<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="1.2" pub_date="2010-02-09" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-1247" seq="2005-1247" severity="Medium" type="CVE" published="2004-01-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0126.html">20040115 OpenSSL ASN.1 parsing bugs PoC / brute forcer</ref>
            <ref source="MISC" url="http://www.cirt.dk/advisories/cirt-31-advisory.pdf" adv="1">http://www.cirt.dk/advisories/cirt-31-advisory.pdf</ref>
            <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097379.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097379.htm</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0021.html">20050424 [CIRT.DK - Advisory] Novell Nsure Audit 1.0.1 Denial of Service</ref>
        </refs>
        <vuln_soft>
            <prod vendor="novell" name="nsure_audit">
                <vers num="1.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2005-0190" seq="2005-0190" severity="Low" type="CVE" published="2004-09-29" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/17551" adv="1">realplayer-media-file-deletion(17551)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/11308" adv="1">11308</ref>
            <ref source="MISC" patch="1" url="http://www.ngssoftware.com/advisories/real-02full.txt" adv="1">http://www.ngssoftware.com/advisories/real-02full.txt</ref>
            <ref source="CONFIRM" patch="1" url="http://service.real.com/help/faq/security/040928_player/EN/" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/12672/" adv="1">12672</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2" adv="1">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
        </refs>
        <vuln_soft>
            <prod vendor="realnetworks" name="realone_player">
                <vers num="1.0" />
                <vers num="2.0" />
            </prod>
            <prod vendor="realnetworks" name="realplayer">
                <vers edition="" num="10.0" />
                <vers edition=":" num="10.0" />
                <vers edition="::english" num="10.0" />
                <vers edition="::japanese" num="10.0" />
                <vers edition=":german" num="10.0" />
                <vers num="10.0_6.0.12.690" />
                <vers num="10.0_beta" />
                <vers num="10.5" />
                <vers num="10.5_6.0.12.1016_beta" />
                <vers num="10.5_6.0.12.1040" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0188" seq="2005-0188" severity="High" type="CVE" published="2004-10-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17628">athoc-toolbar-format-string(17628)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11341">11341</ref>
            <ref source="MISC" url="http://www.ngssoftware.com/advisories/athoc-01full.txt">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2" adv="1">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2" adv="1">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref>
        </refs>
        <vuln_soft>
            <prod vendor="athoc" name="athoc_toolbar">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0189" seq="2005-0189" severity="High" type="CVE" published="2004-10-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/698390" adv="1">VU#698390</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12311" adv="1">12311</ref>
            <ref source="MISC" patch="1" url="http://service.real.com/help/faq/security/040928_player/EN/" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2" adv="1">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
            <ref source="NTBUGTRAQ" patch="1" url="http://archives.neohapsis.com/archives/ntbugtraq/2005-q1/0046.html" adv="1">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
        </refs>
        <vuln_soft>
            <prod vendor="realnetworks" name="realone_player">
                <vers num="1.0" />
                <vers num="2.0" />
            </prod>
            <prod vendor="realnetworks" name="realplayer">
                <vers edition="" num="10.0" />
                <vers edition=":" num="10.0" />
                <vers edition="::english" num="10.0" />
                <vers edition="::japanese" num="10.0" />
                <vers edition=":german" num="10.0" />
                <vers num="10.0_6.0.12.690" />
                <vers num="10.0_beta" />
                <vers num="10.5" />
                <vers num="10.5_6.0.12.1016_beta" />
                <vers num="10.5_6.0.12.1040" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2005-0192" seq="2005-0192" severity="Low" type="CVE" published="2004-10-06" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18984" adv="1">realplayer-rjs-filenane-directory-traversal(18984)</ref>
            <ref source="MISC" patch="1" url="http://www.ngssoftware.com/advisories/real-03full.txt" adv="1">http://www.ngssoftware.com/advisories/real-03full.txt</ref>
            <ref source="MISC" patch="1" url="http://service.real.com/help/faq/security/040928_player/EN/" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2" adv="1">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
        </refs>
        <vuln_soft>
            <prod vendor="realnetworks" name="realone_player">
                <vers num="1.0" />
                <vers num="2.0" />
            </prod>
            <prod vendor="realnetworks" name="realplayer">
                <vers edition="" num="10.0" />
                <vers edition=":" num="10.0" />
                <vers edition="::english" num="10.0" />
                <vers edition="::japanese" num="10.0" />
                <vers edition=":german" num="10.0" />
                <vers num="10.0_6.0.12.690" />
                <vers num="10.0_beta" />
                <vers num="10.5" />
                <vers num="10.5_6.0.12.1016_beta" />
                <vers num="10.5_6.0.12.1040" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0373" seq="2005-0373" severity="High" type="CVE" published="2004-10-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/17642" adv="1">cyrus-sasl-digestmda5-bo(17642)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/11347" adv="1">11347</ref>
            <ref source="MLIST" patch="1" url="http://www.monkey.org/openbsd/archive/ports/0407/msg00265.html" adv="1">[openbsd-ports] 20040717 UPDATE: cyrus-sasl-2.1.19</ref>
            <ref source="SUSE" patch="1" url="http://www.linuxcompatible.org/print42495.html" adv="1">SUSE-SR:2005:006</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml" adv="1">GLSA-200410-05</ref>
            <ref source="CONFIRM" url="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup" adv="1">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup</ref>
            <ref source="CONFIRM" url="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171" adv="1">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:054">MDKSA-2005:054</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cyrus" name="sasl">
                <vers num="1.5.24" />
                <vers num="1.5.27" />
                <vers num="1.5.28" />
                <vers num="2.1.10" />
                <vers num="2.1.11" />
                <vers num="2.1.12" />
                <vers num="2.1.13" />
                <vers num="2.1.14" />
                <vers num="2.1.15" />
                <vers num="2.1.16" />
                <vers num="2.1.17" />
                <vers num="2.1.18" />
                <vers num="2.1.18_r1" />
                <vers num="2.1.9" />
            </prod>
            <prod vendor="openpkg" name="openpkg">
                <vers num="2.1" />
                <vers num="2.2" />
            </prod>
            <prod vendor="suse" name="suse_cvsup">
                <vers num="16.1h_36.i586" />
            </prod>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.0" />
                <vers num="10.0.1" />
                <vers num="10.0.2" />
                <vers num="10.0.3" />
                <vers num="10.0.4" />
                <vers num="10.1" />
                <vers num="10.1.1" />
                <vers num="10.1.2" />
                <vers num="10.1.3" />
                <vers num="10.1.4" />
                <vers num="10.1.5" />
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
                <vers num="10.2.5" />
                <vers num="10.2.6" />
                <vers num="10.2.7" />
                <vers num="10.2.8" />
                <vers num="10.3" />
                <vers num="10.3.1" />
                <vers num="10.3.2" />
                <vers num="10.3.3" />
                <vers num="10.3.4" />
                <vers num="10.3.5" />
                <vers num="10.3.6" />
                <vers num="10.3.7" />
                <vers num="10.3.8" />
            </prod>
            <prod vendor="apple" name="mac_os_x_server">
                <vers num="10.0" />
                <vers num="10.1" />
                <vers num="10.1.1" />
                <vers num="10.1.2" />
                <vers num="10.1.3" />
                <vers num="10.1.4" />
                <vers num="10.1.5" />
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
                <vers num="10.2.5" />
                <vers num="10.2.6" />
                <vers num="10.2.7" />
                <vers num="10.2.8" />
                <vers num="10.3" />
                <vers num="10.3.1" />
                <vers num="10.3.2" />
                <vers num="10.3.3" />
                <vers num="10.3.4" />
                <vers num="10.3.5" />
                <vers num="10.3.6" />
                <vers num="10.3.7" />
                <vers num="10.3.8" />
            </prod>
            <prod vendor="conectiva" name="linux">
                <vers num="10.0" />
                <vers num="9.0" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_1.0" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers edition="" num="1.0" />
                <vers edition=":desktop" num="1.0" />
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers edition=":enterprise_server" num="9.0" />
                <vers edition="" num="9.1" />
                <vers edition=":x86_64" num="9.1" />
                <vers edition="" num="9.2" />
                <vers edition=":x86_64" num="9.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0066" seq="2005-0066" severity="Medium" type="CVE" published="2004-12-22" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tcp" name="tcp">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0067" seq="2005-0067" severity="Medium" type="CVE" published="2004-12-22" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tcp" name="tcp">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0068" seq="2005-0068" severity="Medium" type="CVE" published="2004-12-22" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tcp" name="tcp">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2005-0441" seq="2005-0441" severity="High" type="CVE" published="2004-12-22" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19980" adv="1">sybase-ase-install-java-bo(19980)</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19979" adv="1">sybase-ase-abstract-bo(19979)</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19978" adv="1">sybase-ase-declare-bo(19978)</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19976" adv="1">sybase-ase-convert-bo(19976)</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19974" adv="1">sybase-ase-attribvalid-bo(19974)</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19354" adv="1">sybase-adaptive-server(19354)</ref>
            <ref source="CONFIRM" patch="1" url="http://www.sybase.com/detail?id=1034752" adv="1">http://www.sybase.com/detail?id=1034752</ref>
            <ref source="CONFIRM" patch="1" url="http://www.sybase.com/detail?id=1034520" adv="1">http://www.sybase.com/detail?id=1034520</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12080" adv="1">12080</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/393851" adv="1">20050321 Details of Sybase ASE bugs withheld</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13632" adv="1">13632</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272918117194&amp;w=2" adv="1">20050405 Sybase ASE Multiple Security Issues (#NISR05042005)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0315.html" adv="1">20041222 Sybase ASE 12.5.2 vulnerabilities</ref>
            <ref source="MISC" url="http://www.ngssoftware.com/advisories/sybase-ase.txt" adv="1">http://www.ngssoftware.com/advisories/sybase-ase.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sybase" name="adaptive_server_enterprise">
                <vers edition="" num="11.03.3" />
                <vers edition=":linux" num="11.03.3" />
                <vers edition="" num="11.5" />
                <vers edition=":sun" num="11.5" />
                <vers edition=":win" num="11.5" />
                <vers edition=":hp" num="11.5" />
                <vers edition=":digital_unix" num="11.5" />
                <vers edition="" num="11.5.1" />
                <vers edition=":win" num="11.5.1" />
                <vers edition=":hp" num="11.5.1" />
                <vers edition=":sun" num="11.5.1" />
                <vers edition=":digital_unix" num="11.5.1" />
                <vers edition="" num="11.9.2" />
                <vers edition=":win" num="11.9.2" />
                <vers edition=":digital_unix" num="11.9.2" />
                <vers edition=":sun" num="11.9.2" />
                <vers edition=":hp" num="11.9.2" />
                <vers edition="" num="12.0" />
                <vers edition=":digital_unix" num="12.0" />
                <vers edition=":hp" num="12.0" />
                <vers edition=":sun" num="12.0" />
                <vers edition=":win" num="12.0" />
                <vers edition="" num="12.0.1" />
                <vers edition=":sun" num="12.0.1" />
                <vers edition=":win" num="12.0.1" />
                <vers edition=":digital_unix" num="12.0.1" />
                <vers edition=":hp" num="12.0.1" />
                <vers edition="" num="12.5" />
                <vers edition=":win" num="12.5" />
                <vers edition=":linux" num="12.5" />
                <vers edition=":sun" num="12.5" />
                <vers edition=":sgi" num="12.5" />
                <vers edition=":digital_unix" num="12.5" />
                <vers edition=":hp" num="12.5" />
                <vers num="12.5.2" />
                <vers num="12.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0266" seq="2005-0266" severity="Medium" type="CVE" published="2005-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461706232174&amp;w=2" adv="1">20050101 Cross Site Scripting Vulnerabilities and Possible Code Execution</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18719">sugar-sales-index-xss(18719)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12113">12113</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sugarcrm" name="sugarcrm">
                <vers num="1.0" />
                <vers num="1.0f" />
                <vers num="1.0g" />
                <vers num="1.1" />
                <vers num="1.1a" />
                <vers num="1.1b" />
                <vers num="1.1c" />
                <vers num="1.1d" />
                <vers num="1.1e" />
                <vers num="1.1f" />
                <vers num="1.5d" />
                <vers num="2.0.1" />
                <vers num="2.0.1a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0268" seq="2005-0268" severity="High" type="CVE" published="2005-01-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18746" adv="1">flatnuke-indexphp-xss(18746)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12150" adv="1">12150</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2" adv="1">20050102 Multiple Vulnerabilities in FlatNuke</ref>
        </refs>
        <vuln_soft>
            <prod vendor="flatnuke" name="flatnuke">
                <vers num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0271" seq="2005-0271" severity="High" type="CVE" published="2005-01-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18732" adv="1">reviewpost-php-sql-injection(18732)</ref>
            <ref source="MISC" patch="1" url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13697/" adv="1">13697</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2" adv="1">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref>
        </refs>
        <vuln_soft>
            <prod vendor="photopost" name="reviewpost_php_pro">
                <vers num="1.0.2" />
                <vers num="2.5" />
                <vers num="2.5.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0274" seq="2005-0274" severity="Medium" type="CVE" published="2005-01-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18744" adv="1">photopost-php-showgallery-xss(18744)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12156" adv="1">12156</ref>
            <ref source="MISC" patch="1" url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2" adv="1">20050103 Multiple PhotoPost Pro Vulnerabilities</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13680/" adv="1">13680</ref>
        </refs>
        <vuln_soft>
            <prod vendor="photopost" name="photopost_php_pro">
                <vers num="4.85" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0280" seq="2005-0280" severity="High" type="CVE" published="2005-01-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18752" adv="1">soldner-secret-wars-format-string(18752)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12162" adv="1">12162</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13716">13716</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2" adv="1">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jowood_productions" name="soldner_secret_wars">
                <vers num="30830" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0283" seq="2005-0283" severity="Medium" type="CVE" published="2005-01-04" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18748" adv="1">qwikiwiki-directory-traversal(18748)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12163" adv="1">12163</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486832621053&amp;w=2" adv="1">20050104 QWikiwiki directory traversal vulnerability</ref>
            <ref source="CONFIRM" url="http://www.qwikiwiki.com/index.php?page=QwikiVulnerability">http://www.qwikiwiki.com/index.php?page=QwikiVulnerability</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/12044">12044</ref>
        </refs>
        <vuln_soft>
            <prod vendor="david_barrett" name="qwikiwiki">
                <vers num="1.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0182" seq="2005-0182" severity="Medium" type="CVE" published="2005-01-06" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18765" adv="1">moddosevasive-symlink(18765)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12181" adv="1">12181</ref>
            <ref source="MISC" url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01" adv="1">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547469530582&amp;w=2" adv="1">20050111 Mod_dosevasive symlink and race vulnerability</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13725">13725</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mod_dosevasive" name="mod_dosevasive">
                <vers num="1.8" />
                <vers num="1.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0284" seq="2005-0284" severity="High" type="CVE" published="2005-01-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18859" adv="1">woltlab-book-addentry-sql-injection(18859)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548032401506&amp;w=2" adv="1">20050110 Woltlab Burning Book addentry.php SQL Injection</ref>
        </refs>
        <vuln_soft>
            <prod vendor="woltlab" name="burning_book">
                <vers num="1.0_gold" />
                <vers num="1.1.1e" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0287" seq="2005-0287" severity="Medium" type="CVE" published="2005-01-10" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18862" adv="1">webseries-report-execution(18862)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548383812462&amp;w=2" adv="1">20050110 Portcullis Security Advisory 05-009</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012854">1012854</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13821">13821</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bottomline" name="webseries_payment_application">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0097" seq="2005-0097" severity="Medium" type="CVE" published="2005-01-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="TRUSTIX" patch="1" url="http://www.trustix.org/errata/2005/0003/" adv="1">2005-0003</ref>
            <ref source="CONFIRM" patch="1" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-061.html" adv="1">RHSA-2005:061</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-060.html" adv="1">RHSA-2005:060</ref>
            <ref source="SUSE" patch="1" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" adv="1">SUSE-SA:2005:006</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200501-25.xml" adv="1">GLSA-200501-25</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13789" adv="1">13789</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12220">12220</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012818">1012818</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squid" name="squid">
                <vers num="2.0_patch2" />
                <vers num="2.1_patch2" />
                <vers num="2.3_.stable4" />
                <vers num="2.3_.stable5" />
                <vers num="2.3_stable5" />
                <vers num="2.4" />
                <vers num="2.4_.stable2" />
                <vers num="2.4_.stable6" />
                <vers num="2.4_.stable7" />
                <vers num="2.4_stable7" />
                <vers num="2.5.6" />
                <vers num="2.5.stable1" />
                <vers num="2.5.stable2" />
                <vers num="2.5.stable3" />
                <vers num="2.5.stable4" />
                <vers num="2.5.stable5" />
                <vers num="2.5.stable6" />
                <vers num="2.5.stable7" />
                <vers num="2.5_.stable1" />
                <vers num="2.5_.stable3" />
                <vers num="2.5_.stable4" />
                <vers num="2.5_.stable5" />
                <vers num="2.5_.stable6" />
                <vers num="2.5_stable3" />
                <vers num="2.5_stable4" />
                <vers num="2.5_stable9" />
                <vers num="2.6.stable1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0108" seq="2005-0108" severity="Medium" type="CVE" published="2005-01-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18841" adv="1">modauthradius-dos(18841)</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-659" adv="1">DSA-659</ref>
            <ref source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02" adv="1">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548193312050&amp;w=2" adv="1">20050111 Apache mod_auth_radius remote integer overflow</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12217">12217</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012829">1012829</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14046">14046</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13773">13773</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="mod_auth_radius">
                <vers num="1.5.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0117" seq="2005-0117" severity="Medium" type="CVE" published="2005-01-11" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html" adv="1">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</ref>
            <ref source="MISC" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xshisen" name="xshisen">
                <vers num="1.36" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" name="CVE-2005-0288" seq="2005-0288" severity="Low" type="CVE" published="2005-01-11" CVSS_version="2.0 incomplete approximation" CVSS_score="3.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18860" adv="1">webseries-pa-password-gain-access(18860)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12231" adv="1">12231</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549684319400&amp;w=2" adv="1">20050110 Portcullis Security Advisory 05-008</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012854">1012854</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13821">13821</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bottomline" name="webseries_payment_application">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0376" seq="2005-0376" severity="High" type="CVE" published="2005-01-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18878" adv="1">sgallery-file-include(18878)</ref>
            <ref source="MISC" url="http://www.waraxe.us/advisory-39.html" adv="1">http://www.waraxe.us/advisory-39.html</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012868">1012868</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13824" adv="1">13824</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html" adv="1">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sergey_kiselev" name="sgallery">
                <vers num="1.01" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0456" seq="2005-0456" severity="Medium" type="CVE" published="2005-01-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/882926" adv="1">VU#882926</ref>
            <ref source="CONFIRM" patch="1" url="http://www.opera.com/linux/changelogs/754u2/" adv="1">http://www.opera.com/linux/changelogs/754u2/</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" adv="1">GLSA-200502-17</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13818/" adv="1">13818</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18867" adv="1">opera-data-dialog-spoofing(18867)</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_31_opera.html">SUSE-SA:2005:031</ref>
        </refs>
        <vuln_soft>
            <prod vendor="opera_software" name="opera_web_browser">
                <vers edition="" num="5.0" />
                <vers edition=":mac" num="5.0" />
                <vers edition=":linux" num="5.0" />
                <vers edition="" num="5.0.2" />
                <vers edition=":win32" num="5.0.2" />
                <vers edition="" num="5.1.0" />
                <vers edition=":win32" num="5.1.0" />
                <vers edition="" num="5.1.1" />
                <vers edition=":win32" num="5.1.1" />
                <vers edition="" num="5.12" />
                <vers edition=":win32" num="5.12" />
                <vers edition="" num="6.0" />
                <vers edition=":win32" num="6.0" />
                <vers edition="" num="6.0.1" />
                <vers edition=":linux" num="6.0.1" />
                <vers edition=":win32" num="6.0.1" />
                <vers edition="" num="6.0.2" />
                <vers edition=":linux" num="6.0.2" />
                <vers edition=":win32" num="6.0.2" />
                <vers edition="" num="6.0.3" />
                <vers edition=":win32" num="6.0.3" />
                <vers edition=":linux" num="6.0.3" />
                <vers edition="" num="6.0.4" />
                <vers edition=":win32" num="6.0.4" />
                <vers edition="" num="6.0.5" />
                <vers edition=":win32" num="6.0.5" />
                <vers edition="" num="6.0.6" />
                <vers edition=":win32" num="6.0.6" />
                <vers edition="" num="6.10" />
                <vers edition=":linux" num="6.10" />
                <vers edition="" num="7.0" />
                <vers edition=":win32" num="7.0" />
                <vers edition="" num="7.0.1" />
                <vers edition=":win32" num="7.0.1" />
                <vers edition="" num="7.0.2" />
                <vers edition=":win32" num="7.0.2" />
                <vers edition="" num="7.0.3" />
                <vers edition=":win32" num="7.0.3" />
                <vers edition="" num="7.0_beta1" />
                <vers edition=":win32" num="7.0_beta1" />
                <vers edition="" num="7.0_beta2" />
                <vers edition=":win32" num="7.0_beta2" />
                <vers num="7.10" />
                <vers num="7.11" />
                <vers num="7.11b" />
                <vers num="7.11j" />
                <vers num="7.20" />
                <vers num="7.20_beta1_build2981" />
                <vers num="7.21" />
                <vers num="7.22" />
                <vers num="7.23" />
                <vers num="7.50" />
                <vers num="7.51" />
                <vers num="7.52" />
                <vers num="7.53" />
                <vers num="7.54" />
                <vers num="9.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0069" seq="2005-0069" severity="Medium" type="CVE" published="2005-01-13" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18870" adv="1">vim-symlink(18870)</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-122.html" adv="1">RHSA-2005:122</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-036.html" adv="1">RHSA-2005:036</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13841/" adv="1">13841</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608387001863&amp;w=2" adv="1">20050118 [USN-61-1] vim vulnerabilities</ref>
            <ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2343" adv="1">FLSA:2343</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012938">1012938</ref>
        </refs>
        <vuln_soft>
            <prod vendor="vim_development_group" name="vim">
                <vers num="6.3.011" />
                <vers num="6.3.025" />
                <vers num="6.3.030" />
                <vers num="6.3.044" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0111" seq="2005-0111" severity="High" type="CVE" published="2005-01-13" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities" adv="1">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12265">12265</ref>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012893">1012893</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mysql" name="maxdb">
                <vers num="7.5.00" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0381" seq="2005-0381" severity="Medium" type="CVE" published="2005-01-13" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-10">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18880" adv="1">forumkit-members-xss(18880)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12256" adv="1">12256</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012895">1012895</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110563769413994&amp;w=2" adv="1">20050113 XSS Vulnerability in ForumKIT</ref>
        </refs>
        <vuln_soft>
            <prod vendor="forumkit" name="forumkit">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0740" seq="2005-0740" severity="Medium" type="CVE" published="2005-01-13" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12250" adv="1">12250</ref>
            <ref source="OPENBSD" patch="1" url="http://www.openbsd.org/errata35.html" adv="1">20050111 027: RELIABILITY FIX: January 11, 2005</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1012861" adv="1">1012861</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13819">13819</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openbsd" name="openbsd">
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="2.2" />
                <vers num="2.3" />
                <vers num="2.4" />
                <vers num="2.5" />
                <vers num="2.6" />
                <vers num="2.7" />
                <vers num="2.8" />
                <vers num="2.9" />
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.4" />
                <vers num="3.5" />
                <vers num="3.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2005-0110" seq="2005-0110" severity="Low" type="CVE" published="2005-01-14" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110569119106172&amp;w=2" adv="1">20050114 Internet Explorer (SP2) - Remote File Download</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp2" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2005-0113" seq="2005-0113" severity="High" type="CVE" published="2005-01-14" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18894" adv="1">irix-inpview-gain-privileges(18894)</ref>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=182&amp;type=vulnerabilities" adv="1">20050113 SGI IRIX inpview Design Error Vulnerability</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13858" adv="1">13858</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12259">12259</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/12915">12915</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012894">1012894</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="6.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0094" seq="2005-0094" severity="Medium" type="CVE" published="2005-01-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-061.html" adv="1">RHSA-2005:061</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-060.html" adv="1">RHSA-2005:060</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-651" adv="1">DSA-651</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200501-25.xml" adv="1">GLSA-200501-25</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13825" adv="1">13825</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/" adv="1">2005-0003</ref>
            <ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch</ref>
            <ref source="CONFIRM" url="http://www.squid-cache.org/Advisories/SQUID-2005_1.txt" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_1.txt</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" adv="1">SUSE-SA:2005:006</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" adv="1">CLA-2005:923</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12276">12276</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squid" name="squid">
                <vers num="2.0_patch2" />
                <vers num="2.1_patch2" />
                <vers num="2.3_.stable4" />
                <vers num="2.3_.stable5" />
                <vers num="2.3_stable5" />
                <vers num="2.4" />
                <vers num="2.4_.stable2" />
                <vers num="2.4_.stable6" />
                <vers num="2.4_.stable7" />
                <vers num="2.4_stable7" />
                <vers num="2.5.6" />
                <vers num="2.5.stable1" />
                <vers num="2.5.stable2" />
                <vers num="2.5.stable3" />
                <vers num="2.5.stable4" />
                <vers num="2.5.stable5" />
                <vers num="2.5.stable6" />
                <vers num="2.5.stable7" />
                <vers num="2.5_.stable1" />
                <vers num="2.5_.stable3" />
                <vers num="2.5_.stable4" />
                <vers num="2.5_.stable5" />
                <vers num="2.5_.stable6" />
                <vers num="2.5_stable3" />
                <vers num="2.5_stable4" />
                <vers num="2.5_stable9" />
                <vers num="2.6.stable1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0095" seq="2005-0095" severity="Medium" type="CVE" published="2005-01-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="TRUSTIX" patch="1" url="http://www.trustix.org/errata/2005/0003/" adv="1">2005-0003</ref>
            <ref source="CONFIRM" patch="1" url="http://www.squid-cache.org/Advisories/SQUID-2005_2.txt" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_2.txt</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-061.html" adv="1">RHSA-2005:061</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-060.html" adv="1">RHSA-2005:060</ref>
            <ref source="SUSE" patch="1" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" adv="1">SUSE-SA:2005:006</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-651" adv="1">DSA-651</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200501-25.xml" adv="1">GLSA-200501-25</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13825" adv="1">13825</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" adv="1">CLA-2005:923</ref>
            <ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12275">12275</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/12886">12886</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012882">1012882</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squid" name="squid">
                <vers num="2.0_patch2" />
                <vers num="2.1_patch2" />
                <vers num="2.3_.stable4" />
                <vers num="2.3_.stable5" />
                <vers num="2.3_stable5" />
                <vers num="2.4" />
                <vers num="2.4_.stable2" />
                <vers num="2.4_.stable6" />
                <vers num="2.4_.stable7" />
                <vers num="2.4_stable7" />
                <vers num="2.5.6" />
                <vers num="2.5.stable1" />
                <vers num="2.5.stable2" />
                <vers num="2.5.stable3" />
                <vers num="2.5.stable4" />
                <vers num="2.5.stable5" />
                <vers num="2.5.stable6" />
                <vers num="2.5.stable7" />
                <vers num="2.5_.stable1" />
                <vers num="2.5_.stable3" />
                <vers num="2.5_.stable4" />
                <vers num="2.5_.stable5" />
                <vers num="2.5_.stable6" />
                <vers num="2.5_stable3" />
                <vers num="2.5_stable4" />
                <vers num="2.5_stable9" />
                <vers num="2.6.stable1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0294" seq="2005-0294" severity="Medium" type="CVE" published="2005-01-16" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18929" adv="1">minis-month-dos(18929)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2" adv="1">20050116 Minis directory traversal vulnerability</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030966.html" adv="1">20050116 Minis directory traversal vulnerability</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012911">1012911</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13866">13866</ref>
        </refs>
        <vuln_soft>
            <prod vendor="minis" name="minis">
                <vers num="0.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0221" seq="2005-0221" severity="Medium" type="CVE" published="2005-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18938" adv="1">gallery-multiple-xss(18938)</ref>
            <ref source="CONFIRM" patch="1" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147" adv="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref>
            <ref source="MISC" url="http://theinsider.deep-ice.com/texts/advisory69.txt" adv="1">http://theinsider.deep-ice.com/texts/advisory69.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2" adv="1">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html" adv="1">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43472">gallery-g2formsubject-xss(43472)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gallery_project" name="gallery">
                <vers num="2.0_alpha" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0290" seq="2005-0290" severity="High" type="CVE" published="2005-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18920" adv="1">netgear-fvs318-filter-bypass(18920)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12278" adv="1">12278</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012913">1012913</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13787">13787</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netgear" name="fvs318">
                <vers num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0291" seq="2005-0291" severity="Medium" type="CVE" published="2005-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18921" adv="1">netgear-fvs318-log-xss(18921)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12278" adv="1">12278</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html" adv="1">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/13012">13012</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012913">1012913</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13787">13787</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netgear" name="fvs318">
                <vers num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0292" seq="2005-0292" severity="High" type="CVE" published="2005-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12289" adv="1">12289</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/392485" adv="1">20050307 Re: phpGiftReq SQL Injection</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18925" adv="1">phpgiftregistry-sql-injection(18925)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13873" adv="1">13873</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599710017066&amp;w=2" adv="1">20050116 phpGiftReq SQL Injection</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html" adv="1">20050116 phpGiftReq SQL Injection</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012910">1012910</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php_gift_registry" name="phpgiftreg">
                <vers num="1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0295" seq="2005-0295" severity="Medium" type="CVE" published="2005-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18952" adv="1">nprotect-npptnt2-gain-access(18952)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12280" adv="1">12280</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608422029555&amp;w=2" adv="1">20050116 Unrestricted I/O access vulnerability in INCA Gameguard</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13928">13928</ref>
        </refs>
        <vuln_soft>
            <prod vendor="inca" name="nprotect_gameguard">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0296" seq="2005-0296" severity="Medium" type="CVE" published="2005-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page.  NOTE: the vendor has disputed this issue.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18954" adv="1">groupwise-error-auth-bypass(18954)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12285" adv="1">12285</ref>
            <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.html" adv="1">20050127 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref>
            <ref source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.html" adv="1">20050121 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref>
            <ref source="MISC" url="http://support.novell.com/servlet/tidfinder/10096251" adv="1">http://support.novell.com/servlet/tidfinder/10096251</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608203729814&amp;w=2" adv="1">20050117 Novell GroupWise WebAccess error modules loading</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/13135">13135</ref>
        </refs>
        <vuln_soft>
            <prod vendor="novell" name="groupwise">
                <vers edition="sp1" num="6.0" />
                <vers edition="sp2" num="6.0" />
                <vers edition="sp3" num="6.0" />
                <vers edition="sp4" num="6.0" />
                <vers edition="sp1" num="6.5" />
                <vers edition="sp2" num="6.5" />
            </prod>
            <prod vendor="novell" name="groupwise_webaccess">
                <vers edition="sp4" num="6.0" />
                <vers edition="sp1" num="6.5" />
                <vers edition="sp2" num="6.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0116" seq="2005-0116" severity="High" type="CVE" published="2005-01-18" CVSS_version="2.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/272296" adv="1">VU#272296</ref>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/display?id=185&amp;type=vulnerabilities&amp;flashstatus=false" adv="1">20050117 AWStats Remote Command Execution Vulnerability</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13893/" adv="1">13893</ref>
            <ref source="CONFIRM" patch="1" url="http://awstats.sourceforge.net/docs/awstats_changelog.txt" adv="1">http://awstats.sourceforge.net/docs/awstats_changelog.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12298">12298</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/13002">13002</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf">http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf</ref>
        </refs>
        <vuln_soft>
            <prod vendor="awstats" name="awstats">
                <vers num="6.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0297" seq="2005-0297" severity="High" type="CVE" published="2005-01-18" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110606477308492&amp;w=2" adv="1">20050118 Multiple high risk vulnerabilities in Oracle RDBMS 10g/9i</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers edition="r2" num="10.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0186" seq="2005-0186" severity="Medium" type="CVE" published="2005-01-19" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2009-03-04">
        <desc>
            <descript source="cve">Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18956" adv="1">cisco-ios-sccp-dos(18956)</ref>
            <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml" adv="1">20050119 Vulnerability in Cisco IOS Embedded Call Processing Solutions</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4849">oval:org.mitre.oval:def:4849</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012945">1012945</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13913">13913</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="12.1yd" />
                <vers num="12.2t" />
                <vers num="12.3" />
                <vers num="12.3t" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2005-0191" seq="2005-0191" severity="Medium" type="CVE" published="2005-01-19" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18982" adv="1">realplayer-long-filename-offbyone-bo(18982)</ref>
            <ref source="MISC" patch="1" url="http://www.ngssoftware.com/advisories/real-03full.txt" adv="1">http://www.ngssoftware.com/advisories/real-03full.txt</ref>
            <ref source="CONFIRM" patch="1" url="http://service.real.com/help/faq/security/040928_player/EN/" adv="1">http://service.real.com/help/faq/security/040928_player/EN/</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2" adv="1">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" adv="1">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref>
        </refs>
        <vuln_soft>
            <prod vendor="realnetworks" name="realone_player">
                <vers num="1.0" />
                <vers num="2.0" />
            </prod>
            <prod vendor="realnetworks" name="realplayer">
                <vers edition="" num="10.0" />
                <vers edition=":" num="10.0" />
                <vers edition="::english" num="10.0" />
                <vers edition="::japanese" num="10.0" />
                <vers edition=":german" num="10.0" />
                <vers num="10.0_6.0.12.690" />
                <vers num="10.0_beta" />
                <vers num="10.5" />
                <vers num="10.5_6.0.12.1016_beta" />
                <vers num="10.5_6.0.12.1040" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0300" seq="2005-0300" severity="Medium" type="CVE" published="2005-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18990" adv="1">jsboard-session-file-include(18990)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12319" adv="1">12319</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627201120011&amp;w=2" adv="1">20050120 STG Security Advisory: [SSA-20050120-22] JSBoard file disclosure</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012949">1012949</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13920">13920</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jsboard" name="jsboard">
                <vers num="2.0.7" />
                <vers num="2.0.8" />
                <vers num="2.0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-1846" seq="2005-1846" severity="Medium" type="CVE" published="2005-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html" adv="1">http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html</ref>
            <ref source="CONFIRM" patch="1" url="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html" adv="1">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="yamt" name="yamt">
                <vers num="0.5.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-1847" seq="2005-1847" severity="High" type="CVE" published="2005-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html" adv="1">http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html</ref>
            <ref source="CONFIRM" patch="1" url="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html" adv="1">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="yamt" name="yamt">
                <vers num="0.5.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2005-0193" seq="2005-0193" severity="High" type="CVE" published="2005-01-22" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19011" adv="1">isync-mrouter-bo(19011)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642400018425&amp;w=2" adv="1">20050122 Mac OS X 10.3 iSync Privilege Escalation</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00001.html" adv="1">APPLE-SA-2005-04-19</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12334">12334</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012974">1012974</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13965">13965</ref>
        </refs>
        <vuln_soft>
            <prod vendor="isync" name="mrouter">
                <vers num="1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0566" seq="2005-0566" severity="High" type="CVE" published="2005-01-22" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/620862" adv="1">VU#620862</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19015" adv="1">golden-ftp-rnto-bo(19015)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12333" adv="1">12333</ref>
            <ref source="MISC" patch="1" url="http://www.goldenftpserver.com" adv="1">http://www.goldenftpserver.com</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13966/" adv="1">13966</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012973">1012973</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031098.html" adv="1">20050122 several BO's in goldenftpd</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kmint21_software" name="golden_ftp_server">
                <vers num="1.00b" />
                <vers num="1.20b" />
                <vers num="1.30b" />
                <vers num="1.31b" />
                <vers num="2.02b" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0072" seq="2005-0072" severity="Low" type="CVE" published="2005-01-24" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-655" adv="1">DSA-655</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19045" adv="1">zhcon-information-disclosure(19045)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12343">12343</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012">MDKSA-2005:012</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012977">1012977</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13987">13987</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13982">13982</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13977">13977</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ejoy_and_hu_yong" name="zhcon">
                <vers num="0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2005-0145" seq="2005-0145" severity="Low" type="CVE" published="2005-01-24" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.mozilla.org/show_bug.cgi?id=265176" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=265176</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19170" adv="1">mozilla-script-click-event-bypass(19170)</ref>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/mfsa2005-07.html" adv="1">http://www.mozilla.org/security/announce/mfsa2005-07.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100051" sig="1">oval:org.mitre.oval:def:100051</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="0.10" />
                <vers num="0.10.1" />
                <vers num="0.8" />
                <vers edition="rc" num="0.9" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
                <vers num="0.9.3" />
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0115" seq="2005-0115" severity="High" type="CVE" published="2005-01-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19042" adv="1">database-ida-portable-executable-bo(19042)</ref>
            <ref source="CONFIRM" patch="1" url="http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html" adv="1">http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html</ref>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities" adv="1">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12353">12353</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012975">1012975</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13980">13980</ref>
        </refs>
        <vuln_soft>
            <prod vendor="datarescue" name="ida">
                <vers num="4.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2005-0102" seq="2005-0102" severity="High" type="CVE" published="2005-01-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19031" adv="1">evolution-camellockhelper-bo(19031)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12354" adv="1">12354</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-397.html" adv="1">RHSA-2005:397</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-673" adv="1">DSA-673</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200501-35.xml" adv="1">GLSA-200501-35</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000925" adv="1">CLA-2005:925</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-238.html">RHSA-2005:238</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-69-1">USN-69-1</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:024">MDKSA-2005:024</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012981">1012981</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13830">13830</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ximian" name="evolution">
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.3.2_beta" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0103" seq="2005-0103" severity="High" type="CVE" published="2005-01-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223" adv="1">http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-135.html" adv="1">RHSA-2005:135</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-099.html" adv="1">RHSA-2005:099</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13962/" adv="1">13962</ref>
            <ref source="APPLE" patch="1" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" adv="1">APPLE-SA-2005-03-21</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" adv="1">20050129 SquirrelMail Security Advisory</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19037">squirrelmail-frame-file-include(19037)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squirrelmail" name="squirrelmail">
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.10" />
                <vers num="1.2.11" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.2.7" />
                <vers num="1.2.8" />
                <vers num="1.2.9" />
                <vers num="1.4" />
                <vers num="1.4.0" />
                <vers num="1.4.1" />
                <vers num="1.4.2" />
                <vers num="1.4.3" />
                <vers num="1.4.3_rc1" />
                <vers num="1.4.3a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0072" seq="2005-0072" severity="Low" type="CVE" published="2005-01-24" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-655" adv="1">DSA-655</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19045" adv="1">zhcon-information-disclosure(19045)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12343">12343</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012">MDKSA-2005:012</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012977">1012977</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13987">13987</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13982">13982</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13977">13977</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ejoy_and_hu_yong" name="zhcon">
                <vers num="0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0096" seq="2005-0096" severity="Medium" type="CVE" published="2005-01-25" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-061.html" adv="1">RHSA-2005:061</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-060.html" adv="1">RHSA-2005:060</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200501-25.xml" adv="1">GLSA-200501-25</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" adv="1">CLA-2005:923</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/" adv="1">2005-0003</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" adv="1">SUSE-SA:2005:006</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12324">12324</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012818">1012818</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squid" name="squid">
                <vers num="2.0_patch2" />
                <vers num="2.1_patch2" />
                <vers num="2.3_.stable4" />
                <vers num="2.3_.stable5" />
                <vers num="2.3_stable5" />
                <vers num="2.4" />
                <vers num="2.4_.stable2" />
                <vers num="2.4_.stable6" />
                <vers num="2.4_.stable7" />
                <vers num="2.4_stable7" />
                <vers num="2.5.6" />
                <vers num="2.5.stable1" />
                <vers num="2.5.stable2" />
                <vers num="2.5.stable3" />
                <vers num="2.5.stable4" />
                <vers num="2.5.stable5" />
                <vers num="2.5.stable6" />
                <vers num="2.5.stable7" />
                <vers num="2.5_.stable1" />
                <vers num="2.5_.stable3" />
                <vers num="2.5_.stable4" />
                <vers num="2.5_.stable5" />
                <vers num="2.5_.stable6" />
                <vers num="2.5_stable3" />
                <vers num="2.5_stable4" />
                <vers num="2.5_stable9" />
                <vers num="2.6.stable1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0309" seq="2005-0309" severity="Medium" type="CVE" published="2005-01-25" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19061" adv="1">exponent-module-xss(19061)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12358" adv="1">12358</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110666998407073&amp;w=2" adv="1">20050125 Vulnerabilities in eXponent 0.95</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/13190">13190</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/13188">13188</ref>
        </refs>
        <vuln_soft>
            <prod vendor="exponent" name="exponent">
                <vers num="0.95" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0306" seq="2005-0306" severity="Medium" type="CVE" published="2005-01-25" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19048" adv="1">mercuryboard-multiple-script-path-disclosure(19048)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12359" adv="1">12359</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2" adv="1">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mercuryboard" name="mercuryboard">
                <vers num="1.1" />
                <vers num="1.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0307" seq="2005-0307" severity="Medium" type="CVE" published="2005-01-25" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19050" adv="1">mercuryboard-multiple-scripts-xss(19050)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12359" adv="1">12359</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2" adv="1">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mercuryboard" name="mercuryboard">
                <vers num="1.1" />
                <vers num="1.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2005-0162" seq="2005-0162" severity="High" type="CVE" published="2005-01-26" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19078" adv="1">openswan-xauth-pam-bo(19078)</ref>
            <ref source="CONFIRM" patch="1" url="http://www.openswan.org/support/vuln/IDEF0785/" adv="1">http://www.openswan.org/support/vuln/IDEF0785/</ref>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/display?id=190&amp;type=vulnerabilities" adv="1">20050126 Openswan XAUTH/PAM Buffer Overflow Vulnerability</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12377">12377</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00103.html">FEDORA-2005-082</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/13195">13195</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013014">1013014</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14062">14062</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14038">14038</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openswan" name="openswan">
                <vers num="1.0.9" prev="1" />
                <vers num="2.3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0312" seq="2005-0312" severity="Low" type="CVE" published="2005-01-27" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12384" adv="1">12384</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110687202332039&amp;w=2" adv="1">20050127 WarFTPD 1.82 RC9 DoS</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19129">warftpd-cwd-dos(19129)</ref>
            <ref source="CONFIRM" url="http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643" adv="1">http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643</ref>
        </refs>
        <vuln_soft>
            <prod vendor="war_ftp_daemon" name="war_ftp_daemon">
                <vers num="1.8" />
                <vers num="1.82_rc9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0313" seq="2005-0313" severity="High" type="CVE" published="2005-01-27" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19114" adv="1">magic-winmail-command-directory-traversal(19114)</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19108" adv="1">magicwinmail-uploadphp-file-upload(19108)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12388" adv="1">12388</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013017">1013017</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14053">14053</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="amax_information_technologies" name="magic_winmail_server">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0314" seq="2005-0314" severity="Medium" type="CVE" published="2005-01-27" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19113" adv="1">magic-winmail-userphp-xss(19113)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12388" adv="1">12388</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013017">1013017</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14053">14053</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0315" seq="2005-0315" severity="Medium" type="CVE" published="2005-01-27" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19115" adv="1">magicwinmail-ftp-obtain-information(19115)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12388" adv="1">12388</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2" adv="1">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013017">1013017</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14053">14053</ref>
        </refs>
        <vuln_soft>
            <prod vendor="amax_information_technologies" name="magic_winmail_server">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0316" seq="2005-0316" severity="High" type="CVE" published="2005-01-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12394" adv="1">12394</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14058" adv="1">14058</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19144" adv="1">webwasher-classic-connect-gain-access(19144)</ref>
            <ref source="MISC" url="http://www.oliverkarow.de/research/WebWasherCONNECT.txt" adv="1">http://www.oliverkarow.de/research/WebWasherCONNECT.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693045507245&amp;w=2" adv="1">20050128 WebWasher Classic - HTTP CONNECT weakness</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013036">1013036</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webwasher" name="webwasher_classic">
                <vers num="2.2.1" />
                <vers num="3.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0317" seq="2005-0317" severity="Medium" type="CVE" published="2005-01-28" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19161" adv="1">webadmin-usereditaccountwdm-xss(19161)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12395" adv="1">12395</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013038">1013038</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14079">14079</ref>
        </refs>
        <vuln_soft>
            <prod vendor="alt-n" name="webadmin">
                <vers num="3.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0318" seq="2005-0318" severity="Low" type="CVE" published="2005-01-28" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12395">12395</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013038">1013038</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
        </refs>
        <vuln_soft>
            <prod vendor="alt-n" name="webadmin">
                <vers num="3.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0319" seq="2005-0319" severity="Medium" type="CVE" published="2005-01-28" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12395" adv="1">12395</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19162" adv="1">webadmin-html-injection(19162)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2" adv="1">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref>
        </refs>
        <vuln_soft>
            <prod vendor="alt-n" name="webadmin">
                <vers num="3.0.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0320" seq="2005-0320" severity="Medium" type="CVE" published="2005-01-28" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12396" adv="1">12396</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19147" adv="1">merak-icewarp-multiple-xss(19147)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2" adv="1">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref>
        </refs>
        <vuln_soft>
            <prod vendor="icewarp" name="web_mail">
                <vers num="5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0104" seq="2005-0104" severity="Medium" type="CVE" published="2005-01-29" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.squirrelmail.org/security/issue/2005-01-20" adv="1">http://www.squirrelmail.org/security/issue/2005-01-20</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-135.html" adv="1">RHSA-2005:135</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-099.html" adv="1">RHSA-2005:099</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-662" adv="1">DSA-662</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14096" adv="1">14096</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13962/" adv="1">13962</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" adv="1">20050129 SquirrelMail Security Advisory</ref>
            <ref source="APPLE" patch="1" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" adv="1">APPLE-SA-2005-03-21</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19036">squirrelmail-webmailphp-xss(19036)</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squirrelmail" name="squirrelmail">
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.10" />
                <vers num="1.2.11" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.2.7" />
                <vers num="1.2.8" />
                <vers num="1.2.9" />
                <vers num="1.4" />
                <vers num="1.4.0" />
                <vers num="1.4.1" />
                <vers num="1.4.2" />
                <vers num="1.4.3" />
                <vers num="1.4.3_rc1" />
                <vers num="1.4.3a" />
                <vers num="1.44" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0075" seq="2005-0075" severity="Medium" type="CVE" published="2005-01-29" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.squirrelmail.org/security/issue/2005-01-14" adv="1">http://www.squirrelmail.org/security/issue/2005-01-14</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-135.html" adv="1">RHSA-2005:135</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-099.html" adv="1">RHSA-2005:099</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13962/" adv="1">13962</ref>
            <ref source="APPLE" patch="1" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" adv="1">20050129 SquirrelMail Security Advisory</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squirrelmail" name="squirrelmail">
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.10" />
                <vers num="1.2.11" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.2.7" />
                <vers num="1.2.8" />
                <vers num="1.2.9" />
                <vers num="1.4" />
                <vers num="1.4.0" />
                <vers num="1.4.1" />
                <vers num="1.4.2" />
                <vers num="1.4.3" />
                <vers num="1.4.3a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0224" seq="2005-0224" severity="Medium" type="CVE" published="2005-01-31" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14082/" adv="1">14082</ref>
            <ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726808700080&amp;w=2" adv="1">SSRT5900</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="virtualvault">
                <vers num="4.5" />
                <vers num="4.6" />
                <vers num="4.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0245" seq="2005-0245" severity="High" type="CVE" published="2005-02-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19188" adv="1">postgresql-cursor-bo(19188)</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-150.html" adv="1">RHSA-2005:150</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-138.html" adv="1">RHSA-2005:138</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/12948" adv="1">12948</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-683" adv="1">DSA-683</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2" adv="1">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref>
            <ref source="MLIST" url="http://archives.postgresql.org/pgsql-patches/2005-01/msg00216.php" adv="1">[pgsql-patches] 20050120 Re: WIP: pl/pgsql cleanup</ref>
            <ref source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php" adv="1">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref>
            <ref source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00298.php" adv="1">[pgsql-committers] 20050121 pgsql: Prevent overrunning a heap-allocated buffer is more than 1024</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12417">12417</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref>
        </refs>
        <vuln_soft>
            <prod vendor="postgresql" name="postgresql">
                <vers num="7.2" />
                <vers num="7.2.1" />
                <vers num="7.2.2" />
                <vers num="7.2.3" />
                <vers num="7.2.4" />
                <vers num="7.2.5" />
                <vers num="7.2.6" />
                <vers num="7.2.7" />
                <vers num="7.3" />
                <vers num="7.3.1" />
                <vers num="7.3.2" />
                <vers num="7.3.3" />
                <vers num="7.3.4" />
                <vers num="7.3.5" />
                <vers num="7.3.6" />
                <vers num="7.3.7" />
                <vers num="7.3.8" />
                <vers num="7.3.9" />
                <vers num="7.4" />
                <vers num="7.4.1" />
                <vers num="7.4.2" />
                <vers num="7.4.3" />
                <vers num="7.4.4" />
                <vers num="7.4.5" />
                <vers num="7.4.6" />
                <vers num="7.4.7" />
                <vers num="8.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0101" seq="2005-0101" severity="High" type="CVE" published="2005-02-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200502-05.xml" adv="1">GLSA-200502-05</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19178">newspost-socketgetline-bo(19178)</ref>
            <ref source="CONFIRM" url="http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html" adv="1">http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14092/" adv="1">14092</ref>
            <ref source="MISC" url="http://people.freebsd.org/~niels/issues/newspost-20050114.txt" adv="1">http://people.freebsd.org/~niels/issues/newspost-20050114.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746336728781&amp;w=2" adv="1">20050202 RE: SECURITEY.NNOV.RU NewsPost buffer overflow [EXPLOIT]</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12418">12418</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013056">1013056</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14098">14098</ref>
        </refs>
        <vuln_soft>
            <prod vendor="newspost" name="newspost">
                <vers num="2.1.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0152" seq="2005-0152" severity="High" type="CVE" published="2005-02-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/203214" adv="1">VU#203214</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-662" adv="1">DSA-662</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14096" adv="1">14096</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squirrelmail" name="squirrelmail">
                <vers num="1.2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0226" seq="2005-0226" severity="High" type="CVE" published="2005-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.nosystem.com.ar/advisories/advisory-11.txt" adv="1">http://www.nosystem.com.ar/advisories/advisory-11.txt</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14114/" adv="1">14114</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746413108183&amp;w=2" adv="1">20050203 ngIRCd &lt;= v0.8.2 Format String Vulnerability</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12434">12434</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ngircd" name="ngircd">
                <vers num="0.8.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2005-0231" seq="2005-0231" severity="Low" type="CVE" published="2005-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.mozilla.org/show_bug.cgi?id=280056" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=280056</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19264" adv="1">mozilla-firefox-tab-gain-access(19264)</ref>
            <ref source="SUSE" patch="1" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" adv="1">SUSE-SA:2005:016</ref>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/mfsa2005-26.html" adv="1">http://www.mozilla.org/security/announce/mfsa2005-26.html</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" adv="1">GLSA-200503-30</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" adv="1">GLSA-200503-10</ref>
            <ref source="MISC" url="http://www.mikx.de/firetabbing/" adv="1">http://www.mikx.de/firetabbing/</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781134617144&amp;w=2" adv="1">20050207 Firetabbing [Firefox 1.0]</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100032" sig="1">oval:org.mitre.oval:def:100032</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0156" seq="2005-0156" severity="Low" type="CVE" published="2005-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19208" adv="1">perl-perliodebug-bo(19208)</ref>
            <ref source="TRUSTIX" patch="1" url="http://www.trustix.org/errata/2005/0003/" adv="1">2005-0003</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12426" adv="1">12426</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-105.html" adv="1">RHSA-2005:105</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-103.html" adv="1">RHSA-2005:103</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml" adv="1">GLSA-200502-13</ref>
            <ref source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txt">http://www.digitalmunition.com/DMA[2005-0131b].txt</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779721503111&amp;w=2" adv="1">20050207 DMA[2005-0131b] - 'Setuid Perl PERLIO_DEBUG</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2" adv="1">20050202 [USN-72-1] Perl vulnerabilities</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14120">14120</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</ref>
        </refs>
        <vuln_soft>
            <prod vendor="larry_wall" name="perl">
                <vers num="5.8.0" />
                <vers num="5.8.1" />
                <vers num="5.8.3" />
                <vers num="5.8.4" />
                <vers num="5.8.4.1" />
                <vers num="5.8.4.2" />
                <vers num="5.8.4.2.3" />
                <vers num="5.8.4.3" />
                <vers num="5.8.4.4" />
                <vers num="5.8.4.5" />
            </prod>
            <prod vendor="sgi" name="propack">
                <vers num="3.0" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="5.2" />
                <vers num="5.3" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="3.0" />
                <vers edition=":advanced_server" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
                <vers edition=":workstation_server" num="3.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="3.0" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_3.0" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers num="9.1" />
                <vers num="9.2" />
            </prod>
            <prod vendor="trustix" name="secure_linux">
                <vers num="1.5" />
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="2.2" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers edition="" num="4.1" />
                <vers edition=":ppc" num="4.1" />
                <vers edition=":ia64" num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0174" seq="2005-0174" severity="Medium" type="CVE" published="2005-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/768702" adv="1">VU#768702</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref>
            <ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" adv="1">SUSE-SA:2005:006</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" adv="1">CLA-2005:931</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12412">12412</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squid" name="squid">
                <vers num="2.5.6" />
                <vers num="2.5.stable1" />
                <vers num="2.5.stable2" />
                <vers num="2.5.stable3" />
                <vers num="2.5.stable4" />
                <vers num="2.5.stable5" />
                <vers num="2.5.stable6" />
                <vers num="2.5.stable7" />
                <vers num="2.5_.stable1" />
                <vers num="2.5_.stable3" />
                <vers num="2.5_.stable4" />
                <vers num="2.5_.stable5" />
                <vers num="2.5_.stable6" />
                <vers num="2.5_stable3" />
                <vers num="2.5_stable4" />
                <vers num="2.5_stable9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0175" seq="2005-0175" severity="Medium" type="CVE" published="2005-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/625878" adv="1">VU#625878</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-061.html" adv="1">RHSA-2005:061</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-060.html" adv="1">RHSA-2005:060</ref>
            <ref source="SUSE" patch="1" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html" adv="1">SUSE-SA:2005:006</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-667" adv="1">DSA-667</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" adv="1">20050207 [USN-77-1] Squid vulnerabilities</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" adv="1">CLA-2005:931</ref>
            <ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting</ref>
            <ref source="CONFIRM" url="http://www.squid-cache.org/Advisories/SQUID-2005_5.txt" adv="1">http://www.squid-cache.org/Advisories/SQUID-2005_5.txt</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12433">12433</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squid" name="squid">
                <vers num="2.5.6" />
                <vers num="2.5.stable1" />
                <vers num="2.5.stable2" />
                <vers num="2.5.stable3" />
                <vers num="2.5.stable4" />
                <vers num="2.5.stable5" />
                <vers num="2.5.stable6" />
                <vers num="2.5.stable7" />
                <vers num="2.5_.stable1" />
                <vers num="2.5_.stable3" />
                <vers num="2.5_.stable4" />
                <vers num="2.5_.stable5" />
                <vers num="2.5_.stable6" />
                <vers num="2.5_stable3" />
                <vers num="2.5_stable4" />
                <vers num="2.5_stable9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0100" seq="2005-0100" severity="High" type="CVE" published="2005-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19246" adv="1">xemacs-movemail-format-string(19246)</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-133.html" adv="1">RHSA-2005:133</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-112.html" adv="1">RHSA-2005:112</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-110.html" adv="1">RHSA-2005:110</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-685" adv="1">DSA-685</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-671" adv="1">DSA-671</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-670" adv="1">DSA-670</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780416112719&amp;w=2" adv="1">20050207 [USN-76-1] Emacs vulnerability</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12462">12462</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433928/30/5010/threaded">FLSA-2006:152898</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:038">MDKSA-2005:038</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnu" name="emacs">
                <vers num="20.0" prev="1" />
                <vers num="21.3" />
            </prod>
            <prod vendor="gnu" name="xemacs">
                <vers num="21.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0249" seq="2005-0249" severity="High" type="CVE" published="2005-02-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/107822" adv="1">VU#107822</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18869" adv="1">upx-engine-gain-control(18869)</ref>
            <ref source="ISS" patch="1" url="http://xforce.iss.net/xforce/alerts/id/187" adv="1">20050208 Symantec AntiVirus Library Heap Overflow</ref>
            <ref source="CONFIRM" patch="1" url="http://www.symantec.com/avcenter/security/Content/2005.02.08.html" adv="1">http://www.symantec.com/avcenter/security/Content/2005.02.08.html</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013133">1013133</ref>
        </refs>
        <vuln_soft>
            <prod vendor="symantec" name="antivirus_scan_engine">
                <vers num="3.1.1" />
                <vers num="3.1.2" />
                <vers num="3.1.3" />
                <vers num="3.1.4" />
                <vers num="3.1.5" />
                <vers num="3.1.6" />
                <vers edition="" num="4.0" prev="1" />
                <vers edition=":netapp_netcache" num="4.0" prev="1" />
                <vers edition=":bluecoat" num="4.0" prev="1" />
                <vers edition=":netapp_filer" num="4.0" prev="1" />
                <vers num="4.3" prev="1" />
                <vers edition="" num="4.3.3" prev="1" />
                <vers edition=":filers" num="4.3.3" prev="1" />
                <vers edition=":caching" num="4.3.3" prev="1" />
                <vers edition=":netapp_filer" num="4.3.3" prev="1" />
                <vers edition=":netapp_netcache" num="4.3.3" prev="1" />
                <vers edition=":bluecoat" num="4.3.3" prev="1" />
            </prod>
            <prod vendor="symantec" name="brightmail_antispam">
                <vers num="4.0" prev="1" />
                <vers num="5.5" prev="1" />
            </prod>
            <prod vendor="symantec" name="client_security">
                <vers edition="mr3" num="1.0.1_build_8.01.434" />
                <vers num="1.0.1_build_8.01.437" />
                <vers edition="mr4" num="1.0.1_build_8.01.446" />
                <vers edition="mr5" num="1.0.1_build_8.01.457" />
                <vers edition="mr6" num="1.0.1_build_8.01.460" />
                <vers edition="mr7" num="1.0.1_build_8.01.464" />
                <vers edition="mr8" num="1.0.1_build_8.01.471" />
                <vers num="1.1.1_mr1_build_8.1.1.314a" />
                <vers num="1.1.1_mr2_build_8.1.1.319" />
                <vers num="1.1.1_mr3_build_8.1.1.323" />
                <vers num="1.1.1_mr4_build_8.1.1.329" />
                <vers num="1.1.1_mr5_build_8.1.1.336" />
            </prod>
            <prod vendor="symantec" name="gateway_security">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="2.0.1" />
            </prod>
            <prod vendor="symantec" name="mail_security">
                <vers edition="" num="4.0" />
                <vers edition=":domino" num="4.0" />
                <vers edition="" num="4.0.2" prev="1" />
                <vers edition=":smtp" num="4.0.2" prev="1" />
                <vers edition="build_458" num="4.1" />
                <vers edition="build_458:exchange" num="4.1" />
                <vers edition="build_459" num="4.1" />
                <vers edition="build_459:exchange" num="4.1" />
                <vers edition="build_461" num="4.1" />
                <vers edition="build_461:exchange" num="4.1" />
                <vers edition="" num="4.5_build_719" />
                <vers edition=":exchange" num="4.5_build_719" />
            </prod>
            <prod vendor="symantec" name="norton_antivirus">
                <vers edition="" num="2.18_build_83" />
                <vers edition=":exchange" num="2.18_build_83" />
                <vers edition="" num="2004" />
                <vers edition=":windows" num="2004" />
                <vers edition="" num="8.01.434" />
                <vers edition=":corporate" num="8.01.434" />
                <vers edition="" num="8.01.437" />
                <vers edition=":corporate" num="8.01.437" />
                <vers edition="" num="8.01.446" />
                <vers edition=":corporate" num="8.01.446" />
                <vers edition="" num="8.01.457" />
                <vers edition=":corporate" num="8.01.457" />
                <vers edition="" num="8.01.460" />
                <vers edition=":corporate" num="8.01.460" />
                <vers edition="" num="8.01.464" />
                <vers edition=":corporate" num="8.01.464" />
                <vers edition="" num="8.01.471" />
                <vers edition=":corporate" num="8.01.471" />
                <vers edition="" num="8.1.1.319" />
                <vers edition=":corporate" num="8.1.1.319" />
                <vers edition="" num="8.1.1.323" />
                <vers edition=":corporate" num="8.1.1.323" />
                <vers edition="" num="8.1.1.329" />
                <vers edition=":corporate" num="8.1.1.329" />
                <vers edition="" num="8.1.1_build8.1.1.314a" />
                <vers edition=":corporate" num="8.1.1_build8.1.1.314a" />
                <vers edition="" num="9.0" prev="1" />
                <vers edition=":macintosh_corporate" num="9.0" prev="1" />
                <vers edition=":macintosh_osx" num="9.0" prev="1" />
            </prod>
            <prod vendor="symantec" name="norton_internet_security">
                <vers edition="" num="2004" />
                <vers edition=":professional" num="2004" />
                <vers edition="" num="3.0" prev="1" />
                <vers edition=":macintosh" num="3.0" prev="1" />
            </prod>
            <prod vendor="symantec" name="norton_system_works">
                <vers edition="" num="2004" />
                <vers edition=":windows" num="2004" />
                <vers edition="" num="3.0" prev="1" />
                <vers edition=":macintosh" num="3.0" prev="1" />
            </prod>
            <prod vendor="symantec" name="sav_filter_domino_nt_ports">
                <vers edition="" num="build3.0.5" />
                <vers edition=":os_400" num="build3.0.5" />
                <vers edition=":aix" num="build3.0.5" />
            </prod>
            <prod vendor="symantec" name="sav_filter_for_domino_nt">
                <vers num="3.1.1" />
            </prod>
            <prod vendor="symantec" name="web_security">
                <vers num="3.01.59" />
                <vers num="3.01.60" />
                <vers num="3.01.61" />
                <vers num="3.01.62" />
                <vers num="3.01.63" />
                <vers num="3.01.67" />
                <vers num="3.01.68" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0233" seq="2005-0233" severity="High" type="CVE" published="2005-02-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19236" adv="1">multiple-browsers-idn-spoof(19236)</ref>
            <ref source="SUSE" patch="1" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html" adv="1">SUSE-SA:2005:016</ref>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/mfsa2005-29.html" adv="1">http://www.mozilla.org/security/announce/mfsa2005-29.html</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" adv="1">GLSA-200503-30</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" adv="1">GLSA-200503-10</ref>
            <ref source="MISC" url="http://www.shmoo.com/idn/homograph.txt" adv="1">http://www.shmoo.com/idn/homograph.txt</ref>
            <ref source="MISC" url="http://www.shmoo.com/idn" adv="1">http://www.shmoo.com/idn</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2" adv="1">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html" adv="1">20050206 state of homograph attacks</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100029" sig="1">oval:org.mitre.oval:def:100029</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="camino">
                <vers num="0.8.5" />
            </prod>
            <prod vendor="mozilla" name="firefox">
                <vers num="1.0" />
            </prod>
            <prod vendor="mozilla" name="mozilla">
                <vers num="0.8" />
                <vers num="0.9.2" />
                <vers num="0.9.2.1" />
                <vers num="0.9.3" />
                <vers num="0.9.35" />
                <vers num="0.9.4" />
                <vers num="0.9.4.1" />
                <vers num="0.9.48" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.8" />
                <vers num="0.9.9" />
                <vers edition="rc1" num="1.0" />
                <vers edition="rc2" num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers edition="alpha" num="1.1" />
                <vers edition="beta" num="1.1" />
                <vers edition="alpha" num="1.2" />
                <vers edition="beta" num="1.2" />
                <vers num="1.2.1" />
                <vers num="1.3" />
                <vers num="1.3.1" />
                <vers edition="alpha" num="1.4" />
                <vers edition="beta" num="1.4" />
                <vers num="1.4.1" />
                <vers num="1.4.2" />
                <vers num="1.4.4" />
                <vers num="1.5" />
                <vers num="1.5.1" />
                <vers num="1.6" />
            </prod>
            <prod vendor="omnigroup" name="omniweb">
                <vers num="5" />
            </prod>
            <prod vendor="opera_software" name="opera_web_browser">
                <vers num="7.54" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0367" seq="2005-0367" severity="Medium" type="CVE" published="2005-02-09" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796956011699&amp;w=2" adv="1">20050209 [SIG^2 G-TEC] ArGoSoft Mail Server Webmail Multiple Directory Traversal Vulnerabilities</ref>
            <ref source="MISC" url="http://www.security.org.sg/vuln/argosoftmail1873.html" adv="1">http://www.security.org.sg/vuln/argosoftmail1873.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="argosoft" name="argosoft_mail_server">
                <vers num="1.8.7.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0362" seq="2005-0362" severity="Medium" type="CVE" published="2005-02-09" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/16089">16089</ref>
        </refs>
        <vuln_soft>
            <prod vendor="awstats" name="awstats">
                <vers num="4.0" />
                <vers num="5.0" />
                <vers num="5.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="5.4" />
                <vers num="5.5" />
                <vers num="5.7" />
                <vers num="5.8" />
                <vers num="5.9" />
                <vers num="6.0" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0364" seq="2005-0364" severity="Medium" type="CVE" published="2005-02-10" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2009-03-04">
        <desc>
            <descript source="cve">Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19276" adv="1">hpux-bind-dos(19276)</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14220/" adv="1">14220</ref>
            <ref source="HP" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805105200470&amp;w=2" adv="1">HPSBUX01117</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5690">oval:org.mitre.oval:def:5690</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="11.00" />
                <vers num="11.11" />
                <vers edition="" num="11.23" />
                <vers edition=":ia64_64-bit" num="11.23" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0261" seq="2005-0261" severity="Low" type="CVE" published="2005-02-10" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="AIXAPAR" patch="1" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67655&amp;apar=only" adv="1">IY67655</ref>
            <ref source="AIXAPAR" patch="1" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67457&amp;apar=only" adv="1">IY67457</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19281">ibm-aix-ispath-information-disclosure(19281)</ref>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=195&amp;type=vulnerabilities" adv="1">20050210 IBM AIX lspath Local File Access Vulnerability</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12513">12513</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14232">14232</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="5.2" />
                <vers num="5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2005-0074" seq="2005-0074" severity="High" type="CVE" published="2005-02-11" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-676" adv="1">DSA-676</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12523">12523</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013162">1013162</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14250">14250</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14248">14248</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xpcd" name="xpcd">
                <vers num="2.08" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0114" seq="2005-0114" severity="Low" type="CVE" published="2005-02-11" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/display?id=199&amp;type=vulnerabilities" adv="1">20050211 ZoneAlarm 5.1 Invalid Pointer Dereference Vulnerability</ref>
            <ref source="CONFIRM" patch="1" url="http://download.zonelabs.com/bin/free/securityAlert/19.html" adv="1">http://download.zonelabs.com/bin/free/securityAlert/19.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12531">12531</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14256">14256</ref>
        </refs>
        <vuln_soft>
            <prod vendor="checkpoint" name="check_point_integrity_client">
                <vers num="4.5.122.000" />
                <vers num="5.1.556.166" prev="1" />
            </prod>
            <prod vendor="zonelabs" name="zonealarm">
                <vers num="5.5.062.011" />
            </prod>
            <prod vendor="zonelabs" name="zonealarm_wireless_security">
                <vers num="5.5.080.000" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0430" seq="2005-0430" severity="Medium" type="CVE" published="2005-02-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://aluigi.altervista.org/adv/q3infoboom-adv.txt" adv="1">http://aluigi.altervista.org/adv/q3infoboom-adv.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12534">12534</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824822224025&amp;w=2">20050212 Infostring crash and shutdown in the Quake 3 engine</ref>
        </refs>
        <vuln_soft>
            <prod vendor="id_software" name="quake_3_engine">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0406" seq="2005-0406" severity="Low" type="CVE" published="2005-02-14" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt</ref>
            <ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html">20050214 Advisory: JPEG EXIF information disclosure</ref>
        </refs>
        <vuln_soft>
            <prod vendor="image_processing_software" name="image_processing_software">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0408" seq="2005-0408" severity="High" type="CVE" published="2005-02-14" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the "boogaadeeboo" string, which is hard-coded in the $hidden_hash variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html">20050214 Advisory: Authentication bypass in CitrusDB</ref>
        </refs>
        <vuln_soft>
            <prod vendor="citrusdb" name="citrusdb">
                <vers num="0.3.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2005-0409" seq="2005-0409" severity="Medium" type="CVE" published="2005-02-14" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-10">
        <desc>
            <descript source="cve">CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html">20050214 Advisory: Upload Authorization bypass in CitrusDB</ref>
        </refs>
        <vuln_soft>
            <prod vendor="citrusdb" name="citrusdb">
                <vers num="0.3.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0410" seq="2005-0410" severity="Medium" type="CVE" published="2005-02-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031709.html">20050214 Advisory: SQL-Injection in CitrusDB</ref>
        </refs>
        <vuln_soft>
            <prod vendor="citrusdb" name="citrusdb">
                <vers num="0.3.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0411" seq="2005-0411" severity="High" type="CVE" published="2005-02-14" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031710.html">20050214 Advisory: Directory traversal in CitrusDB</ref>
        </refs>
        <vuln_soft>
            <prod vendor="citrusdb" name="citrusdb">
                <vers num="0.3.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0444" seq="2005-0444" severity="Medium" type="CVE" published="2005-02-14" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-18.xml" adv="1">GLSA-200502-18</ref>
        </refs>
        <vuln_soft>
            <prod vendor="vmware" name="workstation">
                <vers edition="r4" num="4.5.2_build_8848" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0447" seq="2005-0447" severity="Medium" type="CVE" published="2005-02-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14286" adv="1">14286</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19331">solaris-arp-dos(19331)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12553">12553</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57673-1">57673</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013179">1013179</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="7.0" />
                <vers num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0433" seq="2005-0433" severity="Medium" type="CVE" published="2005-02-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19344">phpnuke-multiple-scripts-path-disclosure(19344)</ref>
            <ref source="MISC" url="http://www.waraxe.us/advisory-40.html" adv="1">http://www.waraxe.us/advisory-40.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12561" adv="1">12561</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="6.0" />
                <vers num="6.5" />
                <vers num="6.5_beta1" />
                <vers num="6.5_final" />
                <vers num="6.5_rc1" />
                <vers num="6.5_rc2" />
                <vers num="6.5_rc3" />
                <vers num="6.6" />
                <vers num="6.7" />
                <vers num="6.9" />
                <vers num="7.0" />
                <vers num="7.0_final" />
                <vers num="7.1" />
                <vers num="7.2" />
                <vers num="7.3" />
                <vers num="7.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0434" seq="2005-0434" severity="Medium" type="CVE" published="2005-02-15" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19346">phpnuke-downloads-weblinks-xss(19346)</ref>
            <ref source="MISC" url="http://www.waraxe.us/advisory-40.html" adv="1">http://www.waraxe.us/advisory-40.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12561" adv="1">12561</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="6.0" />
                <vers num="6.5" />
                <vers num="6.5_beta1" />
                <vers num="6.5_final" />
                <vers num="6.5_rc1" />
                <vers num="6.5_rc2" />
                <vers num="6.5_rc3" />
                <vers num="6.6" />
                <vers num="6.7" />
                <vers num="6.9" />
                <vers num="7.0" />
                <vers num="7.0_final" />
                <vers num="7.1" />
                <vers num="7.2" />
                <vers num="7.3" />
                <vers num="7.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0176" seq="2005-0176" severity="Medium" type="CVE" published="2005-02-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html" adv="1">RHSA-2005:092</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" adv="1">CLA-2005:930</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-472.html">RHSA-2005:472</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19607">19607</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">20060402-01-U</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1225" sig="1">oval:org.mitre.oval:def:1225</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="2.6.20" num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0149" seq="2005-0149" severity="Medium" type="CVE" published="2005-02-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.mozilla.org/show_bug.cgi?id=268107" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=268107</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19172" adv="1">mozilla-cookie-policy-bypass(19172)</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-335.html" adv="1">RHSA-2005:335</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-323.html" adv="1">RHSA-2005:323</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-094.html" adv="1">RHSA-2005:094</ref>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/mfsa2005-11.html" adv="1">http://www.mozilla.org/security/announce/mfsa2005-11.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100047" sig="1">oval:org.mitre.oval:def:100047</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="mozilla">
                <vers edition="alpha" num="1.7" />
                <vers edition="beta" num="1.7" />
                <vers edition="rc1" num="1.7" />
                <vers edition="rc2" num="1.7" />
                <vers edition="rc3" num="1.7" />
                <vers num="1.7.1" />
                <vers num="1.7.2" />
                <vers num="1.7.3" />
            </prod>
            <prod vendor="mozilla" name="thunderbird">
                <vers num="0.6" />
                <vers num="0.7" />
                <vers num="0.7.1" />
                <vers num="0.7.2" />
                <vers num="0.7.3" />
                <vers num="0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0105" seq="2005-0105" severity="Medium" type="CVE" published="2005-02-16" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-684" adv="1">DSA-684</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typespeed" name="typespeed">
                <vers num="0.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0452" seq="2005-0452" severity="Medium" type="CVE" published="2005-02-16" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "&lt;".</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12574" adv="1">12574</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14214" adv="1">14214</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2" adv="1">20050217 XSS vulnerabilty in ASP.Net [with details]</ref>
            <ref source="MISC" url="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml" adv="1">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="asp.net">
                <vers edition="sp1" num="1.0" />
                <vers edition="sp2" num="1.0" />
                <vers edition="sp1" num="1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0453" seq="2005-0453" severity="Medium" type="CVE" published="2005-02-16" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200502-21.xml" adv="1">GLSA-200502-21</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14297" adv="1">14297</ref>
            <ref source="CONFIRM" patch="1" url="http://article.gmane.org/gmane.comp.web.lighttpd/1171" adv="1">http://article.gmane.org/gmane.comp.web.lighttpd/1171</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lighttpd" name="lighttpd">
                <vers num="1.3.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0462" seq="2005-0462" severity="Medium" type="CVE" published="2005-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13937" adv="1">13937</ref>
            <ref source="MISC" url="http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html">http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mercuryboard" name="mercuryboard">
                <vers num="1.0" />
                <vers num="1.1" />
                <vers num="1.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0243" seq="2005-0243" severity="Medium" type="CVE" published="2005-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://secunia.com/secunia_research/2005-2/advisory/" adv="1">http://secunia.com/secunia_research/2005-2/advisory/</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13712" adv="1">13712</ref>
        </refs>
        <vuln_soft>
            <prod vendor="yahoo" name="messenger">
                <vers num="5.5" />
                <vers num="5.6" />
                <vers num="5.6.0.1351" />
                <vers num="6.0" />
                <vers num="6.0.0.1750" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0242" seq="2005-0242" severity="Medium" type="CVE" published="2005-02-18" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://secunia.com/secunia_research/2004-6/advisory/" adv="1">http://secunia.com/secunia_research/2004-6/advisory/</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11815">11815</ref>
        </refs>
        <vuln_soft>
            <prod vendor="yahoo" name="messenger">
                <vers num="5.5" />
                <vers num="5.6" />
                <vers num="5.6.0.1351" />
                <vers num="6.0" />
                <vers num="6.0.0.1750" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0502" seq="2005-0502" severity="Medium" type="CVE" published="2005-02-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19404">xinkaa-web-directory-traversal(19404)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12606">12606</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/0189">ADV-2005-0189</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14349" adv="1">14349</ref>
            <ref source="MISC" url="http://aluigi.altervista.org/adv/xinkaa-adv.txt" adv="1">http://aluigi.altervista.org/adv/xinkaa-adv.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xinkaa_web_station" name="xinkaa_web_station">
                <vers num="1.0.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2005-0519" seq="2005-0519" severity="High" type="CVE" published="2005-02-18" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.argosoft.com/ftpserver/changelist.aspx" adv="1">http://www.argosoft.com/ftpserver/changelist.aspx</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14172">14172</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17939">argosoft-ink-file-upload(17939)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12487">12487</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/13614">13614</ref>
        </refs>
        <vuln_soft>
            <prod vendor="argosoft" name="ftp_server">
                <vers num="1.4.1.1" />
                <vers num="1.4.1.2" />
                <vers num="1.4.1.3" />
                <vers num="1.4.1.4" />
                <vers num="1.4.1.5" />
                <vers num="1.4.1.6" />
                <vers num="1.4.1.7" />
                <vers num="1.4.1.8" />
                <vers num="1.4.1.9" />
                <vers num="1.4.2" />
                <vers num="1.4.2.1" />
                <vers num="1.4.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0513" seq="2005-0513" severity="High" type="CVE" published="2005-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying the pm_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2003-1086.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12597" adv="1">12597</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/15473">15473</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110883604531802&amp;w=2" adv="1">20050219 pMachine Pro / pMachine Free Remote Code Execution</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pmachine" name="pmachine_pro">
                <vers num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0495" seq="2005-0495" severity="Medium" type="CVE" published="2005-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19420">zeroboard-xss(19420)</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013243" adv="1">1013243</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110884332105513&amp;w=2" adv="1">20050219 Multiples vulnerability in ZeroBoard,</ref>
        </refs>
        <vuln_soft>
            <prod vendor="zeroboard" name="zeroboard">
                <vers num="4.1_pl2" />
                <vers num="4.1_pl3" />
                <vers num="4.1_pl4" />
                <vers num="4.1_pl5" />
                <vers num="4.1_pl6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0092" seq="2005-0092" severity="Low" type="CVE" published="2005-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12599" adv="1">12599</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-092.html" adv="1">RHSA-2005:092</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20620">red-hat-patch-dos(20620)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0499" seq="2005-0499" severity="Medium" type="CVE" published="2005-02-20" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
            <exception />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19426">gigafast-dns-queries-dos(19426)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900986022760&amp;w=2" adv="1">20050220 Gigafast/CompUSA router (model EE400-R) vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gigafast_ethernet" name="gigafast_router">
                <vers num="ee400-r" />
                <vers num="ee410-r" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0511" seq="2005-0511" severity="High" type="CVE" published="2005-02-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14326" adv="1">14326</ref>
            <ref source="CONFIRM" url="http://www.vbulletin.com/forum/showthread.php?postid=819562">http://www.vbulletin.com/forum/showthread.php?postid=819562</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12622">12622</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910899415763&amp;w=2" adv="1">20050222 [SCAN Associates Security Advisory] vbulletin 3.0.6 and below php code injection</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jelsoft" name="vbulletin">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.0_beta_2" />
                <vers num="2.0_beta_3" />
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
                <vers num="2.2.9_can" />
                <vers num="2.3.0" />
                <vers num="2.3.3" />
                <vers num="2.3.4" />
                <vers num="3.0.0" />
                <vers num="3.0.0_beta_2" />
                <vers num="3.0.0_can4" />
                <vers num="3.0.0_rc4" />
                <vers num="3.0.1" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0_beta_2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0512" seq="2005-0512" severity="High" type="CVE" published="2005-02-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14337" adv="1">14337</ref>
            <ref source="CONFIRM" patch="1" url="http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip">http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mambo" name="mambo">
                <vers num="4.5.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0503" seq="2005-0503" severity="Medium" type="CVE" published="2005-02-21" CVSS_version="2.0" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12604" adv="1">12604</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/13981" adv="1">13981</ref>
            <ref source="MLIST" url="http://lists.freedesktop.org/archives/uim/2005-February/000996.html" adv="1">[uim] 20050220 uim 0.4.5.1 released</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:046">MDKSA-2005:046</ref>
        </refs>
        <vuln_soft>
            <prod vendor="uim" name="uim">
                <vers num="0.4.5" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers edition="" num="10.1" />
                <vers edition=":x86_64" num="10.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0496" seq="2005-0496" severity="High" type="CVE" published="2005-02-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20667">arkeia-backup-client-gain-access(20667)</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013256" adv="1">1013256</ref>
            <ref source="MISC" url="http://metasploit.com/research/arkeia_agent/" adv="1">http://metasploit.com/research/arkeia_agent/</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900879826004&amp;w=2" adv="1">20050220 Arkeia Network Backup Client Remote Access</ref>
        </refs>
        <vuln_soft>
            <prod vendor="knox_software" name="arkeia">
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" />
                <vers num="5.2" />
                <vers num="5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0467" seq="2005-0467" severity="High" type="CVE" published="2005-02-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/display?id=201&amp;type=vulnerabilities" adv="1">20050221 Multiple PuTTY SFTP Client Packet Parsing Integer Overflow Vulnerabilities</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml" adv="1">GLSA-200502-28</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14333" adv="1">14333</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19403">putty-sftppktgetstring-bo(19403)</ref>
            <ref source="CONFIRM" url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html" adv="1">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html</ref>
            <ref source="CONFIRM" url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html" adv="1">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17214">17214</ref>
        </refs>
        <vuln_soft>
            <prod vendor="putty" name="putty">
                <vers num="0.56" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0494" seq="2005-0494" severity="High" type="CVE" published="2005-02-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19387">thomson-tcw690-gain-access(19387)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14353" adv="1">14353</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886937131507&amp;w=2" adv="1">20050219 Thomson TCW690 POST Password Validation Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="thomson" name="thomson_cable_modem">
                <vers num="tcw690" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0537" seq="2005-0537" severity="High" type="CVE" published="2005-02-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013268" adv="1">1013268</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14369" adv="1">14369</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910607229970&amp;w=2" adv="1">20050221 [NOBYTES.COM: #5] iGeneric eShop 1.2 - Information Disclosure &amp; Possible SQL Injection</ref>
        </refs>
        <vuln_soft>
            <prod vendor="igeneric" name="free_shopping_cart">
                <vers num="1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0535" seq="2005-0535" severity="High" type="CVE" published="2005-02-22" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1013260" adv="1">1013260</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14360" adv="1">14360</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml" adv="1">GLSA-200502-33</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml">GLSA-200502-33</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mediawiki" name="mediawiki">
                <vers num="1.3" />
                <vers num="1.3.1" />
                <vers num="1.3.10" />
                <vers num="1.3.2" />
                <vers num="1.3.3" />
                <vers num="1.3.4" />
                <vers num="1.3.5" />
                <vers num="1.3.6" />
                <vers num="1.3.7" />
                <vers num="1.3.8" />
                <vers num="1.3.9" />
            </prod>
            <prod vendor="gentoo" name="linux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0514" seq="2005-0514" severity="Medium" type="CVE" published="2005-02-22" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/716144" adv="1">VU#716144</ref>
            <ref source="MISC" patch="1" url="http://www.mikx.de/index.php?p=6" adv="1">http://www.mikx.de/index.php?p=6</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14367" adv="1">14367</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html" adv="1">20041223 Cross-Site Scripting - an industry-wide problem</ref>
        </refs>
        <vuln_soft>
            <prod vendor="verity" name="verity_ultraseek">
                <vers num="5.3.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2005-0160" seq="2005-0160" severity="Medium" type="CVE" published="2005-02-22" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/215006">VU#215006</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14359" adv="1">14359</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html" adv="1">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12630">12630</ref>
        </refs>
        <vuln_soft>
            <prod vendor="e-merge" name="unace">
                <vers num="1.2b" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0161" seq="2005-0161" severity="Low" type="CVE" published="2005-02-22" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14359" adv="1">14359</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html" adv="1">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12628">12628</ref>
        </refs>
        <vuln_soft>
            <prod vendor="e-merge" name="unace">
                <vers num="1.2b" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" name="CVE-2005-0937" seq="2005-0937" severity="Low" type="CVE" published="2005-02-22" CVSS_version="2.0 incomplete approximation" CVSS_score="1.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other functions.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://lkml.org/lkml/2005/2/22/123" adv="1">http://lkml.org/lkml/2005/2/22/123</ref>
            <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@421cfc11zFsK9gxvSJ2t__FCmuUd3Q" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@421cfc11zFsK9gxvSJ2t__FCmuUd3Q</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-420.html">RHSA-2005:420</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.5.0" />
                <vers num="2.5.1" />
                <vers num="2.5.10" />
                <vers num="2.5.11" />
                <vers num="2.5.12" />
                <vers num="2.5.13" />
                <vers num="2.5.14" />
                <vers num="2.5.15" />
                <vers num="2.5.16" />
                <vers num="2.5.17" />
                <vers num="2.5.18" />
                <vers num="2.5.19" />
                <vers num="2.5.2" />
                <vers num="2.5.20" />
                <vers num="2.5.21" />
                <vers num="2.5.22" />
                <vers num="2.5.23" />
                <vers num="2.5.24" />
                <vers num="2.5.25" />
                <vers num="2.5.26" />
                <vers num="2.5.27" />
                <vers num="2.5.28" />
                <vers num="2.5.29" />
                <vers num="2.5.3" />
                <vers num="2.5.30" />
                <vers num="2.5.31" />
                <vers num="2.5.32" />
                <vers num="2.5.33" />
                <vers num="2.5.34" />
                <vers num="2.5.35" />
                <vers num="2.5.36" />
                <vers num="2.5.37" />
                <vers num="2.5.38" />
                <vers num="2.5.39" />
                <vers num="2.5.4" />
                <vers num="2.5.40" />
                <vers num="2.5.41" />
                <vers num="2.5.42" />
                <vers num="2.5.43" />
                <vers num="2.5.44" />
                <vers num="2.5.45" />
                <vers num="2.5.46" />
                <vers num="2.5.47" />
                <vers num="2.5.48" />
                <vers num="2.5.49" />
                <vers num="2.5.5" />
                <vers num="2.5.50" />
                <vers num="2.5.51" />
                <vers num="2.5.52" />
                <vers num="2.5.53" />
                <vers num="2.5.54" />
                <vers num="2.5.55" />
                <vers num="2.5.56" />
                <vers num="2.5.57" />
                <vers num="2.5.58" />
                <vers num="2.5.59" />
                <vers num="2.5.6" />
                <vers num="2.5.60" />
                <vers num="2.5.61" />
                <vers num="2.5.62" />
                <vers num="2.5.63" />
                <vers num="2.5.64" />
                <vers num="2.5.65" />
                <vers num="2.5.66" />
                <vers num="2.5.67" />
                <vers num="2.5.68" />
                <vers num="2.5.69" />
                <vers num="2.5.7" />
                <vers num="2.5.8" />
                <vers num="2.5.9" />
                <vers edition="test1" num="2.6.0" />
                <vers edition="test10" num="2.6.0" />
                <vers edition="test11" num="2.6.0" />
                <vers edition="test2" num="2.6.0" />
                <vers edition="test3" num="2.6.0" />
                <vers edition="test4" num="2.6.0" />
                <vers edition="test5" num="2.6.0" />
                <vers edition="test6" num="2.6.0" />
                <vers edition="test7" num="2.6.0" />
                <vers edition="test8" num="2.6.0" />
                <vers edition="test9" num="2.6.0" />
                <vers edition="rc1" num="2.6.1" />
                <vers edition="rc2" num="2.6.1" />
                <vers edition="rc2" num="2.6.10" />
                <vers edition="rc2" num="2.6.11" />
                <vers edition="rc3" num="2.6.11" />
                <vers edition="rc4" num="2.6.11" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers edition="rc1" num="2.6.6" />
                <vers edition="rc1" num="2.6.7" />
                <vers edition="rc1" num="2.6.8" />
                <vers edition="rc2" num="2.6.8" />
                <vers edition="rc3" num="2.6.8" />
                <vers edition="2.6.20" num="2.6.9" />
                <vers num="2.6_test9_cvs" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0516" seq="2005-0516" severity="High" type="CVE" published="2005-02-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14384" adv="1">14384</ref>
            <ref source="MISC" url="http://www.enyo.de/fw/security/notes/twiki-robustness.html" adv="1">http://www.enyo.de/fw/security/notes/twiki-robustness.html</ref>
            <ref source="MISC" url="http://static.enyo.de/fw/patches/twiki/imagegallery-robustness-20041128.diff" adv="1">http://static.enyo.de/fw/patches/twiki/imagegallery-robustness-20041128.diff</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110918725225288&amp;w=2" adv="1">20050223 Robustness patch for TWiki, vulnerability in ImageGalleryPlugin</ref>
        </refs>
        <vuln_soft>
            <prod vendor="twiki" name="imagegalleryplugin">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0517" seq="2005-0517" severity="Low" type="CVE" published="2005-02-23" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013263" adv="1">1013263</ref>
        </refs>
        <vuln_soft>
            <prod vendor="peerftp_5" name="peerftp_5">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0518" seq="2005-0518" severity="Low" type="CVE" published="2005-02-23" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013266" adv="1">1013266</ref>
        </refs>
        <vuln_soft>
            <prod vendor="exeem" name="exeem">
                <vers num="0.21" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2005-0520" seq="2005-0520" severity="High" type="CVE" published="2005-02-23" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.argosoft.com/ftpserver/changelist.aspx" adv="1">http://www.argosoft.com/ftpserver/changelist.aspx</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14372" adv="1">14372</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19442">argosoft-site-copy-files(19442)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12632">12632</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/14061">14061</ref>
        </refs>
        <vuln_soft>
            <prod vendor="argosoft" name="ftp_server">
                <vers num="1.4.1.1" />
                <vers num="1.4.1.2" />
                <vers num="1.4.1.3" />
                <vers num="1.4.1.4" />
                <vers num="1.4.1.5" />
                <vers num="1.4.1.6" />
                <vers num="1.4.1.7" />
                <vers num="1.4.1.8" />
                <vers num="1.4.1.9" />
                <vers num="1.4.2" />
                <vers num="1.4.2.1" />
                <vers num="1.4.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0521" seq="2005-0521" severity="Low" type="CVE" published="2005-02-23" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013269" adv="1">1013269</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0543" seq="2005-0543" severity="Medium" type="CVE" published="2005-02-24" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19462" adv="1">phpmyadmin-multiple-php-xss(19462)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12644" adv="1">12644</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml" adv="1">GLSA-200503-07</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14382" adv="1">14382</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110929725801154&amp;w=2" adv="1">20050224 [SECURITYREASON.COM] phpMyAdmin 2.6.1 Remote file inclusion and XSS cXIb8O3.4</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpmyadmin" name="phpmyadmin">
                <vers num="2.6.0_pl2" />
                <vers num="2.6.0_pl3" />
                <vers num="2.6.1" />
                <vers num="2.6.1_rc1" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers edition="" num="9.1" />
                <vers edition=":x86_64" num="9.1" />
                <vers edition="" num="9.2" />
                <vers edition=":x86_64" num="9.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0547" seq="2005-0547" severity="Medium" type="CVE" published="2005-02-24" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2009-03-04">
        <desc>
            <descript source="cve">Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12651" adv="1">12651</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19467">hp-ux-ftpd-gain-access(19467)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5464">oval:org.mitre.oval:def:5464</ref>
            <ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927245211549&amp;w=2" adv="1">SSRT4694</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="11.00" />
                <vers num="11.11" />
                <vers num="11.22" />
                <vers edition="" num="11.23" />
                <vers edition=":ia64_64-bit" num="11.23" />
                <vers num="11.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0598" seq="2005-0598" severity="Medium" type="CVE" published="2005-02-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
            <env />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/579240">VU#579240</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19469" adv="1">cisco-realserver-realsubscriber-dos(19469)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12648" adv="1">12648</ref>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml" adv="1">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14395" adv="1">14395</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="application_and_content_networking_software">
                <vers num="(acns)" />
                <vers num="4.0.3" />
                <vers num="4.1.1" />
                <vers num="4.1.3" />
                <vers num="4.2" />
                <vers num="4.2.11" />
                <vers num="4.2.9" />
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.3" />
                <vers num="5.0.5" />
                <vers num="5.1" />
            </prod>
            <prod vendor="cisco" name="content_delivery_manager">
                <vers num="4630" />
                <vers num="4650" />
            </prod>
            <prod vendor="cisco" name="content_distribution_manager_4630">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
            <prod vendor="cisco" name="content_distribution_manager_4650">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
            <prod vendor="cisco" name="content_distribution_manager_4670">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="content_engine">
                <vers num="507" />
                <vers num="507_2.2_.0" />
                <vers num="507_3.1" />
                <vers num="507_4.0" />
                <vers num="507_4.1" />
                <vers num="510" />
                <vers num="560" />
                <vers num="560_2.2_.0" />
                <vers num="560_3.1" />
                <vers num="560_4.0" />
                <vers num="560_4.1" />
                <vers num="565" />
                <vers num="590" />
                <vers num="590_2.2_.0" />
                <vers num="590_3.1" />
                <vers num="590_4.0" />
                <vers num="590_4.1" />
                <vers num="7320" />
                <vers num="7320_2.2_.0" />
                <vers num="7320_3.1" />
                <vers num="7320_4.0" />
                <vers num="7320_4.1" />
                <vers num="7325" />
            </prod>
            <prod vendor="cisco" name="content_engine_module_for_cisco_router">
                <vers num="2600_series" />
                <vers num="2800_series" />
                <vers num="3600_series" />
                <vers num="3700_series" />
                <vers num="3800_series" />
            </prod>
            <prod vendor="cisco" name="content_router_4430">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="content_router_4450">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="content_router_4430">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0600" seq="2005-0600" severity="Medium" type="CVE" published="2005-02-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19470" adv="1">cisco-acns-dos(19470)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12648" adv="1">12648</ref>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml" adv="1">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14395" adv="1">14395</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="application_and_content_networking_software">
                <vers num="(acns)" />
                <vers num="4.0.3" />
                <vers num="4.1.1" />
                <vers num="4.1.3" />
                <vers num="4.2" />
                <vers num="4.2.11" />
                <vers num="4.2.9" />
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.3" />
                <vers num="5.0.5" />
                <vers num="5.1" />
            </prod>
            <prod vendor="cisco" name="content_delivery_manager">
                <vers num="4630" />
                <vers num="4650" />
            </prod>
            <prod vendor="cisco" name="content_distribution_manager_4630">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
            <prod vendor="cisco" name="content_distribution_manager_4650">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
            <prod vendor="cisco" name="content_distribution_manager_4670">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="content_engine">
                <vers num="507" />
                <vers num="507_2.2_.0" />
                <vers num="507_3.1" />
                <vers num="507_4.0" />
                <vers num="507_4.1" />
                <vers num="510" />
                <vers num="560" />
                <vers num="560_2.2_.0" />
                <vers num="560_3.1" />
                <vers num="560_4.0" />
                <vers num="560_4.1" />
                <vers num="565" />
                <vers num="590" />
                <vers num="590_2.2_.0" />
                <vers num="590_3.1" />
                <vers num="590_4.0" />
                <vers num="590_4.1" />
                <vers num="7320" />
                <vers num="7320_2.2_.0" />
                <vers num="7320_3.1" />
                <vers num="7320_4.0" />
                <vers num="7320_4.1" />
                <vers num="7325" />
            </prod>
            <prod vendor="cisco" name="content_engine_module_for_cisco_router">
                <vers num="2600_series" />
                <vers num="2800_series" />
                <vers num="3600_series" />
                <vers num="3700_series" />
                <vers num="3800_series" />
            </prod>
            <prod vendor="cisco" name="content_router_4430">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="content_router_4450">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="content_router_4430">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0579" seq="2005-0579" severity="Medium" type="CVE" published="2005-02-25" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUSE" url="http://www.linuxcompatible.org/story42495.html" adv="1">SUSE-SR:2005:006</ref>
            <ref source="MLIST" url="http://mail.kde.org/pipermail/freenx-knx/2005-February/000734.html" adv="1">[FreeNX-kNX] 20050217 Security: Serious bug in authority handling found and fixed</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freenx" name="freenx">
                <vers num="0.2.0" />
                <vers num="0.2.1" />
                <vers num="0.2.2" />
                <vers num="0.2.3" />
                <vers num="0.2.4" />
                <vers num="0.2.5" />
                <vers num="0.2.6" />
                <vers num="0.2.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0580" seq="2005-0580" severity="Low" type="CVE" published="2005-02-25" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-30.xml" adv="1">GLSA-200502-30</ref>
        </refs>
        <vuln_soft>
            <prod vendor="krzysztof_dabrowski" name="cmd5checkpw">
                <vers num="0.20" />
                <vers num="0.21" />
                <vers num="0.22" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0107" seq="2005-0107" severity="High" type="CVE" published="2005-02-25" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-690" adv="1">DSA-690</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="bsmtpd">
                <vers num="2.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0603" seq="2005-0603" severity="Medium" type="CVE" published="2005-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.phpbb.com/phpBB/viewtopic.php?t=267563" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?t=267563</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14413" adv="1">14413</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110943646112950&amp;w=2" adv="1">20050225 -==phpBB 2.0.12 Full path disclosure==-</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpbb_group" name="phpbb">
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.11" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.6c" />
                <vers num="2.0.6d" />
                <vers num="2.0.7" />
                <vers num="2.0.7a" />
                <vers num="2.0.8" />
                <vers num="2.0.8a" />
                <vers num="2.0.9" />
                <vers num="2.0_beta1" />
                <vers num="2.0_rc1" />
                <vers num="2.0_rc2" />
                <vers num="2.0_rc3" />
                <vers num="2.0_rc4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0608" seq="2005-0608" severity="High" type="CVE" published="2005-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14302" adv="1">14302</ref>
            <ref source="CONFIRM" patch="1" url="http://djeyl.net/forum/index.php?showtopic=41440" adv="1">http://djeyl.net/forum/index.php?showtopic=41440</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webmod" name="webmod">
                <vers num="0.47" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0613" seq="2005-0613" severity="Medium" type="CVE" published="2005-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12676" adv="1">12676</ref>
        </refs>
        <vuln_soft>
            <prod vendor="fckeditor" name="fckeditor">
                <vers num="2.0_rc2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0616" seq="2005-0616" severity="Medium" type="CVE" published="2005-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6) Version, or (7) Home page variables.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1013324" adv="1">1013324</ref>
            <ref source="CONFIRM" patch="1" url="http://news.postnuke.com/Article2669.html" adv="1">http://news.postnuke.com/Article2669.html</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110962768300373&amp;w=2" adv="1">20050228 [SECURITYREASON.COM] PostNuke Critical XSS 0.760-RC2=>x cXIb8O3.2</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0619" seq="2005-0619" severity="Low" type="CVE" published="2005-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/14212" adv="1">14212</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013316" adv="1">1013316</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14455" adv="1">14455</ref>
            <ref source="MILW0RM" url="http://milw0rm.com/exploits/846">846</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bfriendly.com" name="einstein">
                <vers num="1.0.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0624" seq="2005-0624" severity="Low" type="CVE" published="2005-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19504" adv="1">reportbug-file-world-readable(19504)</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14422/" adv="1">14422</ref>
            <ref source="CONFIRM" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6600" adv="1">https://bugzilla.ubuntu.com/show_bug.cgi?id=6600</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972153627388&amp;w=2" adv="1">20050228 [USN-88-1] reportbug information disclosure</ref>
            <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="reportbug">
                <vers num="2.60" />
                <vers num="2.61" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0625" seq="2005-0625" severity="Low" type="CVE" published="2005-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19520" adv="1">reportbug-smtppasswd-information-disclosure(19520)</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14422/" adv="1">14422</ref>
            <ref source="CONFIRM" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6717" adv="1">https://bugzilla.ubuntu.com/show_bug.cgi?id=6717</ref>
            <ref source="MISC" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6600" adv="1">https://bugzilla.ubuntu.com/show_bug.cgi?id=6600</ref>
            <ref source="MISC" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972153627388&amp;w=2">20050228 [USN-88-1] reportbug information disclosure</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="reportbug">
                <vers num="2.60" />
                <vers num="2.61" />
                <vers num="3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0622" seq="2005-0622" severity="Medium" type="CVE" published="2005-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.security.org.sg/vuln/raidenhttpd1132.html" adv="1">http://www.security.org.sg/vuln/raidenhttpd1132.html</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14453" adv="1">14453</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969702013313&amp;w=2" adv="1">20050301 [SIG^2 G-TEC] RaidenHTTPD Server Buffer Overflow and CGI Source Disclosure Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="raidenhttpd" name="raidenhttpd">
                <vers num="1.1.32" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0623" seq="2005-0623" severity="High" type="CVE" published="2005-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.security.org.sg/vuln/raidenhttpd1132.html" adv="1">http://www.security.org.sg/vuln/raidenhttpd1132.html</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14453" adv="1">14453</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969702013313&amp;w=2" adv="1">20050301 [SIG^2 G-TEC] RaidenHTTPD Server Buffer Overflow and CGI Source Disclosure Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="raidenhttpd" name="raidenhttpd">
                <vers num="1.1.32" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0628" seq="2005-0628" severity="Medium" type="CVE" published="2005-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12689" adv="1">12689</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14418" adv="1">14418</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971101826900&amp;w=2" adv="1">20050301 Forumwa search.php xss vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="demof" name="forumwa">
                <vers num="v1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0629" seq="2005-0629" severity="Medium" type="CVE" published="2005-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19546" adv="1">427bb-profile-xss(19546)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12693" adv="1">12693</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013337" adv="1">1013337</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14434" adv="1">14434</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970911514167&amp;w=2" adv="1">20050301 427BB profile.php XSS vulnerability.</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970474726113&amp;w=2" adv="1">20050301 427BB profile.php XSS vulnerability.</ref>
        </refs>
        <vuln_soft>
            <prod vendor="427bb" name="fourtwosevenbb">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.2" />
                <vers num="2.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0630" seq="2005-0630" severity="Low" type="CVE" published="2005-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19544" adv="1">pblang-sendpm-obtain-information(19544)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12690" adv="1">12690</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971002211589&amp;w=2" adv="1">20050301 Software PBLang 4.63 sendpm.php reply file read vulnerability</ref>
            <ref source="CONFIRM" url="http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=40&amp;page=1">http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=40&amp;page=1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pblang" name="pblang">
                <vers num="4.0" />
                <vers num="4.56_4.5_rc2" />
                <vers num="4.6" />
                <vers num="4.63" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0631" seq="2005-0631" severity="Low" type="CVE" published="2005-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19552" adv="1">pblang-delpm-delete-messages(19552)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12694" adv="1">12694</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970738214608&amp;w=2" adv="1">20050301 Software PBLang 4.63 delpm.php authentication vulnerability</ref>
            <ref source="CONFIRM" url="http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=42&amp;page=1">http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=42&amp;page=1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pblang" name="pblang">
                <vers num="4.0" />
                <vers num="4.56_4.5_rc2" />
                <vers num="4.6" />
                <vers num="4.63" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0632" seq="2005-0632" severity="Medium" type="CVE" published="2005-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1013345" adv="1">1013345</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14449" adv="1">14449</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12696" adv="1">12696</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110989169008570&amp;w=2" adv="1">20050303 PHP News &lt;= 1.2.4 - Remote File Inclusion Exploit</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971663824719&amp;w=2" adv="1">20050301 PHP News &lt;= 1.2.4 - Remote File Inclusion (VXSfx)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpnews" name="phpnews">
                <vers num="1.2.3" />
                <vers num="1.2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0633" seq="2005-0633" severity="High" type="CVE" published="2005-03-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12703" adv="1">12703</ref>
            <ref source="MISC" patch="1" url="http://www.securiteam.com/exploits/5KP030KF5E.html" adv="1">http://www.securiteam.com/exploits/5KP030KF5E.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2005/0221" adv="1">ADV-2005-0221</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111023000624809&amp;w=2" adv="1">20050306 See-security advisory: Trillian Basic 3.0 PNG Processing Buffer overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cerulean_studios" name="trillian">
                <vers num="3.0" />
            </prod>
            <prod vendor="cerulean_studios" name="trillian_pro">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0620" seq="2005-0620" severity="Low" type="CVE" published="2005-03-02" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14455" adv="1">14455</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bfriendly.com" name="einstein">
                <vers num="1.0.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0605" seq="2005-0605" severity="High" type="CVE" published="2005-03-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12714" adv="1">12714</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-331.html" adv="1">RHSA-2005:331</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-15.xml" adv="1">GLSA-200503-15</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-723" adv="1">DSA-723</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1013339" adv="1">1013339</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200503-08.xml" adv="1">GLSA-200503-08</ref>
            <ref source="CONFIRM" patch="1" url="http://bugs.gentoo.org/show_bug.cgi?id=83655" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=83655</ref>
            <ref source="CONFIRM" patch="1" url="http://bugs.gentoo.org/show_bug.cgi?id=83598" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=83598</ref>
            <ref source="CONFIRM" url="https://bugs.freedesktop.org/attachment.cgi?id=1909" adv="1">https://bugs.freedesktop.org/attachment.cgi?id=1909</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-412.html">RHSA-2005:412</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-97-1">USN-97-1</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-92-1">USN-92-1</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-473.html">RHSA-2005:473</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-198.html">RHSA-2005:198</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-044.html">RHSA-2005:044</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html">FLSA-2006:152803</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19624">19624</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18316">18316</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18049">18049</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14460">14460</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U">20060403-01-U</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.57/SCOSA-2005.57.txt">SCOSA-2005.57</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.5/SCOSA-2006.5.txt">SCOSA-2006.5</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lesstif" name="lesstif">
                <vers num="0.93.94" />
            </prod>
            <prod vendor="sgi" name="propack">
                <vers num="3.0" />
            </prod>
            <prod vendor="x.org" name="x11r6">
                <vers num="6.7.0" />
                <vers num="6.8" />
                <vers num="6.8.1" />
            </prod>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="3.3" />
                <vers num="3.3.2" />
                <vers num="3.3.3" />
                <vers num="3.3.4" />
                <vers num="3.3.5" />
                <vers num="3.3.6" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.2.11" />
                <vers num="4.0.3" />
                <vers num="4.1.0" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.2.0" />
                <vers edition="" num="4.2.1" />
                <vers edition=":errata" num="4.2.1" />
                <vers num="4.3.0" />
                <vers num="4.3.0.1" />
                <vers num="4.3.0.2" />
            </prod>
            <prod vendor="altlinux" name="alt_linux">
                <vers edition="" num="2.3" />
                <vers edition=":junior" num="2.3" />
                <vers edition=":compact" num="2.3" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers edition="" num="10.0" />
                <vers edition=":amd64" num="10.0" />
                <vers edition="" num="10.1" />
                <vers edition=":x86_64" num="10.1" />
                <vers edition="" num="10.2" />
                <vers edition=":x86_64" num="10.2" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
                <vers edition="" num="2.1" />
                <vers edition=":x86_64" num="2.1" />
                <vers edition="" num="3.0" />
                <vers edition=":x86_64" num="3.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="3.0" />
                <vers edition=":workstation_server" num="3.0" />
                <vers edition=":advanced_server" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
                <vers edition="" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
                <vers edition=":workstation" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="3.0" />
                <vers num="4.0" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_2.0" />
                <vers num="core_3.0" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers edition="alpha" num="6.1" />
                <vers num="6.2" />
                <vers edition="" num="6.3" />
                <vers edition=":ppc" num="6.3" />
                <vers edition="alpha" num="6.3" />
                <vers edition="" num="6.4" />
                <vers edition=":ppc" num="6.4" />
                <vers edition=":i386" num="6.4" />
                <vers edition="alpha" num="6.4" />
                <vers edition="" num="7.0" />
                <vers edition=":i386" num="7.0" />
                <vers edition=":sparc" num="7.0" />
                <vers edition=":ppc" num="7.0" />
                <vers edition="alpha" num="7.0" />
                <vers edition="" num="7.1" />
                <vers edition=":sparc" num="7.1" />
                <vers edition=":x86" num="7.1" />
                <vers edition=":spa" num="7.1" />
                <vers edition="alpha" num="7.1" />
                <vers edition="" num="7.2" />
                <vers edition=":i386" num="7.2" />
                <vers edition="" num="7.3" />
                <vers edition=":ppc" num="7.3" />
                <vers edition=":sparc" num="7.3" />
                <vers edition=":i386" num="7.3" />
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers edition="" num="9.1" />
                <vers edition=":x86_64" num="9.1" />
                <vers edition="" num="9.2" />
                <vers edition=":x86_64" num="9.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0638" seq="2005-0638" severity="High" type="CVE" published="2005-03-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14459" adv="1">14459</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-695" adv="1">DSA-695</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-05.xml" adv="1">GLSA-200503-05</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14462" adv="1">14462</ref>
            <ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=79762" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=79762</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12712">12712</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433935/30/5010/threaded">FLSA-2006:152923</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-332.html">RHSA-2005:332</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/14365">14365</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-134_RHSA-2005-332.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-134_RHSA-2005-332.pdf</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xli" name="xli">
                <vers num="1.14" />
                <vers num="1.15" />
                <vers num="1.16" />
                <vers num="1.17" />
            </prod>
            <prod vendor="altlinux" name="alt_linux">
                <vers edition="" num="2.3" />
                <vers edition=":junior" num="2.3" />
                <vers edition=":compact" num="2.3" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="4.2" />
                <vers num="4.3" />
                <vers num="4.4" />
                <vers num="4.4.1" />
                <vers num="5.0" />
                <vers num="5.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers edition="alpha" num="6.1" />
                <vers num="6.2" />
                <vers edition="" num="6.3" />
                <vers edition=":ppc" num="6.3" />
                <vers edition="alpha" num="6.3" />
                <vers edition="" num="6.4" />
                <vers edition=":ppc" num="6.4" />
                <vers edition=":i386" num="6.4" />
                <vers edition="alpha" num="6.4" />
                <vers edition="" num="7.0" />
                <vers edition=":i386" num="7.0" />
                <vers edition=":sparc" num="7.0" />
                <vers edition=":ppc" num="7.0" />
                <vers edition="alpha" num="7.0" />
                <vers edition="" num="7.1" />
                <vers edition=":sparc" num="7.1" />
                <vers edition=":x86" num="7.1" />
                <vers edition=":spa" num="7.1" />
                <vers edition="alpha" num="7.1" />
                <vers edition="" num="7.2" />
                <vers edition=":i386" num="7.2" />
                <vers edition="" num="7.3" />
                <vers edition=":ppc" num="7.3" />
                <vers edition=":sparc" num="7.3" />
                <vers edition=":i386" num="7.3" />
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers edition="" num="9.1" />
                <vers edition=":x86_64" num="9.1" />
                <vers edition="" num="9.2" />
                <vers edition=":x86_64" num="9.2" />
                <vers num="9.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0639" seq="2005-0639" severity="High" type="CVE" published="2005-03-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14459" adv="1">14459</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-695" adv="1">DSA-695</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-05.xml" adv="1">GLSA-200503-05</ref>
            <ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=79762" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=79762</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xli" name="xli">
                <vers num="1.14" />
                <vers num="1.15" />
                <vers num="1.16" />
                <vers num="1.17" />
            </prod>
            <prod vendor="altlinux" name="alt_linux">
                <vers edition="" num="2.3" />
                <vers edition=":junior" num="2.3" />
                <vers edition=":compact" num="2.3" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="4.2" />
                <vers num="4.3" />
                <vers num="4.4" />
                <vers num="4.4.1" />
                <vers num="5.0" />
                <vers num="5.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers edition="alpha" num="6.1" />
                <vers num="6.2" />
                <vers edition="" num="6.3" />
                <vers edition=":ppc" num="6.3" />
                <vers edition="alpha" num="6.3" />
                <vers edition="" num="6.4" />
                <vers edition=":ppc" num="6.4" />
                <vers edition=":i386" num="6.4" />
                <vers edition="alpha" num="6.4" />
                <vers edition="" num="7.0" />
                <vers edition=":i386" num="7.0" />
                <vers edition=":sparc" num="7.0" />
                <vers edition=":ppc" num="7.0" />
                <vers edition="alpha" num="7.0" />
                <vers edition="" num="7.1" />
                <vers edition=":sparc" num="7.1" />
                <vers edition=":x86" num="7.1" />
                <vers edition=":spa" num="7.1" />
                <vers edition="alpha" num="7.1" />
                <vers edition="" num="7.2" />
                <vers edition=":i386" num="7.2" />
                <vers edition="" num="7.3" />
                <vers edition=":ppc" num="7.3" />
                <vers edition=":sparc" num="7.3" />
                <vers edition=":i386" num="7.3" />
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers edition="" num="9.1" />
                <vers edition=":x86_64" num="9.1" />
                <vers edition="" num="9.2" />
                <vers edition=":x86_64" num="9.2" />
                <vers num="9.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0640" seq="2005-0640" severity="Medium" type="CVE" published="2005-03-02" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323" adv="1">http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14454" adv="1">14454</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ca" name="unicenter_asset_management">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0641" seq="2005-0641" severity="Medium" type="CVE" published="2005-03-02" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14454" adv="1">14454</ref>
            <ref source="CONFIRM" url="http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323" adv="1">http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ca" name="unicenter_asset_management">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2005-0636" seq="2005-0636" severity="High" type="CVE" published="2005-03-02" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12711" adv="1">12711</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/391960" adv="1">20050302 Foxmail server "USER" command Multiple remote buffer overflow</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013356" adv="1">1013356</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14145" adv="1">14145</ref>
        </refs>
        <vuln_soft>
            <prod vendor="foxmail" name="foxmail_email_server">
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0671" seq="2005-0671" severity="High" type="CVE" published="2005-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12727" adv="1">12727</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14483" adv="1">14483</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013361" adv="1">1013361</ref>
            <ref source="MISC" url="http://aluigi.altervista.org/adv/ca3dex-adv.txt" adv="1">http://aluigi.altervista.org/adv/ca3dex-adv.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ca3de" name="ca3de">
                <vers num="march_2004" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0674" seq="2005-0674" severity="Medium" type="CVE" published="2005-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the News module for paBox 1.6 allows remote attackers to inject arbitrary web script or HTML via the text hidden parameter in an HTTP POST request.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12719" adv="1">12719</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013363" adv="1">1013363</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14474" adv="1">14474</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110987537431541&amp;w=2" adv="1">20050303 [XSS] paBox 1.6</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php_arena" name="pabox">
                <vers num="1.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0668" seq="2005-0668" severity="High" type="CVE" published="2005-03-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.bemberg.de/server-side/index.htm" adv="1">http://www.bemberg.de/server-side/index.htm</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1013370" adv="1">1013370</ref>
        </refs>
        <vuln_soft>
            <prod vendor="christian_hilgers" name="http_anti_virus_proxy_(havp)">
                <vers num="0.50" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2005-0593" seq="2005-0593" severity="Low" type="CVE" published="2005-03-04" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" adv="1">GLSA-200503-10</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=277564" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=277564</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=276720" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=276720</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=268483" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=268483</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=258048" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=258048</ref>
            <ref source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-14.html">http://www.mozilla.org/security/announce/mfsa2005-14.html</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" adv="1">GLSA-200503-30</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100044" sig="1">oval:org.mitre.oval:def:100044</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="0.10" />
                <vers num="0.10.1" />
                <vers num="0.8" />
                <vers edition="rc" num="0.9" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
                <vers num="0.9.3" />
                <vers num="1.0" />
            </prod>
            <prod vendor="mozilla" name="mozilla">
                <vers num="1.3" />
                <vers edition="alpha" num="1.4" />
                <vers num="1.4.1" />
                <vers edition="alpha" num="1.5" />
                <vers edition="rc1" num="1.5" />
                <vers edition="rc2" num="1.5" />
                <vers num="1.5.1" />
                <vers edition="alpha" num="1.6" />
                <vers edition="beta" num="1.6" />
                <vers edition="alpha" num="1.7" />
                <vers edition="beta" num="1.7" />
                <vers edition="rc1" num="1.7" />
                <vers edition="rc2" num="1.7" />
                <vers edition="rc3" num="1.7" />
                <vers num="1.7.1" />
                <vers num="1.7.2" />
                <vers num="1.7.3" />
                <vers num="1.7.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0688" seq="2005-0688" severity="Medium" type="CVE" published="2005-03-05" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" adv="1">MS05-019</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111005099504081&amp;w=2" adv="1">20050305 Windows Server 2003 and XP SP2 LAND attack vulnerability</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded">HPSBST02161</ref>
            <ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx">MS06-064</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3983">ADV-2006-3983</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22341">22341</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4978" sig="1">oval:org.mitre.oval:def:4978</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:482" sig="1">oval:org.mitre.oval:def:482</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1685" sig="1">oval:org.mitre.oval:def:1685</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1288" sig="1">oval:org.mitre.oval:def:1288</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2003_server">
                <vers num="r2" />
            </prod>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition="sp2" num="" />
                <vers edition="sp2:tablet_pc" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2005-0109" seq="2005-0109" severity="High" type="CVE" published="2005-03-05" CVSS_version="2.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/911878" adv="1">VU#911878</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12724" adv="1">12724</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2005/0540" adv="1">ADV-2005-0540</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1013967" adv="1">1013967</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-800.html">RHSA-2005:800</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-476.html">RHSA-2005:476</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/3002">ADV-2005-3002</ref>
            <ref source="MISC" url="http://www.daemonology.net/papers/htt.pdf">http://www.daemonology.net/papers/htt.pdf</ref>
            <ref source="MISC" url="http://www.daemonology.net/hyperthreading-considered-harmful/">http://www.daemonology.net/hyperthreading-considered-harmful/</ref>
            <ref source="MISC" url="http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754">http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1" adv="1">101739</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18165">18165</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15348">15348</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openbsd-misc&amp;m=110995101417256&amp;w=2">[openbsd-misc] 20050304 Re: FreeBSD hiding security stuff</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=110994370429609&amp;w=2">[freebsd-security] 20050304 [Fwd: Re: FW:FreeBSD hiding security stuff]</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=freebsd-hackers&amp;m=110994026421858&amp;w=2">[freebsd-hackers] 20050304 Re: FW:FreeBSD hiding security stuff</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txt">SCOSA-2005.24</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="1.1.5.1" />
                <vers num="2.0" />
                <vers num="2.0.5" />
                <vers num="2.1.0" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.6.1" />
                <vers num="2.1.7.1" />
                <vers num="2.2" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.8" />
                <vers edition="releng" num="3.0" />
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.4" />
                <vers edition="stable" num="3.5" />
                <vers edition="release" num="3.5.1" />
                <vers edition="stable" num="3.5.1" />
                <vers edition="alpha" num="4.0" />
                <vers edition="releng" num="4.0" />
                <vers num="4.1" />
                <vers edition="release" num="4.1.1" />
                <vers edition="stable" num="4.1.1" />
                <vers edition="release" num="4.10" />
                <vers edition="release_p8" num="4.10" />
                <vers edition="releng" num="4.10" />
                <vers edition="release_p3" num="4.11" />
                <vers edition="releng" num="4.11" />
                <vers edition="stable" num="4.11" />
                <vers edition="stable" num="4.2" />
                <vers edition="release" num="4.3" />
                <vers edition="release_p38" num="4.3" />
                <vers edition="releng" num="4.3" />
                <vers edition="stable" num="4.3" />
                <vers edition="release_p42" num="4.4" />
                <vers edition="releng" num="4.4" />
                <vers edition="stable" num="4.4" />
                <vers edition="release" num="4.5" />
                <vers edition="release_p32" num="4.5" />
                <vers edition="releng" num="4.5" />
                <vers edition="stable" num="4.5" />
                <vers edition="release" num="4.6" />
                <vers edition="release_p20" num="4.6" />
                <vers edition="releng" num="4.6" />
                <vers edition="stable" num="4.6" />
                <vers num="4.6.2" />
                <vers edition="release" num="4.7" />
                <vers edition="release_p17" num="4.7" />
                <vers edition="releng" num="4.7" />
                <vers edition="stable" num="4.7" />
                <vers edition="pre-release" num="4.8" />
                <vers edition="release_p6" num="4.8" />
                <vers edition="releng" num="4.8" />
                <vers edition="pre-release" num="4.9" />
                <vers edition="releng" num="4.9" />
                <vers edition="alpha" num="5.0" />
                <vers edition="release_p14" num="5.0" />
                <vers edition="releng" num="5.0" />
                <vers edition="alpha" num="5.1" />
                <vers edition="release" num="5.1" />
                <vers edition="release_p5" num="5.1" />
                <vers edition="releng" num="5.1" />
                <vers num="5.2" />
                <vers edition="release" num="5.2.1" />
                <vers edition="releng" num="5.2.1" />
                <vers edition="release" num="5.3" />
                <vers edition="releng" num="5.3" />
                <vers edition="stable" num="5.3" />
                <vers edition="pre-release" num="5.4" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":advanced_server_ia64" num="2.1" />
                <vers edition=":enterprise_server_ia64" num="2.1" />
                <vers edition=":workstation_ia64" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition="" num="3.0" />
                <vers edition=":workstation_server" num="3.0" />
                <vers edition=":advanced_server" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
                <vers edition="" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="3.0" />
                <vers num="4.0" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_3.0" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0.7" />
            </prod>
            <prod vendor="sco" name="unixware">
                <vers num="7.1.3" />
                <vers num="7.1.3_up" />
                <vers num="7.1.4" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="10.0" />
                <vers edition=":sparc" num="10.0" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition="x86_update_2" num="9.0" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers edition="" num="4.1" />
                <vers edition=":ppc" num="4.1" />
                <vers edition=":ia64" num="4.1" />
                <vers edition="" num="5.04" />
                <vers edition=":amd64" num="5.04" />
                <vers edition=":powerpc" num="5.04" />
                <vers edition=":i386" num="5.04" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0691" seq="2005-0691" severity="High" type="CVE" published="2005-03-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://waraxe.us/ftopic-542-0-days0-orderasc-.html" adv="1">http://waraxe.us/ftopic-542-0-days0-orderasc-.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022633903239&amp;w=2" adv="1">20050307 Remote Testing SocialMPN Remote File Inclusion by y3dips</ref>
        </refs>
        <vuln_soft>
            <prod vendor="socialmpn" name="socialmpn">
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0692" seq="2005-0692" severity="Medium" type="CVE" published="2005-03-06" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14492" adv="1">14492</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022851900028&amp;w=2" adv="1">20050306 PHP-FUSION 5.* XSS VULNERABILITY</ref>
            <ref source="CONFIRM" url="http://www.php-fusion.co.uk/news.php?readmore=183">http://www.php-fusion.co.uk/news.php?readmore=183</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php_fusion" name="php_fusion">
                <vers num="5.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0681" seq="2005-0681" severity="Medium" type="CVE" published="2005-03-06" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013380" adv="1">1013380</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19594">nokia-symbian-dos(19594)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12743">12743</ref>
            <ref source="MISC" url="http://www.securiteam.com/securitynews/5PP0V00G1S.html">http://www.securiteam.com/securitynews/5PP0V00G1S.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/14574">14574</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nokia" name="series">
                <vers num="60" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0687" seq="2005-0687" severity="High" type="CVE" published="2005-03-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via format string specifiers in a reply address, which is not properly handled when printing the header.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-12.xml" adv="1">GLSA-200503-12</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14487" adv="1">14487</ref>
            <ref source="MISC" patch="1" url="http://bugs.gentoo.org/show_bug.cgi?id=83541" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=83541</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hashcash" name="hashcash">
                <vers num="1.14" />
                <vers num="1.15" />
                <vers num="1.16" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0686" seq="2005-0686" severity="High" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Integer overflow in mlterm 2.5.0 through 2.9.1, with gdk-pixbuf support enabled, allows remote attackers to execute arbitrary code via a large image file that is used as a background.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://sourceforge.net/project/shownotes.php?release_id=310416" adv="1">https://sourceforge.net/project/shownotes.php?release_id=310416</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-13.xml" adv="1">GLSA-200503-13</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mlterm" name="mlterm">
                <vers num="2.5" />
                <vers num="2.6" />
                <vers num="2.6.1" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.7" />
                <vers num="2.8" />
                <vers num="2.9" />
                <vers num="2.9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2005-0667" seq="2005-0667" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-303.html" adv="1">RHSA-2005:303</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-26.xml" adv="1">GLSA-200503-26</ref>
            <ref source="CONFIRM" patch="1" url="http://sylpheed.good-day.net/changelog.html.en" adv="1">http://sylpheed.good-day.net/changelog.html.en</ref>
            <ref source="CONFIRM" patch="1" url="http://sylpheed.good-day.net/changelog-devel.html.en" adv="1">http://sylpheed.good-day.net/changelog-devel.html.en</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14491" adv="1">14491</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013376" adv="1">1013376</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sylpheed" name="sylpheed">
                <vers num="0.8.11" />
                <vers num="0.9.10" />
                <vers num="0.9.11" />
                <vers num="0.9.12" />
                <vers num="0.9.4" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.8" />
                <vers num="0.9.9" />
                <vers num="0.9.99" />
                <vers num="1.0.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
            </prod>
            <prod vendor="sylpheed-claws" name="sylpheed-claws">
                <vers num="1.0.2" />
            </prod>
            <prod vendor="altlinux" name="alt_linux">
                <vers edition="" num="2.3" />
                <vers edition=":junior" num="2.3" />
                <vers edition=":compact" num="2.3" />
            </prod>
            <prod vendor="gentoo" name="linux">
                <vers num="" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":workstation_ia64" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition=":advanced_server_ia64" num="2.1" />
                <vers edition=":enterprise_server_ia64" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_3.0" />
            </prod>
            <prod vendor="redhat" name="linux_advanced_workstation">
                <vers edition="" num="2.1" />
                <vers edition=":itanium_processor" num="2.1" />
                <vers edition=":ia64" num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0680" seq="2005-0680" severity="High" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.stadtaus.com/forum/t-1579.html" adv="1">http://www.stadtaus.com/forum/t-1579.html</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14513" adv="1">14513</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996056601719&amp;w=2" adv="1">20050304 Download Center Lite (DCL) - Arbitrary File Inclusion (VXSfx)</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0693" seq="2005-0693" severity="High" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12733" adv="1">12733</ref>
            <ref source="MISC" url="http://aluigi.altervista.org/adv/chasercool-adv.txt" adv="1">http://aluigi.altervista.org/adv/chasercool-adv.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jowood_productions" name="chaser">
                <vers num="1.0" />
                <vers num="1.50" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0694" seq="2005-0694" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14522" adv="1">14522</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026083314947&amp;w=2" adv="1">20050307 Hosting Controller Multiple Unauthenticated information disclose</ref>
            <ref source="MISC" patch="1" url="http://isun.shabgard.org/hc2.txt" adv="1">http://isun.shabgard.org/hc2.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hosting_controller" name="hosting_controller">
                <vers num="1.1" />
                <vers num="1.3" />
                <vers num="1.4.1" />
                <vers num="1.4b" />
                <vers num="6.1" />
                <vers num="6.1_hotfix_1.4" />
                <vers num="6.1_hotfix_1.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0695" seq="2005-0695" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14522" adv="1">14522</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026083314947&amp;w=2" adv="1">20050307 Hosting Controller Multiple Unauthenticated information disclose</ref>
            <ref source="MISC" patch="1" url="http://isun.shabgard.org/hc2.txt" adv="1">http://isun.shabgard.org/hc2.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hosting_controller" name="hosting_controller">
                <vers num="1.1" />
                <vers num="1.3" />
                <vers num="1.4.1" />
                <vers num="1.4b" />
                <vers num="6.1" />
                <vers num="6.1_hotfix_1.4" />
                <vers num="6.1_hotfix_1.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0689" seq="2005-0689" severity="High" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12738" adv="1">12738</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111030957413411&amp;w=2" adv="1">20050308 Re: Remote Command Execution</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111021730710779&amp;w=2" adv="1">20050307 Remote Command Execution</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jimmy" name="the_includer">
                <vers num="1.0" />
                <vers num="1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0690" seq="2005-0690" severity="Low" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12739" adv="1">12739</ref>
            <ref source="MISC" url="http://secway.org/Advisory/ad20050303.txt" adv="1">http://secway.org/Advisory/ad20050303.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14436" adv="1">14436</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026585431080&amp;w=2" adv="1">20050308 Re: Gene6 FTP Server Local Privilege Escalation Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022496826680&amp;w=2" adv="1">20050307 Gene6 FTP Server Local Privilege Escalation Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gene6" name="g6_ftp_server">
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.2" />
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.3.1" />
                <vers num="3.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0697" seq="2005-0697" severity="High" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in the process_picture function xp_publish.php in CopperExport 0.2.1 allows remote attackers to execute arbitrary SQL commands, possibly via the (1) title, (2) caption, or (3) keywords parameters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.zzamboni.org/copperexport/" adv="1">http://www.zzamboni.org/copperexport/</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14401" adv="1">14401</ref>
        </refs>
        <vuln_soft>
            <prod vendor="brt" name="copperexport">
                <vers num="0.1" />
                <vers num="0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0698" seq="2005-0698" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12747" adv="1">12747</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392552" adv="1">20050307 phpWebLog &lt;= 0.5.3 arbitrary file inclusion (VXSfx)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jason_hines" name="phpweblog">
                <vers num="0.4.2" />
                <vers num="0.5" />
                <vers num="0.5.1" />
                <vers num="0.5.2" />
                <vers num="0.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0548" seq="2005-0548" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57737-1" adv="1">57737</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205163531628&amp;w=2" adv="1">20050328 Multiple XSS issues in Sun AnswerBook2</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris_answerbook2">
                <vers num="1.2" />
                <vers num="1.3" />
                <vers num="1.4" />
                <vers num="1.4.1" />
                <vers num="1.4.2" />
                <vers num="1.4.3" />
                <vers num="1.4.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2005-0177" seq="2005-0177" severity="High" type="CVE" published="2005-03-07" CVSS_version="2.0" CVSS_score="7.8" modified="2008-09-05">
        <desc>
            <descript source="cve">nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-092.html" adv="1">RHSA-2005:092</ref>
            <ref source="CONFIRM" patch="1" url="http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" adv="1">CLA-2005:930</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-2005-0178" seq="2005-0178" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0" CVSS_score="6.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-092.html" adv="1">RHSA-2005:092</ref>
            <ref source="CONFIRM" patch="1" url="http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" adv="1">20050215 [USN-82-1] Linux kernel vulnerabilities</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" adv="1">CLA-2005:930</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netkit" name="linux_netkit">
                <vers num="0.17" />
                <vers num="0.17.17" />
            </prod>
            <prod vendor="vserver" name="linux-vserver">
                <vers num="1.20" />
                <vers num="1.21" />
                <vers num="1.22" />
                <vers num="1.23" />
                <vers num="1.24" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.11" />
                <vers num="2.0.12" />
                <vers num="2.0.13" />
                <vers num="2.0.14" />
                <vers num="2.0.15" />
                <vers num="2.0.16" />
                <vers num="2.0.17" />
                <vers num="2.0.18" />
                <vers num="2.0.19" />
                <vers num="2.0.2" />
                <vers num="2.0.20" />
                <vers num="2.0.21" />
                <vers num="2.0.22" />
                <vers num="2.0.23" />
                <vers num="2.0.24" />
                <vers num="2.0.25" />
                <vers num="2.0.26" />
                <vers num="2.0.27" />
                <vers num="2.0.28" />
                <vers num="2.0.29" />
                <vers num="2.0.3" />
                <vers num="2.0.30" />
                <vers num="2.0.31" />
                <vers num="2.0.32" />
                <vers num="2.0.33" />
                <vers num="2.0.34" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.7" />
                <vers num="2.0.8" />
                <vers num="2.0.9" />
                <vers num="2.0.9.9" />
                <vers num="2.1" />
                <vers num="2.1.89" />
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.2.11" />
                <vers num="2.2.12" />
                <vers num="2.2.13" />
                <vers num="2.2.14" />
                <vers edition="pre16" num="2.2.15" />
                <vers num="2.2.15_pre20" />
                <vers edition="pre6" num="2.2.16" />
                <vers num="2.2.17" />
                <vers num="2.2.18" />
                <vers num="2.2.19" />
                <vers num="2.2.2" />
                <vers num="2.2.20" />
                <vers num="2.2.21" />
                <vers num="2.2.22" />
                <vers num="2.2.23" />
                <vers num="2.2.24" />
                <vers num="2.2.25" />
                <vers edition="rc2" num="2.2.27" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
                <vers num="2.2.9" />
                <vers num="2.3.0" />
                <vers edition="pre1" num="2.3.99" />
                <vers edition="pre2" num="2.3.99" />
                <vers edition="pre3" num="2.3.99" />
                <vers edition="pre4" num="2.3.99" />
                <vers edition="pre5" num="2.3.99" />
                <vers edition="pre6" num="2.3.99" />
                <vers edition="pre7" num="2.3.99" />
                <vers edition="test1" num="2.4.0" />
                <vers edition="test10" num="2.4.0" />
                <vers edition="test11" num="2.4.0" />
                <vers edition="test12" num="2.4.0" />
                <vers edition="test2" num="2.4.0" />
                <vers edition="test3" num="2.4.0" />
                <vers edition="test4" num="2.4.0" />
                <vers edition="test5" num="2.4.0" />
                <vers edition="test6" num="2.4.0" />
                <vers edition="test7" num="2.4.0" />
                <vers edition="test8" num="2.4.0" />
                <vers edition="test9" num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition="pre1" num="2.4.18" />
                <vers edition="pre2" num="2.4.18" />
                <vers edition="pre3" num="2.4.18" />
                <vers edition="pre4" num="2.4.18" />
                <vers edition="pre5" num="2.4.18" />
                <vers edition="pre6" num="2.4.18" />
                <vers edition="pre7" num="2.4.18" />
                <vers edition="pre8" num="2.4.18" />
                <vers edition="pre1" num="2.4.19" />
                <vers edition="pre2" num="2.4.19" />
                <vers edition="pre3" num="2.4.19" />
                <vers edition="pre4" num="2.4.19" />
                <vers edition="pre5" num="2.4.19" />
                <vers edition="pre6" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="pre1" num="2.4.21" />
                <vers edition="pre4" num="2.4.21" />
                <vers edition="pre7" num="2.4.21" />
                <vers edition="pre10" num="2.4.22" />
                <vers edition="pre9" num="2.4.23" />
                <vers num="2.4.23_ow2" />
                <vers num="2.4.24" />
                <vers num="2.4.24_ow1" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="pre1" num="2.4.27" />
                <vers edition="pre2" num="2.4.27" />
                <vers edition="pre3" num="2.4.27" />
                <vers edition="pre4" num="2.4.27" />
                <vers edition="pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="rc1" num="2.4.29" />
                <vers edition="rc2" num="2.4.29" />
                <vers edition="pre3" num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers edition="pre1" num="2.4.31" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.5.0" />
                <vers num="2.5.1" />
                <vers num="2.5.10" />
                <vers num="2.5.11" />
                <vers num="2.5.12" />
                <vers num="2.5.13" />
                <vers num="2.5.14" />
                <vers num="2.5.15" />
                <vers num="2.5.16" />
                <vers num="2.5.17" />
                <vers num="2.5.18" />
                <vers num="2.5.19" />
                <vers num="2.5.2" />
                <vers num="2.5.20" />
                <vers num="2.5.21" />
                <vers num="2.5.22" />
                <vers num="2.5.23" />
                <vers num="2.5.24" />
                <vers num="2.5.25" />
                <vers num="2.5.26" />
                <vers num="2.5.27" />
                <vers num="2.5.28" />
                <vers num="2.5.29" />
                <vers num="2.5.3" />
                <vers num="2.5.30" />
                <vers num="2.5.31" />
                <vers num="2.5.32" />
                <vers num="2.5.33" />
                <vers num="2.5.34" />
                <vers num="2.5.35" />
                <vers num="2.5.36" />
                <vers num="2.5.37" />
                <vers num="2.5.38" />
                <vers num="2.5.39" />
                <vers num="2.5.4" />
                <vers num="2.5.40" />
                <vers num="2.5.41" />
                <vers num="2.5.42" />
                <vers num="2.5.43" />
                <vers num="2.5.44" />
                <vers num="2.5.45" />
                <vers num="2.5.46" />
                <vers num="2.5.47" />
                <vers num="2.5.48" />
                <vers num="2.5.49" />
                <vers num="2.5.5" />
                <vers num="2.5.50" />
                <vers num="2.5.51" />
                <vers num="2.5.52" />
                <vers num="2.5.53" />
                <vers num="2.5.54" />
                <vers num="2.5.55" />
                <vers num="2.5.56" />
                <vers num="2.5.57" />
                <vers num="2.5.58" />
                <vers num="2.5.59" />
                <vers num="2.5.6" />
                <vers num="2.5.60" />
                <vers num="2.5.61" />
                <vers num="2.5.62" />
                <vers num="2.5.63" />
                <vers num="2.5.64" />
                <vers num="2.5.65" />
                <vers num="2.5.66" />
                <vers num="2.5.67" />
                <vers num="2.5.68" />
                <vers num="2.5.69" />
                <vers num="2.5.7" />
                <vers num="2.5.8" />
                <vers num="2.5.9" />
                <vers edition="test1" num="2.6.0" />
                <vers edition="test10" num="2.6.0" />
                <vers edition="test11" num="2.6.0" />
                <vers edition="test2" num="2.6.0" />
                <vers edition="test3" num="2.6.0" />
                <vers edition="test4" num="2.6.0" />
                <vers edition="test5" num="2.6.0" />
                <vers edition="test6" num="2.6.0" />
                <vers edition="test7" num="2.6.0" />
                <vers edition="test8" num="2.6.0" />
                <vers edition="test9" num="2.6.0" />
                <vers edition="rc1" num="2.6.1" />
                <vers edition="rc2" num="2.6.1" />
                <vers edition="rc2" num="2.6.10" />
                <vers edition="rc2" num="2.6.11" />
                <vers edition="rc3" num="2.6.11" />
                <vers edition="rc4" num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers edition="rc1" num="2.6.12" />
                <vers edition="rc4" num="2.6.12" />
                <vers num="2.6.2" />
                <vers num="2.6.20.1" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers edition="rc1" num="2.6.6" />
                <vers edition="rc1" num="2.6.7" />
                <vers edition="rc1" num="2.6.8" />
                <vers edition="rc2" num="2.6.8" />
                <vers edition="rc3" num="2.6.8" />
                <vers num="2.6_test9_cvs" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0179" seq="2005-0179" severity="Low" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-092.html" adv="1">RHSA-2005:092</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" adv="1">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" adv="1">CLA-2005:930</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="test1" num="2.4.0" />
                <vers edition="test10" num="2.4.0" />
                <vers edition="test11" num="2.4.0" />
                <vers edition="test12" num="2.4.0" />
                <vers edition="test2" num="2.4.0" />
                <vers edition="test3" num="2.4.0" />
                <vers edition="test4" num="2.4.0" />
                <vers edition="test5" num="2.4.0" />
                <vers edition="test6" num="2.4.0" />
                <vers edition="test7" num="2.4.0" />
                <vers edition="test8" num="2.4.0" />
                <vers edition="test9" num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition="pre1" num="2.4.18" />
                <vers edition="pre2" num="2.4.18" />
                <vers edition="pre3" num="2.4.18" />
                <vers edition="pre4" num="2.4.18" />
                <vers edition="pre5" num="2.4.18" />
                <vers edition="pre6" num="2.4.18" />
                <vers edition="pre7" num="2.4.18" />
                <vers edition="pre8" num="2.4.18" />
                <vers edition="pre1" num="2.4.19" />
                <vers edition="pre2" num="2.4.19" />
                <vers edition="pre3" num="2.4.19" />
                <vers edition="pre4" num="2.4.19" />
                <vers edition="pre5" num="2.4.19" />
                <vers edition="pre6" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="pre1" num="2.4.21" />
                <vers edition="pre4" num="2.4.21" />
                <vers edition="pre7" num="2.4.21" />
                <vers edition="pre10" num="2.4.22" />
                <vers edition="pre9" num="2.4.23" />
                <vers num="2.4.23_ow2" />
                <vers num="2.4.24" />
                <vers num="2.4.24_ow1" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="pre1" num="2.4.27" />
                <vers edition="pre2" num="2.4.27" />
                <vers edition="pre3" num="2.4.27" />
                <vers edition="pre4" num="2.4.27" />
                <vers edition="pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="rc1" num="2.4.29" />
                <vers edition="rc2" num="2.4.29" />
                <vers edition="pre3" num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers edition="pre1" num="2.4.31" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers edition="test1" num="2.6.0" />
                <vers edition="test10" num="2.6.0" />
                <vers edition="test11" num="2.6.0" />
                <vers edition="test2" num="2.6.0" />
                <vers edition="test3" num="2.6.0" />
                <vers edition="test4" num="2.6.0" />
                <vers edition="test5" num="2.6.0" />
                <vers edition="test6" num="2.6.0" />
                <vers edition="test7" num="2.6.0" />
                <vers edition="test8" num="2.6.0" />
                <vers edition="test9" num="2.6.0" />
                <vers edition="rc1" num="2.6.1" />
                <vers edition="rc2" num="2.6.1" />
                <vers edition="rc2" num="2.6.10" />
                <vers edition="rc2" num="2.6.11" />
                <vers edition="rc3" num="2.6.11" />
                <vers edition="rc4" num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers edition="rc1" num="2.6.12" />
                <vers edition="rc4" num="2.6.12" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers edition="rc1" num="2.6.6" />
                <vers edition="rc1" num="2.6.7" />
                <vers edition="rc1" num="2.6.8" />
                <vers edition="rc2" num="2.6.8" />
                <vers edition="rc3" num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers edition="2.6.20" num="2.6.9" />
                <vers num="2.6_test9_cvs" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" name="CVE-2005-0180" seq="2005-0180" severity="Low" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="3.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-092.html" adv="1">RHSA-2005:092</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" adv="1">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" adv="1">CLA-2005:930</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12198">12198</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/386374">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref>
            <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="test1" num="2.6.0" />
                <vers edition="test10" num="2.6.0" />
                <vers edition="test11" num="2.6.0" />
                <vers edition="test2" num="2.6.0" />
                <vers edition="test3" num="2.6.0" />
                <vers edition="test4" num="2.6.0" />
                <vers edition="test5" num="2.6.0" />
                <vers edition="test6" num="2.6.0" />
                <vers edition="test7" num="2.6.0" />
                <vers edition="test8" num="2.6.0" />
                <vers edition="test9" num="2.6.0" />
                <vers edition="rc1" num="2.6.1" />
                <vers edition="rc2" num="2.6.1" />
                <vers edition="rc2" num="2.6.10" />
                <vers edition="rc2" num="2.6.11" />
                <vers edition="rc3" num="2.6.11" />
                <vers edition="rc4" num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers edition="rc1" num="2.6.12" />
                <vers edition="rc4" num="2.6.12" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers edition="rc1" num="2.6.6" />
                <vers edition="rc1" num="2.6.7" />
                <vers edition="rc1" num="2.6.8" />
                <vers edition="rc2" num="2.6.8" />
                <vers edition="rc3" num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers edition="2.6.20" num="2.6.9" />
                <vers num="2.6_test9_cvs" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0700" seq="2005-0700" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12745" adv="1">12745</ref>
            <ref source="MISC" url="http://www.frsirt.com/exploits/20050307.aztek.c.php" adv="1">http://www.frsirt.com/exploits/20050307.aztek.c.php</ref>
        </refs>
        <vuln_soft>
            <prod vendor="aztek_forum" name="aztek_forum">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0701" seq="2005-0701" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.."  (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.argeniss.com/research/ARGENISS-ADV-030501.txt" adv="1">http://www.argeniss.com/research/ARGENISS-ADV-030501.txt</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111023635928211&amp;w=2" adv="1">20050307 - Argeniss - Oracle Database Server Directory transversal</ref>
            <ref source="FULLDISC" patch="1" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032273.html" adv="1">20050307 - Argeniss - Oracle Database Server Directory transversal</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0702" seq="2005-0702" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.phpmyfaq.de/advisory_2005-03-06.php" adv="1">http://www.phpmyfaq.de/advisory_2005-03-06.php</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14516" adv="1">14516</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpmyfaq" name="phpmyfaq">
                <vers num="1.4" />
                <vers num="1.4_alpha1" />
                <vers num="1.4_alpha2" />
                <vers num="1.4a" />
                <vers num="1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0703" seq="2005-0703" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, has an "unauthenticated account," which allows remote attackers to modify system configuration, a different vulnerability than CVE-2005-1179.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14507" adv="1">14507</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xerox" name="workcentre_165">
                <vers edition=":pro" num="" />
                <vers edition="" num="7.47.30.000" />
                <vers edition=":pro" num="7.47.30.000" />
                <vers edition="" num="7.47.33.008" />
                <vers edition=":pro" num="7.47.33.008" />
            </prod>
            <prod vendor="xerox" name="workcentre_175">
                <vers edition=":pro" num="" />
                <vers edition="" num="7.47.30.000" />
                <vers edition=":pro" num="7.47.30.000" />
                <vers edition="" num="7.47.33.008" />
                <vers edition=":pro" num="7.47.33.008" />
            </prod>
            <prod vendor="xerox" name="workcentre_2128">
                <vers edition=":pro_color" num="" />
                <vers edition="" num="0.001.04.044" />
                <vers edition=":pro_color" num="0.001.04.044" />
            </prod>
            <prod vendor="xerox" name="workcentre_2636">
                <vers edition=":pro_color" num="" />
                <vers edition="" num="0.001.04.044" />
                <vers edition=":pro_color" num="0.001.04.044" />
            </prod>
            <prod vendor="xerox" name="workcentre_32_color">
                <vers edition=":pro" num="" />
                <vers edition="" num="0.001.00.060" />
                <vers edition=":pro" num="0.001.00.060" />
                <vers edition="" num="0.001.02.081" />
                <vers edition=":pro" num="0.001.02.081" />
            </prod>
            <prod vendor="xerox" name="workcentre_35">
                <vers edition=":pro" num="" />
                <vers edition="" num="3.028.11.000" />
                <vers edition=":pro" num="3.028.11.000" />
                <vers edition="" num="3.97.20.032" />
                <vers edition=":pro" num="3.97.20.032" />
            </prod>
            <prod vendor="xerox" name="workcentre_3545">
                <vers edition=":pro_color" num="" />
                <vers edition="" num="0.001.04.044" />
                <vers edition=":pro_color" num="0.001.04.044" />
            </prod>
            <prod vendor="xerox" name="workcentre_40_color">
                <vers edition=":pro" num="" />
                <vers edition="" num="0.001.00.060" />
                <vers edition=":pro" num="0.001.00.060" />
                <vers edition="" num="0.001.02.081" />
                <vers edition=":pro" num="0.001.02.081" />
            </prod>
            <prod vendor="xerox" name="workcentre_45">
                <vers edition=":pro" num="" />
                <vers edition="" num="3.028.11.000" />
                <vers edition=":pro" num="3.028.11.000" />
                <vers edition="" num="3.97.20.032" />
                <vers edition=":pro" num="3.97.20.032" />
            </prod>
            <prod vendor="xerox" name="workcentre_55">
                <vers edition=":pro" num="" />
                <vers edition="" num="3.028.11.000" />
                <vers edition=":pro" num="3.028.11.000" />
                <vers edition="" num="3.97.20.032" />
                <vers edition=":pro" num="3.97.20.032" />
            </prod>
            <prod vendor="xerox" name="workcentre_65">
                <vers edition=":pro" num="" />
                <vers edition="" num="1.001.00.060" />
                <vers edition=":pro" num="1.001.00.060" />
                <vers edition="" num="1.001.02.084" />
                <vers edition=":pro" num="1.001.02.084" />
            </prod>
            <prod vendor="xerox" name="workcentre_75">
                <vers edition=":pro" num="" />
                <vers edition="" num="1.001.00.060" />
                <vers edition=":pro" num="1.001.00.060" />
                <vers edition="" num="1.001.02.084" />
                <vers edition=":pro" num="1.001.02.084" />
            </prod>
            <prod vendor="xerox" name="workcentre_90">
                <vers edition=":pro" num="" />
                <vers edition="" num="1.001.00.060" />
                <vers edition=":pro" num="1.001.00.060" />
                <vers edition="" num="1.001.02.084" />
                <vers edition=":pro" num="1.001.02.084" />
            </prod>
            <prod vendor="xerox" name="workcentre_m165">
                <vers num="6.47.30.000" />
                <vers num="6.47.33.008" />
                <vers num="8.47.30.000" />
                <vers num="8.47.33.008" />
            </prod>
            <prod vendor="xerox" name="workcentre_m175">
                <vers num="6.47.30.000" />
                <vers num="6.47.33.008" />
                <vers num="8.47.30.000" />
                <vers num="8.47.33.008" />
            </prod>
            <prod vendor="xerox" name="workcentre_m35">
                <vers num="2.28.11.000" />
                <vers num="2.97.20.032" />
                <vers num="4.84.16.000" />
            </prod>
            <prod vendor="xerox" name="workcentre_m45">
                <vers num="2.28.11.000" />
                <vers num="2.97.20.032" />
                <vers num="4.84.16.000" />
            </prod>
            <prod vendor="xerox" name="workcentre_m55">
                <vers num="2.28.11.000" />
                <vers num="2.97.20.032" />
                <vers num="4.84.16.000" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0722" seq="2005-0722" severity="Medium" type="CVE" published="2005-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111030766324600&amp;w=2" adv="1">20050307 Multiples Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="experience2" name="experience2">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0723" seq="2005-0723" severity="Medium" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using pafiledb.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031801802851&amp;w=2" adv="1">20050308 Multiple vulnerabilities in paFileDB</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php_arena" name="pafiledb">
                <vers num="3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0720" seq="2005-0720" severity="High" type="CVE" published="2005-03-08" CVSS_version="2.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19616" adv="1">mcnews-skinfile-file-include(19616)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12776">12776</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/476277/100/0/threaded">20070811 mcNews (skinfile) Remote File Include Vulnerability</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14528" adv="1">14528</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111025679324892&amp;w=2" adv="1">20050307 PHP mcNews &lt;= 1.3 arbitrary file inclusion (VXSfx)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mcnews" name="mcnews">
                <vers num="1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0741" seq="2005-0741" severity="Medium" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12756" adv="1">12756</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013420" adv="1">1013420</ref>
        </refs>
        <vuln_soft>
            <prod vendor="yabb" name="yabb">
                <vers num="2.0_rc1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0725" seq="2005-0725" severity="High" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19660" adv="1">wfsections-wfsfiles-sql-injection(19660)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111049618519821&amp;w=2" adv="1">20050308 Wfsection 1.07 vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wf-sections" name="wf-sections">
                <vers num="1.07" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0747" seq="2005-0747" severity="Medium" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">ApplyYourself i-Class allows remote attackers to obtain sensitive information about their own applications by reusing the hidden ID field, as demonstrated using the id parameter to ApplicantDecision.asp.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1013400" adv="1">1013400</ref>
        </refs>
        <vuln_soft>
            <prod vendor="applyyourself" name="i-class">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0098" seq="2005-0098" severity="Medium" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-691" adv="1">DSA-691</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14495" adv="1">14495</ref>
        </refs>
        <vuln_soft>
            <prod vendor="abuse" name="abuse-sdl">
                <vers num="2.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0099" seq="2005-0099" severity="Low" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-691" adv="1">DSA-691</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14495" adv="1">14495</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/14610">14610</ref>
        </refs>
        <vuln_soft>
            <prod vendor="abuse" name="abuse-sdl">
                <vers num="2.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0699" seq="2005-0699" severity="High" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12759" adv="1">12759</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-306.html" adv="1">RHSA-2005:306</ref>
            <ref source="CONFIRM" patch="1" url="http://www.ethereal.com/appnotes/enpa-sa-00018.html" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200503-16.xml" adv="1">GLSA-200503-16</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392659" adv="1">20050308 Ethereal remote buffer overflow</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref>
            <ref source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-03-04">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-03-04</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083125521813&amp;w=2">20050314 Ethereal 0.10.9 and below remote root exploit</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111038641832400&amp;w=2">20050309 RE: Ethereal remote buffer overflow - addon</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ethereal_group" name="ethereal">
                <vers num="0.10.3" />
                <vers num="0.10.4" />
                <vers num="0.10.5" />
                <vers num="0.10.6" />
                <vers num="0.10.7" />
                <vers num="0.10.8" />
                <vers num="0.10.9" />
            </prod>
            <prod vendor="altlinux" name="alt_linux">
                <vers num="compact_2.3" />
                <vers num="junior_2.3" />
            </prod>
            <prod vendor="conectiva" name="linux">
                <vers num="10.0" />
                <vers num="9.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":workstation_ia64" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition=":advanced_server_ia64" num="2.1" />
                <vers edition=":enterprise_server_ia64" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
                <vers edition="" num="3.0" />
                <vers edition=":advanced_server" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
                <vers edition=":workstation_server" num="3.0" />
                <vers edition="" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="3.0" />
                <vers num="4.0" />
            </prod>
            <prod vendor="redhat" name="linux_advanced_workstation">
                <vers edition="" num="2.1" />
                <vers edition=":itanium_processor" num="2.1" />
                <vers edition=":ia64" num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0696" seq="2005-0696" severity="High" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12755" adv="1">12755</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14526" adv="1">14526</ref>
            <ref source="MISC" url="https://www.securinfos.info/english/security-advisories-alerts/20060225_ArGoSoft.FTP.Server_Heap.Overflow.html">https://www.securinfos.info/english/security-advisories-alerts/20060225_ArGoSoft.FTP.Server_Heap.Overflow.html</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426081/100/0/threaded">20060225 ArGoSoft FTP server remote heap overflow</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392653" adv="1">20050308 ArGoSoft FTP Server 1.4.2.8 Buffer Overflow</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015681">1015681</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042523.html">20060225 ArGoSoft FTP server remote heap overflow</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/494">494</ref>
        </refs>
        <vuln_soft>
            <prod vendor="argosoft" name="ftp_server">
                <vers num="1.4.2.29" />
                <vers num="1.4.2.8" />
                <vers num="1.4.3.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0685" seq="2005-0685" severity="High" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete arbitrary directory objects by modifying the selectedObjectsCSV parameter to displaydeletenavigator.jsp, and conduct other unauthorized activities via the (4) showDeleteView, (5) showWebFolderView, (6) showLibraryView, (7) showMyLibraryView, (8) singleSelectObject, (9) processRadioSelection, (10) processCheckboxSelection, (11) singleSelectObject, (12) addToSelectedObjects, or (13) removeFromSelectedObjects commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19632" adv="1">pe-access-validation-dos(19632)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12752" adv="1">12752</ref>
            <ref source="MISC" patch="1" url="http://security.honour.ca/outstartpsi.txt" adv="1">http://security.honour.ca/outstartpsi.txt</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14542" adv="1">14542</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392623" adv="1">20050308 PE Multiple Remote Access Validation Vulnerabilities (Participate Systems Inc. / Outstart Inc.)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="outstart" name="participate_enterprise">
                <vers num="3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2005-0626" seq="2005-0626" severity="Low" type="CVE" published="2005-03-08" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19581" adv="1">squid-set-cookie-race-condition(19581)</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-93-1">USN-93-1</ref>
            <ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookie" adv="1">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookie</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-415.html">RHSA-2005:415</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12716">12716</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squid" name="squid">
                <vers num="2.5.stable5" />
                <vers num="2.5.stable6" />
                <vers num="2.5.stable7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0745" seq="2005-0745" severity="Medium" type="CVE" published="2005-03-09" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14544" adv="1">14544</ref>
            <ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Mar/0168.html" adv="1">20050307 Re: Lingo VoIP ATA / UTStarcom iAN-02EX remote access vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="utstarcom" name="ian-02ex_voip_ata">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0719" seq="2005-0719" severity="Low" type="CVE" published="2005-03-09" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in the systems message queue in HP Tru64 Unix 4.0F PK8 through 5.1B-2/PK4 allows local users to cause a denial of service (process crash) for processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and xntpd.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19642" adv="1">tru64-system-message-dos(19642)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12768" adv="1">12768</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14549/" adv="1">14549</ref>
            <ref source="HP" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040492127482&amp;w=2" adv="1">SSRT4891</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="tru64">
                <vers edition="pk8" num="4.0f" />
                <vers edition="pk4" num="4.0g" />
                <vers edition="pk6" num="5.1a" />
                <vers edition="pk3" num="5.1b1" />
                <vers edition="pk4" num="5.1b1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0736" seq="2005-0736" severity="Low" type="CVE" published="2005-03-09" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12763" adv="1">12763</ref>
            <ref source="FULLDISC" patch="1" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032314.html" adv="1">20050309 overwriting low kernel memory</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1">USN-95-1</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" adv="1">SUSE-SA:2005:018</ref>
            <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@422dd06a1p5PsyFhoGAJseinjEq3ew?nav=index.html%7CChangeSet@-1d">http://linux.bkbits.net:8080/linux-2.6/cset@422dd06a1p5PsyFhoGAJseinjEq3ew?nav=index.html|ChangeSet@-1d</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref>
        </refs>
        <vuln_soft>
            <prod vendor="conectiva" name="linux">
                <vers num="10.0" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers edition="2.6.20" num="2.6.9" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="4.0" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_2.0" />
                <vers num="core_3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0731" seq="2005-0731" severity="Medium" type="CVE" published="2005-03-10" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Filelist.html.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19650" adv="1">active-webcam-filelist-dos(19650)</ref>
            <ref source="MISC" url="http://secway.org/advisory/ad20050104.txt" adv="1">http://secway.org/advisory/ad20050104.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14553" adv="1">14553</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html" adv="1">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref>
        </refs>
        <vuln_soft>
            <prod vendor="py_software" name="active_webcam">
                <vers num="5.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0748" seq="2005-0748" severity="High" type="CVE" published="2005-03-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14550">14550</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19651" adv="1">webinsta-initdb-file-include(19651)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12773" adv="1">12773</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/0248" adv="1">ADV-2005-0248</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013409" adv="1">1013409</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webinsta" name="webinsta_mailing_manager">
                <vers num="1.3d" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0774" seq="2005-0774" severity="High" type="CVE" published="2005-03-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in member.php and possibly other scripts in PhotoPost PHP 5.0 RC3 allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19675" adv="1">photopost-uid-sql-injection(19675)</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14576" adv="1">14576</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12779" adv="1">12779</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2" adv="1">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="photopost" name="photopost_php_pro">
                <vers num="5.0_rc3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0780" seq="2005-0780" severity="Medium" type="CVE" published="2005-03-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066293914977&amp;w=2" adv="1">20050312 [SECURITYREASON.COM]  Mass Full Path Disclosure in paFileDB</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php_arena" name="pafiledb">
                <vers num="1.1.3" />
                <vers num="2.1.1" />
                <vers num="3.0" />
                <vers num="3.0_beta_3.1" />
                <vers num="3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0765" seq="2005-0765" severity="Medium" type="CVE" published="2005-03-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in the JXTA dissector in Ethereal 0.10.9 allows remote attackers to cause a denial of service (application crash).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml" adv="1">GLSA-200503-16</ref>
            <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00018.html" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12762">12762</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ethereal_group" name="ethereal">
                <vers num="0.10.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0786" seq="2005-0786" severity="High" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12801" adv="1">12801</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14583" adv="1">14583</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082702422979&amp;w=2" adv="1">20050313 SimpGB SQL Injection Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19694" adv="1">simpgb-gbnew-sql-injection(19694)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="simpgb" name="simpgb">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0788" seq="2005-0788" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19693" adv="1">limewire-client-information-disclosure(19693)</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml" adv="1">GLSA-200503-37</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14555/" adv="1">14555</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082448213238&amp;w=2" adv="1">20050314 LimeWire Gnutella client two vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="limewire" name="limewire">
                <vers num="4.1.2" />
                <vers num="4.5.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0789" seq="2005-0789" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19695" adv="1">limewire-magnet-directory-traversal(19695)</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml" adv="1">GLSA-200503-37</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14555/" adv="1">14555</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082448213238&amp;w=2" adv="1">20050314 LimeWire Gnutella client two vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="limewire" name="limewire">
                <vers num="3.9.6" />
                <vers num="4.6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0790" seq="2005-0790" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7) remotehtmlview.php, (8) click.php, (9) adcontent.php, which reveal the path in a PHP error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc" adv="1">http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083286926490&amp;w=2" adv="1">20050314 [SECURITYREASON.COM] phpAdsNew 2.0.4-pr1 Multiple vulnerabilities cXIb8O3.9</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013429">1013429</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpadsnew" name="phpadsnew">
                <vers num="2.0.4_pr1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0791" seq="2005-0791" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12803" adv="1">12803</ref>
            <ref source="MISC" patch="1" url="http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc" adv="1">http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14592" adv="1">14592</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083286926490&amp;w=2" adv="1">20050314 [SECURITYREASON.COM] phpAdsNew 2.0.4-pr1 Multiple vulnerabilities cXIb8O3.9</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/14787">14787</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013429">1013429</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0795" seq="2005-0795" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.holacms.de/?content=changelog" adv="1">http://www.holacms.de/?content=changelog</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14566" adv="1">14566</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0210.html" adv="1">20050315 Virginity Security Advisory 2005-001 : Hola CMS - File destruction and System access</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hola" name="holacms">
                <vers num="1.2.10" />
                <vers num="1.2.9" />
                <vers num="1.4" />
                <vers num="1.4.1" />
                <vers num="1.4.2" />
                <vers num="1.4.2a" />
                <vers num="1.4.3" />
                <vers num="1.4.4" />
                <vers num="1.4.5" />
                <vers num="1.4.6" />
                <vers num="1.4.7" />
                <vers num="1.4.8" />
                <vers num="1.4.9" />
                <vers num="1.4.9_1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0504" seq="2005-0504" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0" CVSS_score="4.6" modified="2008-11-15">
        <desc>
            <descript source="cve">Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12195" adv="1">12195</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-508-1">USN-508-1</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-551.html">RHSA-2005:551</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-529.html">RHSA-2005:529</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/1878" adv="1">ADV-2005-1878</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013273">1013273</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30112">30112</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26651" adv="1">26651</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20338" adv="1">20338</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20163" adv="1">20163</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17002" adv="1">17002</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref>
            <ref source="CONFIRM" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0237.html">RHSA-2008:0237</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.2.11" />
                <vers num="2.2.12" />
                <vers num="2.2.13" />
                <vers num="2.2.14" />
                <vers edition="pre16" num="2.2.15" />
                <vers num="2.2.15_pre20" />
                <vers edition="pre6" num="2.2.16" />
                <vers num="2.2.17" />
                <vers num="2.2.18" />
                <vers num="2.2.19" />
                <vers num="2.2.2" />
                <vers num="2.2.20" />
                <vers num="2.2.21" />
                <vers num="2.2.22" />
                <vers num="2.2.23" />
                <vers num="2.2.24" />
                <vers num="2.2.25" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
                <vers num="2.2.9" />
                <vers num="2.3.0" />
                <vers edition="pre1" num="2.3.99" />
                <vers edition="pre2" num="2.3.99" />
                <vers edition="pre3" num="2.3.99" />
                <vers edition="pre4" num="2.3.99" />
                <vers edition="pre5" num="2.3.99" />
                <vers edition="pre6" num="2.3.99" />
                <vers edition="pre7" num="2.3.99" />
                <vers edition="test1" num="2.4.0" />
                <vers edition="test10" num="2.4.0" />
                <vers edition="test11" num="2.4.0" />
                <vers edition="test12" num="2.4.0" />
                <vers edition="test2" num="2.4.0" />
                <vers edition="test3" num="2.4.0" />
                <vers edition="test4" num="2.4.0" />
                <vers edition="test5" num="2.4.0" />
                <vers edition="test6" num="2.4.0" />
                <vers edition="test7" num="2.4.0" />
                <vers edition="test8" num="2.4.0" />
                <vers edition="test9" num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition="pre1" num="2.4.18" />
                <vers edition="pre2" num="2.4.18" />
                <vers edition="pre3" num="2.4.18" />
                <vers edition="pre4" num="2.4.18" />
                <vers edition="pre5" num="2.4.18" />
                <vers edition="pre6" num="2.4.18" />
                <vers edition="pre7" num="2.4.18" />
                <vers edition="pre8" num="2.4.18" />
                <vers edition="pre1" num="2.4.19" />
                <vers edition="pre2" num="2.4.19" />
                <vers edition="pre3" num="2.4.19" />
                <vers edition="pre4" num="2.4.19" />
                <vers edition="pre5" num="2.4.19" />
                <vers edition="pre6" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="pre1" num="2.4.21" />
                <vers edition="pre4" num="2.4.21" />
                <vers edition="pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="pre9" num="2.4.23" />
                <vers num="2.4.23_ow2" />
                <vers num="2.4.24" />
                <vers num="2.4.24_ow1" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="pre1" num="2.4.27" />
                <vers edition="pre2" num="2.4.27" />
                <vers edition="pre3" num="2.4.27" />
                <vers edition="pre4" num="2.4.27" />
                <vers edition="pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="rc2" num="2.4.29" />
                <vers num="2.4.3" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.5.0" />
                <vers num="2.5.1" />
                <vers num="2.5.10" />
                <vers num="2.5.11" />
                <vers num="2.5.12" />
                <vers num="2.5.13" />
                <vers num="2.5.14" />
                <vers num="2.5.15" />
                <vers num="2.5.16" />
                <vers num="2.5.17" />
                <vers num="2.5.18" />
                <vers num="2.5.19" />
                <vers num="2.5.2" />
                <vers num="2.5.20" />
                <vers num="2.5.21" />
                <vers num="2.5.22" />
                <vers num="2.5.23" />
                <vers num="2.5.24" />
                <vers num="2.5.25" />
                <vers num="2.5.26" />
                <vers num="2.5.27" />
                <vers num="2.5.28" />
                <vers num="2.5.29" />
                <vers num="2.5.3" />
                <vers num="2.5.30" />
                <vers num="2.5.31" />
                <vers num="2.5.32" />
                <vers num="2.5.33" />
                <vers num="2.5.34" />
                <vers num="2.5.35" />
                <vers num="2.5.36" />
                <vers num="2.5.37" />
                <vers num="2.5.38" />
                <vers num="2.5.39" />
                <vers num="2.5.4" />
                <vers num="2.5.40" />
                <vers num="2.5.41" />
                <vers num="2.5.42" />
                <vers num="2.5.43" />
                <vers num="2.5.44" />
                <vers num="2.5.45" />
                <vers num="2.5.46" />
                <vers num="2.5.47" />
                <vers num="2.5.48" />
                <vers num="2.5.49" />
                <vers num="2.5.5" />
                <vers num="2.5.50" />
                <vers num="2.5.51" />
                <vers num="2.5.52" />
                <vers num="2.5.53" />
                <vers num="2.5.54" />
                <vers num="2.5.55" />
                <vers num="2.5.56" />
                <vers num="2.5.57" />
                <vers num="2.5.58" />
                <vers num="2.5.59" />
                <vers num="2.5.6" />
                <vers num="2.5.60" />
                <vers num="2.5.61" />
                <vers num="2.5.62" />
                <vers num="2.5.63" />
                <vers num="2.5.64" />
                <vers num="2.5.65" />
                <vers num="2.5.66" />
                <vers num="2.5.67" />
                <vers num="2.5.68" />
                <vers num="2.5.69" />
                <vers num="2.5.7" />
                <vers num="2.5.8" />
                <vers num="2.5.9" />
                <vers edition="test1" num="2.6.0" />
                <vers edition="test10" num="2.6.0" />
                <vers edition="test11" num="2.6.0" />
                <vers edition="test2" num="2.6.0" />
                <vers edition="test3" num="2.6.0" />
                <vers edition="test4" num="2.6.0" />
                <vers edition="test5" num="2.6.0" />
                <vers edition="test6" num="2.6.0" />
                <vers edition="test7" num="2.6.0" />
                <vers edition="test8" num="2.6.0" />
                <vers edition="test9" num="2.6.0" />
                <vers edition="rc1" num="2.6.1" />
                <vers edition="rc2" num="2.6.1" />
                <vers edition="rc2" num="2.6.10" />
                <vers num="2.6.2" />
                <vers edition="rc7" num="2.6.21" prev="1" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers edition="rc1" num="2.6.6" />
                <vers edition="rc1" num="2.6.7" />
                <vers edition="rc1" num="2.6.8" />
                <vers edition="rc2" num="2.6.8" />
                <vers edition="rc3" num="2.6.8" />
                <vers edition="2.6.20" num="2.6.9" />
                <vers num="2.6_test9_cvs" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0505" seq="2005-0505" severity="High" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers has "potentially serious" impact, related to LDAP logins.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19419" adv="1">irm-ldap-security-bypass(19419)</ref>
            <ref source="CONFIRM" patch="1" url="http://sourceforge.net/project/shownotes.php?release_id=306629" adv="1">http://sourceforge.net/project/shownotes.php?release_id=306629</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14342" adv="1">14342</ref>
        </refs>
        <vuln_soft>
            <prod vendor="stackworks_enterprises" name="information_resource_manager">
                <vers num="1.4.3" />
                <vers num="1.5.0" />
                <vers num="1.5.1" />
                <vers num="1.5.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0506" seq="2005-0506" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-041_Sensitive_Info_Leak.pdf" adv="1">http://support.avaya.com/elmodocs2/security/ASA-2005-041_Sensitive_Info_Leak.pdf</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910486128709&amp;w=2" adv="1">20050222 Re: Avaya IP Office Phone Manager - Sensitive Information Cleartext Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110909733831694&amp;w=2" adv="1">20050222 Avaya IP Office Phone Manager - Sensitive Information Cleartext</ref>
        </refs>
        <vuln_soft>
            <prod vendor="avaya" name="ip_office_phone_manager">
                <vers num="" />
            </prod>
            <prod vendor="avaya" name="ip_soft_phone">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0507" seq="2005-0507" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in SD Server 4.0.70 and earlier allows remote attackers to read arbitrary files via .. sequences in an HTTP request.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14365" adv="1">14365</ref>
            <ref source="FULLDISC" patch="1" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110901639709476&amp;w=2" adv="1">20050221 SD Server 4.0.70 Directory Traversal Bug</ref>
            <ref source="CONFIRM" url="http://www.gdsoftware.dk/">http://www.gdsoftware.dk/</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910535122762&amp;w=2">20050222 SD Server 4.0.70 Directory Traversal Bug</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gd_software" name="sd_server">
                <vers num="4.0.70" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0508" seq="2005-0508" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12619" adv="1">12619</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14336" adv="1">14336</ref>
            <ref source="CONFIRM" url="http://xml.apache.org/batik/#SecurityWarning">http://xml.apache.org/batik/#SecurityWarning</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-0509" seq="2005-0509" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "&lt;".</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14325" adv="1">14325</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2">20050217 XSS vulnerabilty in ASP.Net [with details]</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2" adv="1">20050217 XSS vulnerabilty in ASP.Net [with details]</ref>
            <ref source="MISC" url="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name=".net_framework">
                <vers edition="sp1" num="1.0" />
                <vers edition="sp2" num="1.0" />
                <vers edition="sp1" num="1.1" />
            </prod>
            <prod vendor="mono" name="mono">
                <vers num="1.0.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2005-0510" seq="2005-0510" severity="Low" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14328" adv="1">14328</ref>
            <ref source="CONFIRM" url="http://dcs.nac.uci.edu/~strombrg/fallback-reboot/" adv="1">http://dcs.nac.uci.edu/~strombrg/fallback-reboot/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="fallback-reboot" name="fallback-reboot">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0470" seq="2005-0470" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19357" adv="1">wpasupplicant-bo(19357)</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200502-22.xml" adv="1">GLSA-200502-22</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14313" adv="1">14313</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013226">1013226</ref>
            <ref source="MLIST" url="http://lists.shmoo.com/pipermail/hostap/2005-February/009465.html">[HostAP] 20050213 wpa_supplicant - new stable releases v0.3.8 and v0.2.7</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wpa_supplicant" name="wpa_supplicant">
                <vers num="0.2" />
                <vers num="0.2.1" />
                <vers num="0.2.2" />
                <vers num="0.2.3" />
                <vers num="0.2.4" />
                <vers num="0.2.5" />
                <vers num="0.2.6" />
            </prod>
            <prod vendor="gentoo" name="linux">
                <vers num="" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers edition="" num="9.2" />
                <vers edition=":x86_64" num="9.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0471" seq="2005-0471" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/544392" adv="1">VU#544392</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19285">sun-java-create-files(19285)</ref>
            <ref source="MISC" url="http://secunia.com/secunia_research/2004-7/advisory/">http://secunia.com/secunia_research/2004-7/advisory/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11070/" adv="1">11070</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers num="1.1.0" />
                <vers num="1.2.0" />
                <vers num="1.3.0" />
                <vers num="1.4.0" />
                <vers num="1.5.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.1" />
                <vers num="1.2" />
                <vers num="1.3.0" />
                <vers num="1.4" />
                <vers num="1.5.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0472" seq="2005-0472" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/839280" adv="1">VU#839280</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19380" adv="1">gaim-snac-dos(19380)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-432.html">RHSA-2005:432</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-215.html">RHSA-2005:215</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml">GLSA-200503-03</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-716">DSA-716</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14322">14322</ref>
            <ref source="CONFIRM" url="http://gaim.sourceforge.net/security/index.php?id=10" adv="1">http://gaim.sourceforge.net/security/index.php?id=10</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12589">12589</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2">20050225 [USN-85-1] Gaim vulnerabilities</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933">CLA-2005:933</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rob_flynn" name="gaim">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1.1" />
                <vers num="1.1.2" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers edition="" num="10.0" />
                <vers edition=":amd64" num="10.0" />
                <vers edition="" num="10.1" />
                <vers edition=":x86_64" num="10.1" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
                <vers edition="" num="3.0" />
                <vers edition=":x86_64" num="3.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0473" seq="2005-0473" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/523888" adv="1">VU#523888</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19381" adv="1">gaim-html-dos(19381)</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-215.html" adv="1">RHSA-2005:215</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml">GLSA-200503-03</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14322">14322</ref>
            <ref source="CONFIRM" url="http://gaim.sourceforge.net/security/index.php?id=11">http://gaim.sourceforge.net/security/index.php?id=11</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12589">12589</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2">20050225 [USN-85-1] Gaim vulnerabilities</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933">CLA-2005:933</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rob_flynn" name="gaim">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1.1" />
                <vers num="1.1.2" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers edition="" num="10.0" />
                <vers edition=":amd64" num="10.0" />
                <vers edition="" num="10.1" />
                <vers edition=":x86_64" num="10.1" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
                <vers edition="" num="3.0" />
                <vers edition=":x86_64" num="3.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0398" seq="2005-0398" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2009-06-13">
        <desc>
            <descript source="cve">The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=109966&amp;action=view" adv="1">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=109966&amp;action=view</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19707" adv="1">racoon-isakmp-header-dos(19707)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12804" adv="1">12804</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2005-232.html" adv="1">RHSA-2005:232</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2005/0264" adv="1">ADV-2005-0264</ref>
            <ref source="MLIST" patch="1" url="http://sourceforge.net/mailarchive/forum.php?thread_id=6787713&amp;forum_id=32000" adv="1">[ipsec-tools-devel] 20050312 potential remote crash in racoon</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1013433" adv="1">1013433</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200503-33.xml" adv="1">GLSA-200503-33</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14584" adv="1">14584</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:062">MDKSA-2005:062</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ipsec-tools" name="ipsec-tools">
                <vers num="0.3.3" />
                <vers num="0.5" />
            </prod>
            <prod vendor="kame" name="racoon">
                <vers num="2003-07-11" />
                <vers num="2004-04-05" />
                <vers num="2004-04-07b" />
                <vers num="2004-05-03" />
                <vers num="2005-01-03" />
                <vers num="2005-01-10" />
                <vers num="2005-01-17" />
                <vers num="2005-01-24" />
                <vers num="2005-01-31" />
                <vers num="2005-02-07" />
                <vers num="2005-02-14" />
                <vers num="2005-02-21" />
                <vers num="2005-02-28" />
                <vers num="2005-03-07" />
            </prod>
            <prod vendor="sgi" name="propack">
                <vers num="3.0" />
            </prod>
            <prod vendor="altlinux" name="alt_linux">
                <vers edition="" num="2.3" />
                <vers edition=":junior" num="2.3" />
                <vers edition=":compact" num="2.3" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="3.0" />
                <vers edition=":workstation" num="3.0" />
                <vers edition=":advanced_servers" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
                <vers edition="" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="3.0" />
                <vers num="4.0" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers edition=":desktop" num="" />
                <vers edition=":enterprise_server" num="" />
                <vers edition="" num="9.1" />
                <vers edition=":x86_64" num="9.1" />
                <vers edition="" num="9.2" />
                <vers edition=":x86_64" num="9.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0258" seq="2005-0258" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via "/../" sequences in the avatarselect parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/display?id=205&amp;type=vulnerabilities" adv="1">20050222 phpBB Group phpBB2 Arbitrary File Unlink Vulnerability</ref>
            <ref source="CONFIRM" url="http://www.phpbb.com/support/documents.php?mode=changelog" adv="1">http://www.phpbb.com/support/documents.php?mode=changelog</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml">GLSA-200503-02</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpbb_group" name="phpbb">
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.11" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.6c" />
                <vers num="2.0.6d" />
                <vers num="2.0.7" />
                <vers num="2.0.7a" />
                <vers num="2.0.8" />
                <vers num="2.0.8a" />
                <vers num="2.0.9" />
                <vers num="2.0_beta1" />
                <vers num="2.0_rc1" />
                <vers num="2.0_rc2" />
                <vers num="2.0_rc3" />
                <vers num="2.0_rc4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2005-0259" seq="2005-0259" severity="Medium" type="CVE" published="2005-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-10">
        <desc>
            <descript source="cve">phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/774686">VU#774686</ref>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/display?id=204&amp;type=vulnerabilities" adv="1">20050222 phpBB Group phpBB Arbitrary File Disclosure Vulnerability</ref>
            <ref source="CONFIRM" url="http://www.phpbb.com/support/documents.php?mode=changelog" adv="1">http://www.phpbb.com/support/documents.php?mode=changelog</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml">GLSA-200503-02</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14362/">14362</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpbb_group" name="phpbb">
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.11" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.6c" />
                <vers num="2.0.6d" />
                <vers num="2.0.7" />
                <vers num="2.0.7a" />
                <vers num="2.0.8" />
                <vers num="2.0.8a" />
                <vers num="2.0.9" />
                <vers num="2.0_beta1" />
                <vers num="2.0_rc1" />
                <vers num="2.0_rc2" />
                <vers num="2.0_rc3" />
                <vers num="2.0_rc4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0384" seq="2005-0384" severity="Medium" type="CVE" published="2005-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1">USN-95-1</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0009/" adv="1">2005-0009</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12810">12810</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-284.html" adv="1">RHSA-2005:284</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-283.html" adv="1">RHSA-2005:283</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" adv="1">SUSE-SA:2005:018</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref>
        </refs>
        <vuln_soft>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers num="8.2" />
                <vers num="9.0" />
                <vers num="9.1" />
                <vers num="9.2" />
            </prod>
            <prod vendor="trustix" name="secure_linux">
                <vers num="2" />
                <vers num="2.1" />
                <vers num="2.2" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers num="4.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0792" seq="2005-0792" severity="High" type="CVE" published="2005-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14602" adv="1">14602</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19709" adv="1">zpanel-index-sql-injection(19709)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12809" adv="1">12809</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2" adv="1">20050320 Re: Few remote bugs in zPanel</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2" adv="1">20050315 Few remote bugs in zPanel</ref>
        </refs>
        <vuln_soft>
            <prod vendor="zpanel" name="zpanel">
                <vers num="2.0" />
                <vers num="2.5_beta" />
                <vers num="2.5_beta10" />
                <vers num="2.5_beta9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0793" seq="2005-0793" severity="High" type="CVE" published="2005-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12809" adv="1">12809</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2" adv="1">20050320 Re: Few remote bugs in zPanel</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2" adv="1">20050315 Few remote bugs in zPanel</ref>
        </refs>
        <vuln_soft>
            <prod vendor="zpanel" name="zpanel">
                <vers num="2.0" />
                <vers num="2.5_beta" />
                <vers num="2.5_beta10" />
                <vers num="2.5_beta9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2005-0794" seq="2005-0794" severity="Medium" type="CVE" published="2005-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-05">
        <desc>
            <descript source="cve">ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14602" adv="1">14602</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2" adv="1">20050320 Re: Few remote bugs in zPanel</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2" adv="1">20050315 Few remote bugs in zPanel</ref>
        </refs>
        <vuln_soft>
            <prod vendor="zpanel" name="zpanel">
                <vers num="2.0" />
                <vers num="2.5_beta10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0797" seq="2005-0797" severity="Medium" type="CVE" published="2005-03-15" CVSS_version="2.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/12811" adv="1">12811</ref>
            <ref source="MISC" url="http://www.infobyte.com.ar/adv/ISR-04.html" adv="1">http://www.infobyte.com.ar/adv/ISR-04.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14607" adv="1">14607</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091027000721&amp;w=2" adv="1">20050315 [ISR] - Novell iChain Mini FTP Server Valid User Disclosure Vulnerability</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-0798" seq="2005-0798" severity="High" type="CVE" published="2005-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.infobyte.com.ar/adv/ISR-05.html" adv="1">http://www.infobyte.com.ar/adv/ISR-05.html</ref>
            <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096887.htm" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096887.htm</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14607" adv="1">14607</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091517007681&amp;w=2" adv="1">20050315 [ISR] - Novell iChain Mini FTP Server Bruteforce Problem</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/14648">14648</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1013408">1013408</ref>
        </refs>
        <vuln_soft>
            <prod vendor="novell" name="ichain">
                <vers edition="sp1" num="2.2" />
                <vers edition="sp1a" num="2.2" />
                <vers edition="sp2" num="2.2" />
                <vers edition="sp3" num="2.2" />
                <vers num="2.2.113" />
                <vers edition="sp2" num="2.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-0799" seq="2005-0799" severity="Medium" type="CVE" published="2005-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14564" adv="1">14564</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091250923281&amp;w=2">20050315 Denial of Service Vulnerability in MySQL Server for Windows</ref>
            <ref source="CONFIRM" url="http://bugs.mysql.com/bug.php?id=9148" adv="1">http://bugs.mysql.com/bug.php?id=9148</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mysql" name="mysql">
                <vers num="4.1.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" name="CVE-2005-0767" seq="2005-0767" severity="Medium" type="CVE" published="2005-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="6.9" modified="2008-09-10">
        <desc>
            <descript source="cve">Race condition in the Radeon DRI driver for Linux kernel 2.6.8.1 allows local users with DRI privileges to execute arbitrary code as root.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1">USN-95-1</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945" adv="1">CLA-2005:945</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2005-0352" seq="2005-0352" severity="High" type="CVE" published="2005-03-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19715" adv="1">serversalive-gain-privileges(19715)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12822" adv="1">12822</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14616/" adv="1">14616</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100364513513&amp;w=2" adv="1">20050316 Servers Alive: Local Privilege Escalation</ref>
        </refs>
        <vuln_soft>
            <prod vendor="woodstone" name="servers_alive">
                <vers num="4.1" />
                <vers num="5.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-0713" seq="2005-0713" severity="Medium" type="CVE" published="2005-03-21" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-an