8" edition=""/>
        <vers num="3.8" edition=":microsoft_exchange"/>
        <vers num="3.81" edition=""/>
        <vers num="3.81" edition=":microsoft_exchange"/>
        <vers num="6.1" edition=""/>
        <vers num="6.1" edition=":microsoft_exchange"/>
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":lotus_domino_on_aix"/>
        <vers num="gold" edition=":lotus_domino_on_s_390"/>
        <vers num="gold" edition=":lotus_domino_on_solaris"/>
        <vers num="gold" edition=":lotus_domino_on_as_400"/>
        <vers num="gold" edition=":lotus_domino_on_windows"/>
      </prod>
      <prod vendor="trend_micro" name="scanmail_emanager">
        <vers num=""/>
      </prod>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="1.25_2007-02-16" edition=""/>
        <vers num="1.25_2007-02-16" edition=":linux"/>
        <vers num="1.3" edition=""/>
        <vers num="1.3" edition=":linux"/>
        <vers num="2.5" edition=""/>
        <vers num="2.5" edition=":linux"/>
        <vers num="5.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0534" published="2005-05-02" name="CVE-2005-0534" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=307067" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=307067</ref>
      <ref url="http://securitytracker.com/id?1013260" source="SECTRACK" patch="1" adv="1">1013260</ref>
      <ref url="http://secunia.com/advisories/14360" source="SECUNIA" patch="1" adv="1">14360</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.4_beta1"/>
        <vers num="1.4_beta2"/>
        <vers num="1.4_beta3"/>
        <vers num="1.4_beta4"/>
        <vers num="1.4_beta5"/>
        <vers num="1.4_beta6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0535" published="2005-02-22" name="CVE-2005-0535" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013260" source="SECTRACK" patch="1" adv="1">1013260</ref>
      <ref url="http://secunia.com/advisories/14360" source="SECUNIA" patch="1" adv="1">14360</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0536" published="2005-05-02" name="CVE-2005-0536" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to image deletion.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=307067" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=307067</ref>
      <ref url="http://securitytracker.com/id?1013260" source="SECTRACK" patch="1" adv="1">1013260</ref>
      <ref url="http://secunia.com/advisories/14360" source="SECUNIA" patch="1" adv="1">14360</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.4_beta1"/>
        <vers num="1.4_beta2"/>
        <vers num="1.4_beta3"/>
        <vers num="1.4_beta4"/>
        <vers num="1.4_beta5"/>
        <vers num="1.4_beta6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0537" published="2005-02-21" name="CVE-2005-0537" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1013268" source="SECTRACK" adv="1">1013268</ref>
      <ref url="http://secunia.com/advisories/14369" source="SECUNIA" adv="1">14369</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910607229970&amp;w=2" source="BUGTRAQ" adv="1">20050221 [NOBYTES.COM: #5] iGeneric eShop 1.2 - Information Disclosure &amp; Possible SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="free_shopping_cart">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0538" published="2005-05-02" name="CVE-2005-0538" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in (1) GinpPictureServlet.java and (2) PicCollection.java in ginp (Java Photo Gallery Web Application) before 0.22 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=307518" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=307518</ref>
      <ref url="http://secunia.com/advisories/14373" source="SECUNIA" adv="1">14373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ginp" name="ginp">
        <vers num="0.20"/>
        <vers num="0.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0539" published="2005-05-02" name="CVE-2005-0539" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://techsupport.services.ibm.com/server/hmc/power5/fixes/ptf_MH00220.html" source="CONFIRM" patch="1">http://techsupport.services.ibm.com/server/hmc/power5/fixes/ptf_MH00220.html</ref>
      <ref url="http://secunia.com/advisories/14377" source="SECUNIA" patch="1" adv="1">14377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="hardware_management_console">
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0540" published="2005-05-02" name="CVE-2005-0540" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to obtain sensitive information via a direct request to the /about.html page.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/14073" source="OSVDB">14073</ref>
      <ref url="http://www.cirt.net/advisories/alterpath_disclosure.shtml" source="MISC" adv="1">http://www.cirt.net/advisories/alterpath_disclosure.shtml</ref>
      <ref url="http://secunia.com/advisories/14378" source="SECUNIA" adv="1">14378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2" source="FULLDISC" adv="1">20050224 Cyclades AlterPath Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyclades" name="alterpath_manager">
        <vers num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0541" published="2005-05-02" name="CVE-2005-0541" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">consoleConnect.jsp in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to connect to arbitrary consoles by modifying the consolename parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/14075" source="OSVDB">14075</ref>
      <ref url="http://www.cirt.net/advisories/alterpath_console.shtml" source="MISC" adv="1">http://www.cirt.net/advisories/alterpath_console.shtml</ref>
      <ref url="http://secunia.com/advisories/14378" source="SECUNIA" adv="1">14378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2" source="FULLDISC" adv="1">20050224 Cyclades AlterPath Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyclades" name="alterpath_manager">
        <vers num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0542" published="2005-05-02" name="CVE-2005-0542" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">saveUser.do in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows local users to gain privileges by setting the adminUser parameter to true.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/14074" source="OSVDB">14074</ref>
      <ref url="http://www.cirt.net/advisories/alterpath_privesc.shtml" source="MISC" adv="1">http://www.cirt.net/advisories/alterpath_privesc.shtml</ref>
      <ref url="http://secunia.com/advisories/14378" source="SECUNIA" adv="1">14378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2" source="FULLDISC" adv="1">20050224 Cyclades AlterPath Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyclades" name="alterpath_manager">
        <vers num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0543" published="2005-02-24" name="CVE-2005-0543" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19462" source="XF" patch="1" adv="1">phpmyadmin-multiple-php-xss(19462)</ref>
      <ref url="http://www.securityfocus.com/bid/12644" source="BID" patch="1" adv="1">12644</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-07</ref>
      <ref url="http://secunia.com/advisories/14382" source="SECUNIA" patch="1" adv="1">14382</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110929725801154&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050224 [SECURITYREASON.COM] phpMyAdmin 2.6.1 Remote file inclusion and XSS cXIb8O3.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.6.0_pl2"/>
        <vers num="2.6.0_pl3"/>
        <vers num="2.6.1"/>
        <vers num="2.6.1_rc1"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":x86_64"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":x86_64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2005-0544" published="2005-05-02" name="CVE-2005-0544" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200503-07</ref>
      <ref url="http://secunia.com/advisories/14382" source="SECUNIA" patch="1" adv="1">14382</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149383&amp;group_id=23067&amp;atid=377408" source="CONFIRM" adv="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149383&amp;group_id=23067&amp;atid=377408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2005-0545" published="2005-05-02" name="CVE-2005-0545" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive.  NOTE: this issue has been disputed in a followup post.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12641" source="BID">12641</ref>
      <ref url="http://www.securityfocus.com/archive/1/391332" source="BUGTRAQ" adv="1">20050223 Office 10 applications &amp; flashdrives can be used to browse restricted drives</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935549821930&amp;w=2" source="BUGTRAQ" adv="1">20050225 Re: Office 10 applications &amp; flashdrives can be used to browse restricted</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
      